March 29, 2008 10:53 AM PDT

Malware to blame in supermarket data breach

It turns out malware somehow found its way onto a Maine-based supermarket chain's servers, which led to the security breach announced earlier this month compromising up to 4.2 million credit cards.

Hannford logo

Citing a letter the Hannaford grocer sent to Massachusetts regulators, The Boston Globe on Friday reported that the malicious software intercepted data from customers as they paid with plastic at checkout counters and sent data overseas.

The malware was installed on computer servers at each of the 300-some stores operated by Hannaford and its partners, the Globe reported.

The company is continuing its investigation into how the malware may have been placed on the servers. The Secret Service, meanwhile is conducting its own investigation.

The breach appears to be one of the first in which credit card numbers were stolen while the information was in transit, or at the point of sale. One of a growing number of sophisticated attacks, it illustrates vulnerabilities in the communication between cash registers and branch servers, as Neal Krawetz of Hacker Factor Solutions has warned in research (PDF).

That mode contrasts to attacks on databases, the method used to compromise 45.7 million accounts over a two-year period in a data breach of customer records at TJX Companies, the operator of T.J. Maxx and Marshalls retail chains.

Andrew Conry of InformationWeek adds that Hannaford, in addition to the breach, has two related class action lawsuits on its hands alleging negligence in maintaining customer security. And he suggests that there might be some truth to the claims, noting that Hannaford should have noticed that "internal servers were transmitting outside the network to a strange IP. This should've raised flags somewhere--server logs, IDS logs, firewall logs."

I'll second Conry's conclusion: "In any case, the whole mess should be very instructional to retailers everywhere," particularly in light of Friday's news of attacks on top Web sites like USAToday.com, Target.com, ABCNews.com, Walmart.com, and of a data breach at Antioch University in Ohio.

Recent posts from News Blog
XACML: A still-emerging standard worth watching
Alltel joins LTE bandwagon
Wafer-thin: Samsung's OLED laptop prototype
Georgia law aims to lure video game makers
iPhone expands its empire, once again
Add a Comment (Log in or register) 6 comments (Page 1 of 1)
Blogs CNET
by paulsecic March 30, 2008 10:40 AM PDT
Please use better fonts in blogs. Too hard to read.
Reply to this comment
Should've used an *IX OS on those servers.
by BtmnHatesRbn March 30, 2008 4:31 PM PDT
C'mon! How dumb can these IT dorks be at this supermarket chain? What? They installed DOOM or Quake once and got it to work on a Compaq Presario 5610 in 1998? Please. Should've been using a flavor of Linux, OS X Server, FreeBSD or even frickin' DOS 2000. Anything but a M$ OS that has now created this mess with NSA-requested backdoors and security holes. Ugh!
Reply to this comment
PCI Law
by BenjaminWright March 31, 2008 7:09 AM PDT
Legally speaking, we can't expect the PCI to keep up with the criminals. Therefore the legal system (Federal Trade Commission) is wrong to punish merchants like Hannaford and TJX for credit card break-ins. http://hack-igations.blogspot.com/2008/03/ftc-treats-tjx-unfairly.html --Ben
Reply to this comment View all 2 replies
Powered by Jive Software
  • About News Blog

  • Recent posts on technology, trends, and more.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. CBS to buy CNET Networks

  2. Images: Microsoft telescope puts universe on your desktop

  3. End of Intel, AMD duopoly near? Via readies Isaiah chip

  4. If Gates is right, how much longer for keyboards & mice?

  5. Photos: Microsoft previews 2008 Xbox games

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

advertisement
On TechRepublic: 3 habits of highly ineffective employees
Advanced
search
Advanced
search
Visit other CNET Networks sites: