Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

steve2470

(37,457 posts)
Thu Feb 6, 2014, 11:31 PM Feb 2014

Hackers accessed Target's network using credentials stolen from a contractor

http://www.theverge.com/2014/2/5/5383338/target-hackers-accessed-retailers-network-with-stolen-contractor-credentials

Customers might have to be worried about another range of companies thanks to the Target credit card security breach. The retailer reported that the initial intrusion into its network was traced back to credentials stolen from Fazio Mechanical Services, a refrigeration, heating, and air conditioning company hired by Target. Hackers used the stolen credentials between November 15th and November 28th to upload card-stealing malware to many of Target's cash registers, and within a month, completely infiltrate the system.

Krebs on Security explains that Fazio Mechanical could have had access to Target's network for maintenance purposes. It's common practice for large companies to hire teams to monitor energy consumption in stores to help save on energy costs. Those teams need to have remote access to the company's network, so that is one way the HVAC company could have had long-term access to Target's system.

However, that does not explain why the retailer's maintenance network led the hackers to its payment network. It's possible that Target had the maintenance and payment networks connected, making it easy for hackers to access one from the other. But Krebs alluded to an even more unsettling scenario — the networks could have been separated from the start, but the hackers found a way to connect them.

Fazio Mechanical president Ross Fazio confirmed that the US Secret Service — which has not been shy about its investigation — has visited the company's offices while investigating the Target breach. It makes sense for the Department of Justice to take a hard look at Fazio: the HVAC contractor has completed projects for Trader Joe’s, Whole Foods, BJ’s Wholesale Club, and others, suggesting those companies could be susceptible to similar attacks. While the identities of the hackers are still unknown, this discovery shows how even the most tangental connection to a huge company like Target could open the door for hackers to access information. Target is now rushing to install chip-enabled smart cards to provide better security at the point of sale, but it can only try to control what happens in its stores.

*bolding mine*
9 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Hackers accessed Target's network using credentials stolen from a contractor (Original Post) steve2470 Feb 2014 OP
I was fortunate with Target, BUT this could put me off using credit or debit cards at all. hedda_foil Feb 2014 #1
This could be solved easily and permanently Orrex Feb 2014 #2
Trader Joe's? I use my debit card there all the time. cui bono Feb 2014 #3
Have these idiots never heard of a VLAN? Xithras Feb 2014 #4
It's just not a pretty picture, is it? bemildred Feb 2014 #5
I went to Target yesterday and paid cash. ananda Feb 2014 #6
The underlying problem, though dickthegrouch Feb 2014 #7
kick nt steve2470 Feb 2014 #8
Got the Target email, had my cards reissued, did security freeze at all 3 credit bureaus and DeschutesRiver Feb 2014 #9

hedda_foil

(16,375 posts)
1. I was fortunate with Target, BUT this could put me off using credit or debit cards at all.
Fri Feb 7, 2014, 12:10 AM
Feb 2014

I don't have a Target card, and I'd just received a $50 VISA prepaid card from switching my cable/net/phone package, so I maxed that out to buy a couple of gifts there. Ordinarily, I would have used my debit card, so I felt I'd gotten a lucky break. But I think I'll stick to cash for awhile.

Orrex

(63,216 posts)
2. This could be solved easily and permanently
Fri Feb 7, 2014, 12:17 AM
Feb 2014

Simply fine the vendor and retailer $100,000 per compromised card. I'll bet that they come up with some impenetrable security measures within the hour.

Xithras

(16,191 posts)
4. Have these idiots never heard of a VLAN?
Fri Feb 7, 2014, 03:03 AM
Feb 2014

They run their AC system on the same network as their registers? What a stupid, amateur mistake.

bemildred

(90,061 posts)
5. It's just not a pretty picture, is it?
Fri Feb 7, 2014, 08:28 AM
Feb 2014

This is why I avoid debit cards. You have more protection from this sort of random attack with credit cards.

dickthegrouch

(3,175 posts)
7. The underlying problem, though
Fri Feb 7, 2014, 02:17 PM
Feb 2014

Is that users are encouraged to link all their accounts through that bastion of privacy and security: Facebook

I can't tell you how many times I've been unable to take advantage of an offer or even play some games because they require access to your Facebook credentials.

Even LinkedIn does some of this. I will never join two of my accounts together in this way (alright the whole bloody lot are joined through my service providers).

I don't recommend anyone join their Facebook to their bank account or their iPhone bridge game or anything remotely similar.

DeschutesRiver

(2,354 posts)
9. Got the Target email, had my cards reissued, did security freeze at all 3 credit bureaus and
Sat Feb 8, 2014, 10:57 PM
Feb 2014

have been using cash when I go to town for errands and gas. Strengthened all passwords on everything I can find, new email, etc.

But I did pay our business registration fee online to the State of Oregon the last week of January, figuring what could go wrong with that one, right? Well, I just read that the system was hacked around Feb 5. They don't think the credit card info was compromised but we will see.

http://www.katu.com/politics/Oregon-secretary-of-states-website-hacked-office-says-243868591.html?mobile=y

This is making me extremely cranky, in large part now because I am not sure what else to do except turn completely to cash for everything this year until things settle or the banks get chip cards faster than originally planned, though not even those will be safe for long. It will be highly impractical to keep getting credit cards reissued if every time I use one, there is a subsequent hack of the system.

Latest Discussions»General Discussion»Hackers accessed Target's...