Kmart stores hit by data breach

Published October 12, 2014

NEW YORK: Sears Hol­dings Corp said it was the victim of a cyber-attack that likely resulted in the theft of some customer payment cards at its Kmart stores, the latest in a series of computer security breaches to hit US companies and dealing a fresh blow to the struggling US retailer.

The US Secret Service confirmed it was investigating the breach, which occurred in September and compromised the systems of Kmart, which has about 1,200 stores across the United States. The breach did not affect the Sears department store chain.

A Sears spokesman said he could not say how many credit and debit card numbers had been taken. He added that the personal information, debit card PIN numbers, email addresses and Social Security numbers of its customers remained safe.

Security professionals said they were not surprised to learn that yet another major retailer was reporting a breach, adding they believe many big merchants do not have adequate systems for detecting cyber-attacks, which means they still remain easy prey for hackers.

“This is going to continue indefinitely until people change their practices,” said Shawn Henry, a former senior cyber cop with the FBI who is now of the president of cyber forensics firm CrowdStrike Services.

He said that hackers are able to get into networks beca­use they are “so broad and vast” that attackers will always find a way in. Retailers need to do a better job of quickly detecting them before they begin to steal data, he said.

Sears said that the attackers used malicious software that was undetectable using anti-virus software, highligh­ting the challenge of keeping up with the evolving techniques of computer hackers.

Company spokesman Chris Brathwaite said Sears had been upgrading its systems even before the recent spate of incidents involving retailers, which included a massive breach of the systems of Target Corp in late 2013.

“Our IT team was able to quickly remove the malware and we are deploying further advanced software to protect our customers’ information,” Brathwaite said.

Security experts say retailers have traditionally not invested enough in security, partly because of the industry’s relatively thin profit margins.

The breach comes as Sears is struggling to revive itself under Chief Executive Eddie Lampert, who has been closing stores and slashing costs to try to return to profitability. Critics say Lampert has been investing too little in the Sears and Kmart stores, contributing to nine straight quarterly losses.

Tom Kellermann, chief cyber-security officer with security software maker Trend Micro, said that retailers need to be prepared to deal with malicious software crafted specifically for the purposes of burglarising retailers.

Kmart apologised to its customers on Friday and said it was working with federal authorities, banking partners and security firms in the probe.

Published in Dawn, October 12th, 2014

Opinion

Editorial

Positive overtures
Updated 06 Sep, 2024

Positive overtures

It is hoped politicians refusing to frame Balochistan’s problems in black and white is taken as a positive overture by the province's people.
Capital poll delay
06 Sep, 2024

Capital poll delay

THE ECP has cancelled the local government elections in Islamabad for the third time subsequent to a recent ...
Perks galore
06 Sep, 2024

Perks galore

A parasitic bureaucracy still upholds colonial customs whereby a struggling citizenry and flood victims are subservient to status.
Fragile stability
Updated 05 Sep, 2024

Fragile stability

The only way forward towards long-term economic stability lies in broadening tax revenue base, increasing and diversifying exports, and attracting FDI.
Baloch voices
05 Sep, 2024

Baloch voices

AKHTAR Mengal, one of the most prominent voices from Balochistan in parliament, has nothing left to say. On Tuesday,...
Mpox alarm
05 Sep, 2024

Mpox alarm

PAKISTAN must take timely action before it ends up with a cluster of mpox cases. Our authorities would do well to...