Target hackers reportedly used credentials stolen from ventilation contractor
KrebsOnSecurity: Feds probing theft of 40 million payment cards call on HVAC firm.
The hackers who broke into Target's corporate network and made off with payment card data for 40 million of its customers gained entry using authentication credentials stolen from a heating, ventilation, and air-conditioning (HVAC) subcontractor that has done work for a variety of other large retailers, according to a report published Wednesday by KrebsOnSecurity.
Reporter Brian Krebs writes:
Wednesday's post reports several newly available details, including a timeline of the attack. The attackers, Krebs says, spent about 13 days uploading their card-stealing malware to a small number of point-of-sale terminals within Target stores to make sure it worked as designed. They then pushed the malicious software to a majority of Target's cash registers and actively collected card records captured from live customer transactions.
The report provides other details, including an estimate from one analyst that Target may face losses as high as $420 million as a result of the breach.
Be sure to read the comments on this article here:
http://arstechnica.com/security/2014/02/target-hackers-reportedly-used-credentials-stolen-from-ventilation-contractor/?comments=1&post=26179111#comment-26179111
http://arstechnica.com/security/2014/02/target-hackers-reportedly-used-credentials-stolen-from-ventilation-contractor/?comments=1&post=26179111#comment-26179111
No comments:
Post a Comment