We're a little less than a month into the new year, and there's already a strong contender for biggest data security breach of '09. Actually, the breach, which involved a compromise of Heartland Payment Systems took place in 2008, but it wasn't publicly disclosed until yesterday, so I'm classifying it as a 2009 breach. However, whatever year the breach is placed in, it's potentially a monster, with over 100,000,000 accounts at risk. We don't know the full extent of the breach yet, but this is one to keep an eye on as potentially not only being a candidate for the biggest breach of 2009, but also as having the potential to dethrone TJX as the biggest breach ever.
via
Showing posts with label TJX. Show all posts
Showing posts with label TJX. Show all posts
Wednesday, January 21, 2009
Thursday, August 7, 2008
Drawing the Wrong Lessons from a Breach
The other day, I was listening to the radio, and a commentator said that the most significant harm that could come from a major breach like the TJX breach was not identity theft, but was actually people losing faith in doing business over the internet. Frankly, I'm not sure he was right, given that identity theft is a major problem for consumers. However, while it might not be the biggest harm from a breach, losing faith in doing business over the internet would be an inappropriate response to a breach like that at TJX for the simple reason that the internet had nothing to do with that breach. Instead, the hackers found stores which had unsecure wireless connections, used them to install malicious software on the TJX corporate network, then used the software to harvest credit cards from TJX's systems. The internet didn't come into play until after the cards were stolen and the thieves needed to sell them. While avoiding doing business over the internet might avoid some types of risks (particularly phishing scams), it would have no effect whatsoever on a consumer's risk of being affected by a breach such as took place at TJX.
Wednesday, August 6, 2008
Hackers Caught
As described in this article from cnn.com, the justice department has issued 11 indictments for stealing more than 40 million credit and debit card numbers. Unsurprisingly given the nature of the crime the suspects are from all over the world - three from the U.S., three from Estonia, two from Ukraine, two from China, and one from Belarus. The arrests are the result of years of investigation, showing both the difficulty of making arrests in cases of international card fraud, and the potential of dedicated police work.
One question raised by the article is how many more people were involved. The article says that "[t]he 41 million credit and debit numbers were used internationally," and also says that the suspects are accused of hacking into the TJX network. There's something of a disconnect between the numbers and the crime. As I mentioned here, depending on whose numbers you go by, the TJX breach involved either 94 or 45 million records. Thus, if the indicted suspects really were behind the breach, and actually did steal only 41 million numbers, it implies that they aren't the only ones who were taking numbers from TJX. Still, aside from that small detail, the indictments appear to be happy news. Hopefully the police got the right people, and will continue to do so in the future.
One question raised by the article is how many more people were involved. The article says that "[t]he 41 million credit and debit numbers were used internationally," and also says that the suspects are accused of hacking into the TJX network. There's something of a disconnect between the numbers and the crime. As I mentioned here, depending on whose numbers you go by, the TJX breach involved either 94 or 45 million records. Thus, if the indicted suspects really were behind the breach, and actually did steal only 41 million numbers, it implies that they aren't the only ones who were taking numbers from TJX. Still, aside from that small detail, the indictments appear to be happy news. Hopefully the police got the right people, and will continue to do so in the future.
Tuesday, April 15, 2008
A "New" Data Security Threat, and Why That's a Good Thing
this article from Computer World describes a "new" type of attack hackers have been using to get at credit card data: interception of unencrypted data while in transit. Now, as the article points out, the tools being used by hackers to intercept data in transit aren't novel technology, so the description of a "new" threat is, in one sense, not accurate. However, obtaining unencrypted information in transit marks a significant shift from the traditional hacker tactic of stealing information stolen from databases (see, e.g., TJX and CardSystems, the two biggest data security incidents on record). Of course, to a consumer, it doesn't matter much how their credit card numbers were stolen. However, to me, the fact that hackers are switching tactics is not only a big deal, it's also good news for at least three reasons.
