Target: The data breach before the confirmation
Summary
Before Target’s public confirmation, Brian Krebs reports on card data stolen on a massive scale and shows the value of independent sources during ongoing security incidents. Target confirmed up to 40 million affected card accounts the following day. The confirmed attack window ran from 27 November to 15 December.
Ideas
- Fraud patterns at card issuers can reveal a data breach that has not yet been confirmed.
- Magnetic stripe data allows working card copies to be made.
- A growing incident window continuously changes damage estimates and the scope of the response.
- Several independent sources increase the reliability of early reports.
- Underground markets provide indirect evidence of the scale and origin of stolen data.
- Public communication often lags behind technical and financial indicators.
Insights
- Security incidents often first become measurable outside the affected company.
- Payment ecosystems spread detection, damage and responsibility across different organisations.
- Early reporting must preserve speed and documented uncertainty at the same time.
Quotes
The breach window is definitely expanding.
– anonymous fraud analyst at a major US bank
Habits
- Krebs cross-checks tips from several card issuers and explicitly marks unknown quantities.
Facts
- The early report concerned purchases in stores and not Target’s online shop.
References
- Brian Krebs: Sources: Target Investigating Data Breach
- Target Corporation: later confirmation and investigation of the incident.
Critique
- The first report could not yet conclusively prove the cause, the full scale or the perpetrators.
- Anonymous sources make it harder for readers to judge for themselves how close they are to the incident.
Remarks
- The report was quickly corroborated by Target’s confirmation the next morning.
- Later articles reconstructed the supplier access, malware and card sales in more detail.
Recommendations
- Payment service providers should correlate anomalies across company boundaries early on.
- Restrict supplier access technically and monitor its use continuously.
- Keep confirmed facts and preliminary assumptions apart in every situation report.
Links to the original source and the Web Archive open in a new tab.