Attacks/Breaches
7/3/2014
00:00 AM
Tim Wilson
Tim Wilson
Quick Hits
Connect Directly
RSS
E-Mail
50%
50%

Retail Breaches Change Customer Behavior, Attitudes, Studies Say

Recent breaches of retail and credit card data are making customers think twice about where they shop and how they pay, researchers say

U.S. consumers are beginning to see the impact of the recent spate of credit card data breaches at retail stores -- and they are doing something about it.

That's the conclusion of two separate studies of consumer attitudes and behavior published this week. The first study, National Consumer League's Data Insecurity Report, indicates that consumers are increasingly blaming retailers for the compromise of their credit card data and are responding by changing the stores they patronize.

The second study, Security Matters: Americans on EMV Chip Cards, indicates that nearly two thirds of Americans are more likely to pay in cash after hearing about security breaches at large retailers.

The NCL study, which was conducted by Javelin Strategy & Research on behalf of the consumer group, indicates that about one in three consumers who receive notice of a data breach subsequently become the victims of fraud. In a survey of victims in major U.S. metropolitan areas, 61 percent of fraud victims said they are "certain" that breaches of their data at retail sites were the source of the fraud. About a third pointed to large retail merchants directly.

Nearly 60 percent of fraud victims said their trust in retailers has significantly decreased after their data was compromised. Fourteen percent said they avoid certain merchants because of the potential for fraud. Only 10 percent of consumers said they believe retailers can keep their data safe.

Confidence in financial institutions remains higher, according to both surveys. Twenty-eight percent of fraud victims in the NCL study said they lost confidence in their financial institutions following their experiences. The second study, which was conductioned by research firm Vision Critical on behalf of payment technology vendor NXP Semiconductors, moree than 70 percent of Americans are confident in the security of their debit/credit cards, even after the news of major retail breaches.

However, many Americans are changing their payment strategies, the NXP study says. Some 64 percent of respondents say they are more likely to pay in cash after hearing about security breaches at large retailers, the survey says.

According to the NCL study, many Americans believe that government should step in and take a more active role in protecting consumer data. The NCL used the survey findings to call for national data breach notification standards, better protection of personally-identifiable information, increased penalties for online data theft, and increased partnerships with overseas law enforcement agencies to stop cyber criminal attacks from other countries.

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
7/9/2014 | 5:13:15 PM
Re: Be proactive
Your reference specifically to the US has made me think towards other countries. I know that other countries in the EU have much more astringent privacy laws which leads to more security safeguards put in place. Why do you think that similar strict protocols are not in place in this country? 
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
7/7/2014 | 11:14:35 AM
Re: Be proactive
There are a lot of things to do from the retailers' point of view. The recent cases in US are the demonstration that security has been ignored for too much time by retailers and by Credit Card Issues. 

We need a layered approach and every actor involved in the process must re-analyze and improve security measures to adopt to mitigate the risks.

 

 
anon7386852492
50%
50%
anon7386852492,
User Rank: Apprentice
7/7/2014 | 11:06:02 AM
Two common Web application attacks illustrate security concerns
An attack by Hackers on consumer data poses a great risk for retail businesses. These attacks are common and retailers need to adopt suitable measures to check these risks in order to retain confidence of their customers. I work with McGladrey and there's a whitepaper on our website that offers useful information on the common security concerns for businesses and ways to mitigate them. "Two common Web application attacks illustrate security concerns"   @   http://bit.ly/1c0f35M     
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
7/6/2014 | 4:11:16 PM
Be proactive
I have noticed the same changes in behavior even with people who were not directly affected. I noticed that my relatives, due to the target breach, have changed all of their passwords and have become more aware of their finances. I think this might have been a blessing in disguise. It is making people become more aware of the threats and the real life circumstances that the digital realm can entail.

What needs to be emphasized is always be vigilant of your accounts. Check them at least once a week and change passwords regularly. Even when your data is breached, you can stay a step ahead by being aware of personal changes. Although we may not have the ability to change the situation, we definitely have the ability to alleviate future woes.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6335
Published: 2014-08-26
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and ...

CVE-2014-0480
Published: 2014-08-26
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL ...

CVE-2014-0481
Published: 2014-08-26
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a d...

CVE-2014-0482
Published: 2014-08-26
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors relate...

CVE-2014-0483
Published: 2014-08-26
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.