First, it's harder for a hacker to steal huge amounts of data by intercepting it in transit than it is for a hacker to steal huge amounts of data by stealing it from a database. For example, it takes at least a month for a hacker to steal a month's worth of credit card numbers if they're being captured while in transit during a transaction. By contrast, a month's worth of credit card numbers can be stolen from a database in seconds. Thus, if hackers focusing on data in transit rather than data at rest should decrease the overall amount of data stolen.
Second, as described in the article, one reason that hackers are switching to catching information in transit rather than focusing on databases is that companies have hardened their databases in order to comply with the PCI DSS. This shows that compliance with the DSS, while admittedly not universal, has been widespread enough to change criminal behavior, something that is clearly a positive development for data security.
Third, the fact that hackers have switched from high value targets (databases) to relatively lower value targets (data transmissions) based on the behavior of their targets shows that, when properly motivated, regulation can address and alleviate serious problems (in this case, the problem of easily compromised databases). Of course, at this point, the switch from targeting databases to targeting transmissions means that some tinkering with the PCI DSS is probably in order. However, there is no reason why the same framework which resulted in the increases in database security that led to the shift can't also be used to address threats to transmissions. Thus, while the new tactics being used to steal credit cards represent new challenges, they also show that some progress has been made in the ongoing battle to increase the security of individual consumer data.
PostScript: On a quasi-related note for everyone who says that private initiatives are always superior to government action, the HIPAA security regulations actually address protecting information in transit and at rest, so they already address the "new" threat described in the article.
First, it's harder for a hacker to steal huge amounts of data by intercepting it in transit than it is for a hacker to steal huge amounts of data by stealing it from a database. For example, it takes at least a month for a hacker to steal a month's worth of credit card numbers if they're being captured while in transit during a transaction. By contrast, a month's worth of credit card numbers can be stolen from a database in seconds. Thus, if hackers focusing on data in transit rather than data at rest should decrease the overall amount of data stolen.
Second, as described in the article, one reason that hackers are switching to catching information in transit rather than focusing on databases is that companies have hardened their databases in order to comply with the PCI DSS. This shows that compliance with the DSS, while admittedly not universal, has been widespread enough to change criminal behavior, something that is clearly a positive development for data security.
Third, the fact that hackers have switched from high value targets (databases) to relatively lower value targets (data transmissions) based on the behavior of their targets shows that, when properly motivated, regulation can address and alleviate serious problems (in this case, the problem of easily compromised databases). Of course, at this point, the switch from targeting databases to targeting transmissions means that some tinkering with the PCI DSS is probably in order. However, there is no reason why the same framework which resulted in the increases in database security that led to the shift can't also be used to address threats to transmissions. Thus, while the new tactics being used to steal credit cards represent new challenges, they also show that some progress has been made in the ongoing battle to increase the security of individual consumer data.
PostScript: On a quasi-related note for everyone who says that private initiatives are always superior to government action, the HIPAA security regulations actually address protecting information in transit and at rest, so they already address the "new" threat described in the article.
Tuesday, February 26, 2008
Study: Data Exposure Less Expensive than Previously Estimated
There's a new data point for organizations struggling to figure out what impact data exposure has on a business' bottom line. According to a study from the Ponemon Institute, described in this article, the average costs of an information security breach in the UK is about 47 pounds/record (about 103 dollars/record at current exchange rates). This is much less than the 197 dollars/record figure from a different Ponemon study from last year, which I described in this post. Why the discrepancy? My immediate thought is data underlying sets. The more recent study is focused on the UK, while the previous study was not. On the other hand, it's also possible that the previous study simply overestimated the costs of a breach. At this point, my guess is that the discrepancy is based on a combination of the two factors, but that the actual cost is closer to the lower number, a conclusion I draw in part because of the relatively low per record cost associated with massive breaches, something I wrote about here in the context of the TJX case.
