|
|
Printer
Friendly Version
Email
Story
Increase
Text
Decrease
Text
iPod Friendly
Comments
|
Illicit software placed on Hannaford servers blamed for breach
Associated Press
Friday, March 28, 2008
PORTLAND – Unauthorized software that was secretly installed on servers in nearly all of Hannaford Bros. Co.'s supermarkets paved the way for a massive data breach that compromised up to 4.2 million credit and debit cards, the company said Friday.
The Scarborough-based grocer confirmed a report in the Boston Globe that it told Massachusetts regulators this week about the link to the illicit computer program known as "malware."
The company doesn't know if the malware – industry shorthand for malicious software – was downloaded to the servers from a remote location or at each of the nearly 300 stores, Hannaford spokeswoman Carol Eleazer said.
"Virtually everything is possible," she said. "There are still many, many aspects that we don't totally understand."
The company has said that the data theft, which occurred between Dec. 7 and March 10, took place as shoppers swiped their cards at checkout line machines and the information was transmitted to banks for approval.
The malware installation was revealed in a letter from Hannaford general counsel Emily Dickinson to Massachusetts Attorney General Martha Coakley and Gov. Deval Patrick's Office of Consumer Affairs and Business Regulation. Eleazer declined to release a copy, saying it was an attorney-to-attorney communication that was intended to be private.
The involvement of the software was not new information but rather "a level of detail that we've not shared previously because of the confidential nature of the investigation," she said. The breach remains under investigation by the U.S. Secret Service.
The software was installed in all Hannaford stores in New England and New York, and in most of the company's affiliated Sweetbay stores in Florida, Eleazer said.
At least 1,800 cases of fraud have been linked to the data breach, with unauthorized charges showing up as far afield as Mexico, Italy and Bulgaria.
The breach has prompted concern in the industry because it appeared to be the first large-scale theft of credit and debit card numbers while the information was in transit. The usual mode of attack targets data sitting in databases, as in the record-setting theft of information from Massachusetts-based TJX Cos. involving least 45 million cards.
Even while the Hannaford hack was still going on last month, the company was found to be in compliance with security standards required by the Payment Card Industry, a coalition founded by credit card companies.
Hannaford has declined to discuss specifics of its security system or spell out the extent to which its stores encrpyt payment data throughout the transmission process. |
CLICK HERE To Show/Hide Discussion Thread - (1 Comment)
Comments
 |
Posted By:dr. dosh at March 29, 2008 12:21 AM (Suggest Removal) Malware, sniffers , trojans & why do i use a Mac® ? Heads are gonna' roll in China • *<=)
| Add your comments
|
|
Advertisement

|
 |
| CMHVI and AHA Restaurant Event - May 12 thru 17 |
In celebration of its fifth anniversary, the Central Maine Heart and Vascular Institute is partnering with Lewiston-Auburn area restaurants to present “A Taste of the Twin Cities”, a fund-raiser for the American Heart Association that will feature heart h |
read more >>
|
| Making A Difference Commemorative Quilt |
In celebration of its fifth anniversary, the Central Maine Heart and
Vascular Institute is sponsoring the creation of a Making A Difference Commemorative Quilt to recognize those with or those who have had heart disease. |
read more >>
|
| “Growing Through Cancer: Your Personal Toolkit” |
is the theme of a multipart
workshop series being presented by the Patrick Dempsey Center for Cancer
Hope and Healing at Central Maine Medical Center. |
read more >>
|
| Ann E. Traynor, M.D |
a medical hematologist and oncologist, has been appointed to the Central Maine Medical Center Medical Staff. She is practicing with Hematology-Oncology Associates in Lewiston. |
read more >>
|
|
|