<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: canton]]></title>
    <link>http://securityratty.com/tag/canton</link>
    <description></description>
    <pubDate>Sat, 26 Apr 2008 17:01:56 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hundreds of WiseBuys customers are victims of credit card fraud]]></title>
      <link>http://securityratty.com/article/6a6e2e458675a57e767b333a17041140</link>
      <guid>http://securityratty.com/article/6a6e2e458675a57e767b333a17041140</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/24/08

Organization
WiseBuys Stores, Inc

Contractor/Consultant/Branch
WiseBuys of Canton

WiseBuys Plaza, 5533 US Highway 11, Canton, NY 13617,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wisebuys.jpg" align="right" height="52" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/24/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.wisebuysstores.com/index.php">WiseBuys Stores, Inc.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.wisebuysstores.com/locations.php">WiseBuys of Canton</a> <br><br><font size="1">WiseBuys Plaza, 5533 US Highway 11, Canton, NY 13617, 315.379.0456</font><br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>"hundreds"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"credit and debit card numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Hundreds of credit and debit card numbers were stolen in December at the Canton Wisebuys store, according to Canton Village Police."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.watertowndailytimes.com/article/20080425/NEWS05/133127784">Watertown Daily News</a> <br><a href="http://www.newswatch50.com/news/local/story.aspx?content_id=af161116-25f2-4a78-ab2e-c730e28cc4bb">WWTI Channel 50 News</a> <br><a href="http://news10now.com/content/all_news/114840/credit-card-numbers-stolen-from-canton-wisebuys/Default.aspx">TWEAN News Channel of Syracuse</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>WWTI Channel 50 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>CANTON — Police are investigating hundreds of reports of thefts of credit and debit card numbers belonging to customers who shopped at WiseBuys department store in December.<br><br>"We have had hundreds of victims and thousands of thefts. We have had amounts as high as $3,000 and as low as $10," said Sgt. Lori A. McDougal of the village police department. "I would say at this point they total upwards of $100,000."<br><br>Victims are all believed to have shopped at the Canton WiseBuys store between Dec. 5 and 20<br><br>Since then, stolen credit card numbers have been used to create fake cards in New York City.<br><br>The fraudulent cards were used to pay for taxi rides, to buy food at a Wendy's Restaurant and to make purchases at New York City drug stores and other locations.<br><br>"We had the New York City police call us about one of our cards that was picked up in a sting," said Scott A. Wilson, president and chief executive officer of SeaComm Federal Credit Union, which has a branch in Canton.<br><br>Complaints about the thefts began to come in early in March as victims received their monthly bank and credit card statements<br><br>"At this point we are not sure how the numbers were obtained. It may be an employee or it may be somebody who hacked into their system," Ms. McDougal said.<br><br>Hannaford Bros., which operates supermarkets in the Northeast including stores in Watertown and Massena, reported the theft of up to 4.2 million credit and debit card numbers from 300 of its stores in March.<br><span style="font-style: italic;">[Evan] I think Watertown, NY is ~60 miles from Canton, and Massena is ~30 miles away.</span><br><br>It is unknown if there is any similarity between the Hannaford thefts and the WiseBuys thefts.<br><span style="font-style: italic;">[Evan] I certainly don't know enough to speculate (but I will later <img src="http://breachblog.com/emoticons/wink.png" border="0" />).</span><br><br>"We have people working on it," said Norman V. Garrelts, chief executive officer of Hacketts, which took over operation of WiseBuys after a November merger.<br><br>"We had no inkling it was going on. The police notified us," he said. "How anybody could have hacked into the system, I am not a big enough geek to know. It happened over a day or two."<br><span style="font-style: italic;">[Evan] I think there are many organizations that have "no inkling".&nbsp; CEOs like Mr. Garrelts don't need to be "a big enough geek" to know how the companies they run are managing information security.&nbsp; CEOs are the ones that are ultimately responsible.&nbsp; Information security should be governed in such a way that it has visibility with the CEO.&nbsp; Information security is an organizational issue, <span style="font-weight: bold;">NOT </span>an IT (or geek) issue.</span><br><br>"We have rechecked all of our safeguards and everything seems to be in order," Mr. Garrelts said. "It should not have been able to happen."<br><span style="font-style: italic;">[Evan] This incident is proof of the contrary.&nbsp; I agree that it should not have been able to happen, but it <span style="font-weight: bold;">DID </span>happen.&nbsp; The question is what is the "it"?</span><br><br>The Canton store was the only one in the WiseBuys and Hacketts chain that was affected by the number thefts. The stores use the credit card processing system used by nearly every True Value hardware store in the nation, Mr. Garrelts said.<br><br>WiseBuys changed its computer system in December and investigators are attempting to determine whether that was when the numbers were stolen<br><br>Village police have begun interviewing about 30 WiseBuys employees but so far have not identified any as suspects.<br><br>District Attorney Nicole M. Duvé, who learned of the thefts Thursday, said she takes the thefts seriously.<br><br>"This is starting to eat up a lot of law enforcement time and a lot of our time. I intend to take a very dim view of anybody caught doing it," she said.<br><span style="font-style: italic;">[Evan] I wonder what the ultimate cost of incidents like this really is.&nbsp; Law enforcement time, employee time, bank and credit issuer time, victim time, actual fraud dollar amounts, prosecutorial time, etc. etc.&nbsp; It all ends up, and somebody has to pay for it all, right?</span><br><br>Debit and credit card issuers believed to have been affected by the thefts to date include Community Bank N.A., SeaComm Federal Credit Union, Key Bank, Discover Card, Capital One and NBT Bank, Ms. McDougal said.<br><br>"As far as I know, all of the banks have been cooperating with their customers and all have been reimbursed by their banks or credit card companies," she said.<br><br>"We have a zero loss policy," said Mr. Wilson, of SeaComm Federal in Massena. Under the policy, the credit union absorbs any losses caused by fraud.<br><br>In all, 42 credit union members were among those whose numbers were stolen. All were issued new numbers and cards.<br><br><span style="font-weight: bold;">Commentary:</span><br>I don't get a good feeling about this one.&nbsp; Too many unanswered questions.&nbsp; Nobody seems to know very much.&nbsp; There has been no official public response by WiseBuys.<br><br>NOT FACT, only speculation:<br>I like to speculate, so what the heck I'll throw something out there.&nbsp; I'm going to say that full magnetic stripe data was captured during data transmission and that this is not an inside job.&nbsp; I am also going to say that this was not related to the Hannaford breach.&nbsp; I didn't exactly go out on a limb with my speculation, but I did speculate nonetheless. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/26/wisebuys.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 26 Apr 2008 17:01:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/wisebuys">wisebuys</category>
      <category domain="http://securityratty.com/tag/credit union">credit union</category>
      <category domain="http://securityratty.com/tag/credit union absorbs">credit union absorbs</category>
      <category domain="http://securityratty.com/tag/credit issuer time">credit issuer time</category>
      <category domain="http://securityratty.com/tag/canton wisebuys store">canton wisebuys store</category>
      <category domain="http://securityratty.com/tag/report credit">report credit</category>
      <category domain="http://securityratty.com/tag/credit card companies">credit card companies</category>
      <source url="http://breachblog.com/2008/04/26/wisebuys.aspx">Hundreds of WiseBuys customers are victims of credit card fraud</source>
    </item>
  </channel>
</rss>