Thursday, January 3, 2008
2007: Year of Controversy
Was 2007 a good or bad year (in terms of number of breaches and number of records stolen)? As it happens, there's some controversy as to the answer for that question. This article from Information Week says that 2007 was a bad year for privacy, breaking records in terms of both number of incidents and number of records lost. However, when this blogger at Chronicles of Dissent crunched the numbers, (s)he concluded that 2007 was a (relatively) good year in terms of both number of incidents and number of records exposed.
While the fight involves doing things like actually counting numbers of breaches and records (something I don't want to do), I will say that the post from Chronicles of Dissent brings up some good points, something even Information Week concedes. However, there is something I wanted to clarify. Both Information Week and Chronicles of Dissent listed the number of records exposed by the TJX breach at 94 million. That number, while included in court documents filed by the plaintiffs in that case, could very well be wrong. There has been no trial in TJX, and so the plaintiffs' contention that 94 million records (rather than the 46 million records cited by TJX) were exposed has never been tested or validated by a court. Given that, if 2007 is counted with the more conservative (but clearly not overstated) 46 million figure, the number of records lost in 2007 drops by more than half, regardless of who's counting. With that drop, the number of records lost in 2007 appears to be trending down from 2007, meaning that 2007 was (according to that measure) a relatively good year for data privacy.
While the fight involves doing things like actually counting numbers of breaches and records (something I don't want to do), I will say that the post from Chronicles of Dissent brings up some good points, something even Information Week concedes. However, there is something I wanted to clarify. Both Information Week and Chronicles of Dissent listed the number of records exposed by the TJX breach at 94 million. That number, while included in court documents filed by the plaintiffs in that case, could very well be wrong. There has been no trial in TJX, and so the plaintiffs' contention that 94 million records (rather than the 46 million records cited by TJX) were exposed has never been tested or validated by a court. Given that, if 2007 is counted with the more conservative (but clearly not overstated) 46 million figure, the number of records lost in 2007 drops by more than half, regardless of who's counting. With that drop, the number of records lost in 2007 appears to be trending down from 2007, meaning that 2007 was (according to that measure) a relatively good year for data privacy.
Wednesday, December 5, 2007
The Forgotten Side of the TJX Litigation
As it happens, the TJX litigation isn't only about TJX. That litigation is actually about lawsuits against both TJX and Fifth Third, TJX's bank. The relationship between Fifth Third and TJX was that, when a consumer would make a credit card purchase, the information from that purchase would be sent from TJX to Fifth Third. The information would then be sent to the bank that issued the credit card to the consumer, who would say either yea or nay, then the information would be passed back to TJX through Fifth Third. For some purposes in the litigation, TJX and Fifth Third could be (and were) given the same treatment. However, the unique status of Fifth Third came to the fore when the judge in the TJX litigation decided to deny class certification to the issuing banks in their suit against TJX. For class certification, it was necessary that there be some assurance that the issuing banks would vigorously prosecute the litigation, and that there be no conflict between the members of the class as a whole. The problem raised by Fifth Third's relationship with TJX is that some of the issuing banks suing TJX were also acquiring banks, that is, they functioned in the same capacity for their customers as Fifth Third had for TJX. The result was that the court found that a verdict which imposed liability on Fifth Third could actually be negative for some of the banks filing suit - leading to a conflict between those banks and the banks which only issued credit cards, but did not act as acquiring banks. For the court, that conflict provided an independent reason why class certification in the parallel action against Fifth Third was inappropriate.
Tuesday, December 4, 2007
Bankers' Class Action Rejected
Last Thursday, the judge in the ongoing TJX litigation denied the motion for class certification by financial institutions seeking to recover damages caused by cancelling and reissuing credit cards. The primary reasons given by the court for denying class certification was that the issues of whether any individual banks relied on TJX's maintaining adequate security, and whether any losses for individual banks were caused by TJX's security breach (as opposed to, for example, unrelated fraud) predominated over issues common to the class seeking to sue TJX.
