Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Michaels Stores Investigates Data Breach

Arts-and-crafts retailer goes into damage-control mode after banks report fraud possibly tied to shoppers' credit cards.

Top 10 Retail CIO Priorities For 2014
Top 10 Retail CIO Priorities for 2014
(Click image for larger view and slideshow.)

Arts-and-crafts retailer Michaels Stores is the latest business to confirm that it's investigating an apparent hack attack against its systems resulting in the theft of shoppers' credit and debit card details.

"We recently learned of possible fraudulent activity on some US payment cards that had been used at Michaels, suggesting we may have experienced a data security attack," said Michaels CEO Chuck Rubin in a statement Friday.

"Although the investigation is ongoing, based on the information we have received and in light of the widely reported criminal efforts to penetrate the data systems of US retailers, we believe it is appropriate to notify our customers that a potential issue may have occurred," he added. The company also posted a link to the statement -- "Important Notice About Certain Customer Payment Card Information" -- at the top of its website's homepage.

Michaels' statement came just hours after security journalist Brian Krebs first reported that multiple sources in the banking industry said elevated levels of fraud were traced to the accounts of people who shopped at the retailer.

[Are retailers trying to shift the blame? See why one commentator says Target Mocks, Not Helps, Its Data Breach Victims.]

So far, however, Michaels has yet to offer any breach-related details, such as attack timing or the number of cards that may have been compromised. But the retailer did say Friday that it's brought in third-party digital forensic investigators, continues to work with law enforcement agencies, will offer regular updates about the investigation on the Michaels website, and will extend ID theft monitoring to anyone who was affected. "If we find as part of our investigation that any of our customers were affected, we will offer identity protection and credit monitoring services to them at no cost," Rubin said.

Michaels operates more than 1,250 stores in the United States and Canada -- some under the Aaron Brothers name -- and appears to have quickly gone into damage-control mode. Notably, the retailer Saturday began offering a seven-day "40% off any one regular price item" promotion. That fast response could relate to the company's plans to go public this year. According to a related document filed in December with the Securities and Exchange Commission, the retailer booked $4.4 billion in 2012 revenue.

The apparent Michaels breach suggests that the retailer is the latest victim of hackers wielding memory-scraping point-of-sale (POS) malware. Previous victims have included Target, Neiman Marcus, and a handful of other retailers that have yet to disclose that they were breached.

How bad have those breaches been? For starters, the Target breach resulted in the theft of 40 million credit and debit cards used by shoppers in Target's retail stores, as well as personal information on 70 million Target customers. Meanwhile, Neiman Marcus disclosed Thursday that 1.1 million credit and debit cards -- though not PIN codes -- were compromised by hackers during a three-month attack. Those cards were all used by shoppers in its Neiman Marcus and Last Call stores. To date, Discover, MasterCard, and Visa have reported seeing about 2,400 of the stolen payment cards being used for fraudulent purchases.

In the past 10 months, US-CERT, which is part of the Department of Homeland Security, has published three security advisories warning retailers about the increasing threat of POS-malware attacks, as well as how to protect themselves.

In other data breach news, Coca-Cola disclosed Friday that a laptop stolen by a former employee contained personal information -- including social security and driver's license numbers -- on 74,000 current and former employees in North America, including information on about 4,500 contractors and vendors.

Unlike the breaches at Target and Neiman Marcus, however, Coke said its data breach occurred after a former employee stole 55 company laptops over a six-year period. Coke said it recovered the laptops in November and December and began reviewing the 200,000 files collectively stored on the machines for signs of personal information.

Coke found that the exposed personal information had been stored on the laptops in unencrypted form, thus in violation of Coke's data-encryption security policies. The company told The Wall Street Journal that it notified people who were affected by the breach within 45 days, which is the time limit set by states with the most stringent data breach laws.

Mathew Schwartz is a freelance writer, editor, and photographer, as well the InformationWeek information security reporter.

Having a wealth of data is a good thing -- if you can make sense of it. Most companies are challenged with aggregating and analyzing the plethora of data being generated by their security applications and devices. This Dark Reading report, How Existing Security Data Can Help ID Potential Attacks, recommends how to effectively leverage security data in order to make informed decisions and spot areas of vulnerability. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mathew
50%
50%
Mathew,
User Rank: Apprentice
1/29/2014 | 11:30:31 AM
Re: Promising Career Path

Wait for it, wait for it: Michaels sued over possible data breach.

And yes, "digital forensic investigator" looks like an already hot job prospect that's just going to keep getting hotter.

BobH088
50%
50%
BobH088,
User Rank: Apprentice
1/28/2014 | 1:24:40 PM
data loss
One of the most common causes of data getting in the wrong hands is the loss of mobile devices that often contain a frightening amount of private information. I want to share a protection option that worked for me. Tracer tags let someone who finds your lost stuff contact you directly without exposing your private information.  I use them on almost everything I take when I travel after one of the tags was responsible for getting my lost laptop returned to me in Rome one time. You can get them at mystufflostandfound.com
Ariella
50%
50%
Ariella,
User Rank: Apprentice
1/27/2014 | 3:34:30 PM
Re: Killing debits
@Lorna even before all these huge breaches made the headlines, I was warned that debit cards are not very secure. The only time I ever used one for purchase was by mistake -- the chashier must have entered debit as a default.
D. Henschen
50%
50%
D. Henschen,
User Rank: Apprentice
1/27/2014 | 2:14:01 PM
Promising Career Path
Looking for a promising career path related to the growth of big data and online transactions? Try "digital forensic investigator," as mentioned above. I'm guessing this is a white-hot niche within the already hot, larger category of computer security.
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
1/27/2014 | 12:44:35 PM
Killing debits
At what point does all this breach news kill the willingness of consumers to enter PIN numbers to use debit cards? I never have done so, and just recently advised several family members to stop using debit.

That will cost banks and retailers -- and ultimately consumers -- money as CCs become the only game in town.  
Stop Defending Everything
Kevin Kurzawa, Senior Information Security Auditor,  2/12/2020
Small Business Security: 5 Tips on How and Where to Start
Mike Puglia, Chief Strategy Officer at Kaseya,  2/13/2020
5 Common Errors That Allow Attackers to Go Undetected
Matt Middleton-Leal, General Manager and Chief Security Strategist, Netwrix,  2/12/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20477
PUBLISHED: 2020-02-19
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
CVE-2019-20478
PUBLISHED: 2020-02-19
In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.
CVE-2011-2054
PUBLISHED: 2020-02-19
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper in...
CVE-2015-0749
PUBLISHED: 2020-02-19
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker ...
CVE-2015-9543
PUBLISHED: 2020-02-19
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is rel...