The Breach: Target and the Forty Million
On Monday, the biggest retail story of the holiday season is not the shopping, and it is the theft. Target, one of the largest retailers in the United States, confirmed last Thursday that hackers had stolen the credit and debit card data of about forty million shoppers, and the theft happened during the biggest shopping weeks of the year. The breach is the December 2013 story, and the story is the lesson: the security of a company is only as strong as the system it fails to watch.
The Breach is the subject of this article: how the theft happened, when it happened, what Target knew and when, and what it means for every company that touches a payment card. The company disclosed the breach on Thursday, December 19, and the disclosure came four days after the intrusion was discovered. This is the story of the breach, and the story is about the moment the holiday shopping season became a security lesson.
1. The Disclosure
The disclosure came on a Thursday, and the timing made the story worse. Target announced that criminals had stolen data from about forty million credit and debit card accounts, and the theft had happened between November 27 and December 15, the exact window of Black Friday and the height of the holiday shopping season. The company said it had discovered the intrusion on December 15, with the help of federal authorities and a security firm, and that it was working around the clock to address the problem.
The disclosure was the first public word, and the first public word was a flood of questions. The customers who had swiped their cards at Target during the busiest weeks of the year were now the customers whose data might be in the hands of criminals. The banks were reissuing cards, the news was full of advice, and the company was facing the biggest retail data breach in American history. The disclosure was the beginning, and the beginning was the nightmare.
2. The Window
The window of the theft was the detail that made the breach personal, and the detail was the holiday season. The attackers had access to Target's point of sale systems from late November through mid December, the weeks when the stores were full, the lines were long, and the registers were ringing. Every swipe of a card in those weeks was a swipe through a compromised system, and the compromised system captured the data from the magnetic stripe: the card number, the expiration date, and the security code.
The window was also the reason the damage was so large. The holiday season was the busiest time of the year for the retailer, and the busiest time was the time the attackers chose. The stolen data was already appearing for sale on the black markets of the internet, and the markets were the proof that the theft was professional. The window was the scale, and the scale was the horror.
3. The Malware
The malware was the mechanism of the theft, and the mechanism was the story that the security experts would tell. The attackers had infected Target's point of sale systems with software that captured the card data as it was swiped, and the captured data was sent out of the network to the criminals. The malware was the tool of the modern bank robber: no masks, no guns, no vault, just code that read the cards as they passed through the register.
The malware was also the proof of the professionalization of crime. The attack had the hallmarks of a sophisticated operation: the malware was designed to be stealthy, the data was exfiltrated in a way that avoided detection, and the operation ran for weeks without being noticed by the company. The malware was the weapon, and the weapon was the lesson: the criminals had learned to attack the systems that the companies had stopped watching.
4. The Discovery
The discovery was the detail that would haunt the company, and the detail was the delay. Target said it learned of the intrusion on December 15, and the disclosure came on December 19, and the theft had been running since November 27. The weeks of silence were the weeks when the data was flowing out, and the silence was the gap between the attack and the awareness. The company's security systems had been in place, and the systems had not caught the theft.
The discovery also raised the question that every company would face in the aftermath: how long does it take to know you have been robbed? The answer, in this case, was almost three weeks, and the answer was the lesson. The company that had invested in security, that had a security team, that had the resources of a retail giant, had still missed the theft for weeks. The discovery was the delay, and the delay was the failure.
5. The Apology
The apology came from the chief executive, and the apology was the human face of the crisis. Gregg Steinhafel, the CEO of Target, appeared in a video and a statement, apologizing to the customers and promising to make things right. The company offered free credit monitoring to the affected customers, and it said it was working with the banks and the authorities. The apology was the beginning of the response, and the response was the test.
The apology was also the first step in the long recovery. The customers were angry, the trust was shaken, and the holiday season had been poisoned. The company that had built its brand on the friendly shopping experience was now the company that had lost the data of forty million customers. The apology was the acknowledgment, and the acknowledgment was the beginning of the rebuilding. The apology was the words, and the words would need to be backed by actions.
6. The Market
The market's reaction was the scoreboard of the crisis, and the scoreboard was red. Target's shares fell about eleven percent in the days after the disclosure, wiping out billions of dollars in market value. The fall was the market's estimate of the damage: the cost of the response, the cost of the lawsuits, the cost of the lost trust, and the cost of the holiday season that would not come back.
The market was also the measure of the uncertainty. The company did not know the full scope of the theft, the customers did not know if their data was safe, and the investors did not know the final bill. The uncertainty was the enemy, and the enemy was reflected in the share price. The market was the judgment, and the judgment was the damage.
7. The Lesson
The lesson of the breach was about the systems that companies stop watching, and the lesson was the malware. Target had firewalls, and the attackers went around them; it had security software, and the malware hid from it; it had a network, and the network was the highway for the stolen data. The company had built defenses at the perimeter, and the attackers had moved inside, and the inside was where the cards were swiped.
The lesson was also about the difference between compliance and security. The company had passed the audits, had met the standards, had done what the industry required, and the requirements had not stopped the theft. The criminals did not care about the standards; they cared about the cards, and the cards were flowing through the registers. The lesson was that security is not a checklist and is a practice, and the practice was the gap.
8. The Future
The future of the story would be written in the months ahead, and the future was the aftermath. The investigators would trace the attack, the lawyers would file the lawsuits, and the customers would decide whether to trust the store again. The company would rebuild its security, would change its systems, would promise to do better, and the promises would be tested by the next attempt. The future was the recovery, and the recovery was the test.
The future was also the lesson in the making. The breach would be studied by every company that touched a payment card, and the study would change the industry. The banks would push for new cards with chips, the retailers would harden their systems, and the security teams would watch the point of sale. The breach is the December 2013 story, and the story is the lesson: the security of a company is only as strong as the system it fails to watch. The cards were swiped, the data was stolen, and the watching began after the theft. The future of security starts with the forty million. The customers who shopped in the weeks of the theft are the reminders of the cost, and the reminders are the motivation. The company that rebuilds the trust will do it with time, with transparency, and with the systems that watch the places the thieves entered. The watching is the work, and the work is the future. The banks are reissuing the cards, and the customers are watching the statements, and the watching is the price of the breach. The company that rebuilds the trust will do it with time, with transparency, and with the systems that watch the places the thieves entered. The watching is the work, and the work is the future, and the future is the lesson in the making.
Tags
#engineering #technology
Comments
No comments yet. Be the first!
Leave a comment