Assuming that the court adheres to its denial of class certification (there is a pending motion to amend the banks' complaint, and there will likely be an appeal of the denial of class certification) the result will be that individual banks will have to either drop their litigation against TJX, or pursue their cases on an individual basis. Realistically, many of the bankers' claims will likely be too small to justify the costs of pursuing individual litigation, meaning that the denial of class certification could effectively end TJX's current legal troubles. Accordingly, this decision should be seen as a big (albeit potentially temporary) win for TJX, and a similarly large setback for those seeking to recover costs caused by that breach.
Assuming that the court adheres to its denial of class certification (there is a pending motion to amend the banks' complaint, and there will likely be an appeal of the denial of class certification) the result will be that individual banks will have to either drop their litigation against TJX, or pursue their cases on an individual basis. Realistically, many of the bankers' claims will likely be too small to justify the costs of pursuing individual litigation, meaning that the denial of class certification could effectively end TJX's current legal troubles. Accordingly, this decision should be seen as a big (albeit potentially temporary) win for TJX, and a similarly large setback for those seeking to recover costs caused by that breach.
Sunday, December 2, 2007
TJX Settling Out?
According to this article from Computer World TJX has proposed to pay $40.9 million to banks that issued Visa cards potentially affected by TJX's massive data breach if the affected banks agree not to pursue litigation against TJX. The article describes TJX's offer a move which could save "tens of millions of dollars in lawsuit damages." Actually, that's understating things quite a bit. In paragraph 96 of the fifth amended complaint in the ongoing litigation regarding the TJX breach (case number 1:07-cv-10162), a bankers association seeking class certification alleged that "The cancellation and reissuance of cards resulted in damages and losses to Plaintiff Banks and members of the proposed Class of up to $25 per card." As the first paragraph of that same complaint alleged that "approximately 100 million credit cards were compromised because of TJX's acts and omissions," it seems that there were potentially up to 2.5 billion (25 dollars/card * 100 million cards) dollars in damages. Even assuming that the $25 per card cited as the maximum in the lawsuit is unrepresentative, and the real cost is lower (e.g., the 10 dollars/card quoted in this posting), the cost of canceling and reissuing almost 100 million cards is certainly greater than the $40.9 million offered by TJX. Of course, there's no guarantee that the banks would win if they did pursue litigation. However, if TJX ends up eliminating its litigation risks from banks who had to reissue cards for only $40.9 million, then TJX would dodge a very big bullet at only a (relatively) low cost.
Thursday, October 25, 2007
Bigger Trouble for TJX
Apparently, the TJX breach could have been bigger than previously estimated. According to court papers filed by plaintiff banks and bankers associations seeking class certification (described in this article from Computer World, TJX's breach actually exposed 94 million records, not the 45 million records previously announced. According to the banks, the costs to card issuing companies on Visa accounts alone already total between $68 and $83 million.
So what will the practical effect of all this be for TJX? More bad publicity for one, but that shouldn't be a surprise. There will also be higher legal fees, since more money at stake means that everyone involved will fight more tenaciously. Will TJX be forced to pay the bank's losses? That's a more interesting question. Individuals who try to recover from retailers who suffer from data breaches generally have little success (see, e.g., this post about a case which was thrown out in the seventh circuit). However, the bankers might have better luck. Individuals often lose because courts determine that they can't prove damages from a breach, but the bankers are in a much better position to put actual numbers on the harm they claim to have suffered. On the other hand, the current case is taking place in Boston, and Massachusetts (like every other state in the country except Minnesota) does not have a law which shifts costs of a breach from banks to retailers. This is the case even though Massachusetts was considering such a law earlier this year (see here for an article on that proposed law). My guess is that courts would be reluctant to shift costs from retailers to banks when the legislature considered and rejected such a cost shift itself.
Happily, I'm not personally involved in this case, so I can just watch and see how it shakes out.
