国产热热热精品,亚洲视频久久】日韩,三级婷婷在线久久,99人妻精品视频,精品九热人人肉肉在线,AV东京热一区二区,91po在线视频观看,久久激情宗合,青青草黄色手机视频

Make me your Homepage
left corner left corner
China Daily Website

More well-known US retailers victims of cyber attacks

Updated: 2014-01-12 15:55
( Agencies)

BOSTON/WASHINGTON - Target Corp and Neiman Marcus are not the only US retailers whose networks were breached over the holiday shopping season last year, according to sources familiar with attacks on other merchants that have yet to be publicly disclosed.

Smaller breaches on at least three other well-known US retailers took place and were conducted using similar techniques as the one on Target, according to the people familiar with the attacks. Those breaches have yet to come to light. Also, similar breaches may have occurred earlier last year.

The sources said that they involved retailers with outlets in malls, but declined to elaborate. They also said that while they suspect the perpetrators may be the same as those who launched the Target attack, they cannot be sure because they are still trying to find the culprits behind all of the security breaches.

Law enforcement sources have said they suspect the ring leaders are from Eastern Europe, which is where most big cyber crime cases have been hatched over the past decade.

Only one well-known retailer, Neiman Marcus, has said that they too have been victim of a cyber attack since Target's December 19 disclosure that some 40 million payment card numbers had been stolen in a cyber attack. On Friday, Target said the data breach was worse than initially thought.

An investigation found that hackers stole the personal information of at least 70 million customers, including names, mailing addresses, telephone numbers and email addresses. Neiman Marcus said it was not sure if the breach was related to the Target incident.

Most states have laws that require companies to contact customers when certain personal information is compromised. In many cases the task of notification falls on the credit card issuer.

Merchants are required to report breaches of personal information including social security numbers. It was not immediately clear if that was the case with the retailers who were attacked around the same time as Target.

The Secret Service and Department of Justice, which are investigating the Target breach, declined to comment on Saturday.

SCRAPING MEMORY

Target has not disclosed how the attackers managed to breach its network or siphon off some of its most sensitive data.

The sources who spoke to Reuters about the breaches said that investigators believe the attackers used similar techniques and pieces of malicious software to steal data from Target and other retailers.

One of the pieces of malware they used was something known as a RAM scraper, or memory-parsing software, which enables cyber criminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text, the sources said.

While the technology has been around for many years, its use has increased in recent years as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.

Visa Inc issued two alerts last year about a surge in cyber attacks on retailers that specifically warned about the threat from memory parsing malware.

The alerts, published in April and August, provided retailers with technical details on how the attacks were launched and advice on thwarting them.

A Visa spokeswoman declined comment on the reports, which did not identify specific victims.

It was not clear whether Target's security team had implemented the measures that Visa had recommended to mitigate the risks of being attacked.

Yet a law enforcement source familiar with the breach said that even if the retailer had implemented those steps, the efforts may not have succeeded in stopping the attack.

That is because the attackers were more sophisticated than the ones in the previous attacks described in the Visa alerts, according to the source. The source asked not to be identified because they were not authorized to discuss the matter publicly.

Previous Page 1 2 Next Page

 
...
旬邑县| 汉沽区| 长宁县| 沂水县| 吴江市| 青海省| 贡嘎县| 连江县| 渭源县| 招远市| 拜城县| 吉水县| 湘西| 灵山县| 江城| 丰城市| 隆昌县| 莆田市| 德钦县| 卢龙县| 丹阳市| 兴文县| 博乐市| 二连浩特市| 沙湾县| 塔河县| 永顺县| 仪陇县| 鲁甸县| 丰宁| 兴化市| 商丘市| 兴文县| 镇坪县| 西乌| 辽源市| 虞城县| 湘乡市| 阳江市| 江津市| 琼海市|