Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Breaches Cause Skittish Attitudes Among Holiday Shoppers

Many consumers no longer sure of the security of their transactions, study says

Dec 14, 2007 | 07:22 AM

By Tim Wilson
DarkReading

Holiday shoppers are in stores and online again this year -- but they don't feel too safe doing it, according to a report scheduled to be published Monday by security vendor Utimaco.

The study, which was conducted by a third-party research company, asked consumers about their attitudes toward security and credit card fraud following high-profile security breaches at retailers such as the TJX Companies. (See TJX Settles With Banks for $41 Million.)

The study shows a widespread lack of confidence in retailers' security systems. Eighty-nine percent of the respondents said they believe a breach similar to the TJX leak is likely to happen again. Forty-nine percent said they do not think retailers are doing more to protect consumer data, according to Utimaco.

Fifty-eight percent of consumers say they do not assume their personal data and credit card information is safe when they shop, the study says. Forty-seven percent say that recent breaches of personal information security make them feel less comfortable using credit card information when shopping online.

"Holiday shoppers have been rocked by the magnitude and severity of data security threats that have impacted leaders such as TJX Companies, Stop & Shop, and others," said Craig Bumpus, COO of Utimaco America. "In addition to capturing the consumer pulse around personal and credit card data, this survey is a wakeup call to retailers worldwide. [They] must deploy processes and technologies that will stem the tide of data breaches and ensure consumer protection."

Other vendors offered similar warnings to retailers and consumers. (See Cybercriminals Ready for Banner Holiday Shopping Season, Check Point Urges Shoppers to Be Cautious, and Norton, McAfee & Kaspersky Fighting for Seagate's HDD Security.)

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Utimaco Safeware AG


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)