So what will the practical effect of all this be for TJX? More bad publicity for one, but that shouldn't be a surprise. There will also be higher legal fees, since more money at stake means that everyone involved will fight more tenaciously. Will TJX be forced to pay the bank's losses? That's a more interesting question. Individuals who try to recover from retailers who suffer from data breaches generally have little success (see, e.g., this post about a case which was thrown out in the seventh circuit). However, the bankers might have better luck. Individuals often lose because courts determine that they can't prove damages from a breach, but the bankers are in a much better position to put actual numbers on the harm they claim to have suffered. On the other hand, the current case is taking place in Boston, and Massachusetts (like every other state in the country except Minnesota) does not have a law which shifts costs of a breach from banks to retailers. This is the case even though Massachusetts was considering such a law earlier this year (see here for an article on that proposed law). My guess is that courts would be reluctant to shift costs from retailers to banks when the legislature considered and rejected such a cost shift itself.
Happily, I'm not personally involved in this case, so I can just watch and see how it shakes out.
Tuesday, September 25, 2007
TJX to Pay Settlement (Maybe)
According to this article from ComputerWorld TJX has proposed to settle consumer class actions arising from its massive data breach earlier this year. As part of the settlement, TJX would provide credit monitoring, identity theft insurance, and payment of the cost of credit card replacement for individuals whose personal data may have been stolen during the breach. The company would also agree to hold a 15% off sale at some point in the next year, and to pay for "certain losses from identity theft" for individuals whose driver's license or other ID numbers were the same as their Social Security numbers.
The questions now are whether consumers should take the settlement, and whether the court should bless it as fair. At first blush, it seems like the settlement is almost an insult. After all, large retailers routinely hold sales with discounts greater than the 15% off that TJX is offering, and it is not clear what the "certain losses from identity theft" that TJX would agree to cover would actually entail. On the other hand, the credit monitoring, card replacement and free identity theft insurance are real benefits. True, it might seem like paying these costs is the least TJX should do, but when consumers have tried to use courts to force those payments out of companies which have had a security breach they have generally been unsuccessful. For example, this post discusses a case from the seventh circuit where consumers were thrown (figuratively) out of court because the judges decided that damages from fear of future identity theft weren't real enough to be used as a basis for compensation - even compensation for the cost of credit monitoring. Thus, while the settlement from TJX may seem like a bargain, it could be the best that the consumer plaintiffs can reasonably expect.
The questions now are whether consumers should take the settlement, and whether the court should bless it as fair. At first blush, it seems like the settlement is almost an insult. After all, large retailers routinely hold sales with discounts greater than the 15% off that TJX is offering, and it is not clear what the "certain losses from identity theft" that TJX would agree to cover would actually entail. On the other hand, the credit monitoring, card replacement and free identity theft insurance are real benefits. True, it might seem like paying these costs is the least TJX should do, but when consumers have tried to use courts to force those payments out of companies which have had a security breach they have generally been unsuccessful. For example, this post discusses a case from the seventh circuit where consumers were thrown (figuratively) out of court because the judges decided that damages from fear of future identity theft weren't real enough to be used as a basis for compensation - even compensation for the cost of credit monitoring. Thus, while the settlement from TJX may seem like a bargain, it could be the best that the consumer plaintiffs can reasonably expect.
Thursday, August 16, 2007
How Much Does a Mega-Breach Cost?
According to this article from Computerworld TJX has announced that the costs of a massive 45 million+ record data breach could reach over $150,000,000. While certainly a significant amount of money (I know my net worth doesn't even approach $150,000,000) the figure given by TJX is actually significantly less than I would have expected. When taking into account the magnitude of the breach, the per record cost given by TJX is only about $3.30. That's orders of magnitude lower than the $182/record average cost given by the Ponemon institute described in this article. While it's possible that larger breaches have lower cost/record numbers (something like buying in bulk), my guess is that $150,000,000 is something of a lowball estimate. However, even at $3.30/record, a breach like the one which hit TJX isn't cheap, and even the $150,000,000 figure is likely to spur some long overdue emphasis on information security.
Labels:
costs,
data protection,
Security Breaches,
TJX
Subscribe to:
Posts (Atom)