<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sweetbay]]></title>
    <link>http://securityratty.com/tag/sweetbay</link>
    <description></description>
    <pubDate>Sun, 16 Mar 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Hannaford and Sweetbay supermarkets announce compromise of 4.2 million credit and debit cards]]></title>
      <link>http://securityratty.com/article/c1b967b003725194a9e1a04d3dc456b8</link>
      <guid>http://securityratty.com/article/c1b967b003725194a9e1a04d3dc456b8</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/17/08

Organization
Delhaize Group

Contractor/Consultant/Branch
Hannaford Bros. Co
Sweetbay Supermarket

Victims
Customers of Hannaford stores,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/hannaford.jpg" align="right" height="200" width="157"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/17/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.delhaizegroup.com/TopSectionPages/Home/tabid/152/language/en-US/Default.aspx">Delhaize Group</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.hannaford.com/home.shtml">Hannaford Bros. Co</a> <br><a href="http://www.sweetbaysupermarket.com/">Sweetbay Supermarket</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Customers of Hannaford stores, Sweetbay stores in Florida and certain independently-owned retail locations in the Northeast that carry Hannaford products.<br><br><span style="font-weight: bold;">Number Affected:</span><br>4,200,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Credit card and debit card information<br><br><span style="font-weight: bold;">Breach Description:</span><br>"New England grocery chain Hannaford Brothers says a security breach has exposed 4.2 million customer credit- and debit-card numbers to scammers, with 1,800 fraud cases already reported."&nbsp; Anyone who used a credit or debit card between December 7, 2007 and March 10, 2008 at any one of the 165 Hannaford stores in the Northeast or 106 Sweetbay stores in Florida is a potential victim of this breach.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.hannaford.com/Contents/News_Events/News/News.shtml">Message from Hannaford CEO Ron Hodge</a> <br><a href="http://news.bostonherald.com/business/general/view.bg?articleid=1080953&amp;srvc=home&amp;position=emailed">The Boston Herald</a> <br><a href="http://online.wsj.com/article/SB120578480456942847.html?mod=googlenews_wsj">The Wall Street Journal</a> <br><a href="http://www.boston.com/business/ticker/2008/03/supermarket_dat.html?p1=Well_MostPop_Emailed4">The Boston Globe</a> <br><a href="http://www.pcworld.com/article/id,143523-c,onlinesecurity/article.html">PC World</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Hannaford Bros. Co.<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>BOSTON -- Two grocery store chains -- Hannaford Bros. and Sweetbay Supermarket -- both owned by Belgium-based Delhaize Group SA, suffered a credit-card data breach, the companies said Monday.<br><br>Hannaford has contained a data intrusion into its computer network that resulted in the theft of customer credit and debit card numbers. No personal information, such as names or addresses, was accessed. Hannaford doesn’t collect, know or keep any personally identifiable customer information from transactions.<br><br>exposed about 4.2 million credit and debit card numbers<br><br>about 1,800 cases of fraud have been tied to the breach<br><span style="font-style: italic;">[Evan] This is probably a hint as to how Hannaford became aware of the breach.&nbsp; I am guessing that Hannaford was clueless until investigators contacted them.</span><br><br>evidence of unauthorized uses of card data have surfaced in Houston, Detroit, San Francisco, France and Brazil.<br><br>We sincerely regret this intrusion into our systems, which we believe, are among the strongest in the industry. The stolen data was limited to credit and debit card numbers and expiration dates, and was illegally accessed from our computer systems during transmission of card authorization.<br><span style="font-style: italic;">[Evan] Their information security is "among the strongest in the industry"?&nbsp; Here is a hint as to how the information was illegally obtained, "during transmission of card authorization".</span><br><br>The intrusion affected Hannaford stores, Sweetbay stores in Florida and certain independently-owned retail locations in the Northeast that carry Hannaford products.<br><br>Hannaford operates 165 stores in the Northeast. There are 106 Sweetbay supermarkets in Florida.<br><br>the breach began on Dec. 7 and continued until last Monday.<br><br>Hannaford is cooperating with credit and debit card issuers to ensure those customers who may be affected by the theft are protected. We also alerted law enforcement authorities, and are working closely with them to help identify those responsible.<br><br>the U.S. Secret Service is investigating the possibility that Track 2 data -- including PIN numbers and expiration dates contained on credit cards -- were compromised<br><br>We realize this incident may raise concerns and questions for our customers, and we sincerely regret any inconvenience this attack on our system may cause you. As always, we appreciate you choosing to shop at Hannaford. We remain committed to providing you with the finest foods and a clean, friendly and secure shopping experience.<br><span style="font-style: italic;">[Evan] This will be my understatement of the day, "We realize this incident may raise concerns and questions for our customers".&nbsp; You think?&nbsp; The banks are probably a little torqued too!</span><br><br><span style="font-weight: bold;">Commentary</span>:<br>This is going to be another legal battle.&nbsp; State and/or federal legislators are going to want more laws and regulations.&nbsp; The consumers are caught in the middle, and the banks are going to want their money back.&nbsp; 4.2 million credit and debit card number heisted over a three month period is pretty hard to explain away.<br><br>How do you suppose the data was captured by thieves?&nbsp; I know that Hannaford claims "during transmission of card authorization", but where?&nbsp; Was the data captured while it was in transit over a public network?&nbsp; The Payment Card Industry Data Security Standard (<a href="https://www.pcisecuritystandards.org/pdfs/pci_dss_v1-1.pdf">PCI DSS</a>) states:<br>"<span style="font-style: italic;">Requirement 4: Encrypt transmission of cardholder data across open, public networks</span><br>Sensitive information must be encrypted during transmission over networks that are easy and common for<br>a hacker to intercept, modify, and divert data while in transit."&nbsp; <br>It's hard for Hannaford to claim they didn't know.<br><br>I sincerely hope that the statement "our systems, which we believe, are among the strongest in the industry", isn't true.&nbsp; If it is, then we are in for a lot more breaches like this one, and more regulations to comply with. <br><br>This breach reminds me of a conversation I had a few years ago with the head of information security for a top 10 US bank.&nbsp; He complained to me for ten minutes about how he was being forced to spend three million dollars encrypt data data between ATMs and central processing.&nbsp; He claimed that the bank doesn't really have to be "secure", it only needs to be more secure that the next guy.&nbsp; Believe it or not, he is still the head of security at the same bank.&nbsp; Oy vey.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/17/hannaford.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 17 Mar 2008 21:07:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/hannaford">hannaford</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/credit-card data breach">credit-card data breach</category>
      <category domain="http://securityratty.com/tag/carry hannaford products">carry hannaford products</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <source url="http://breachblog.com/2008/03/17/hannaford.aspx">Hannaford and Sweetbay supermarkets announce compromise of 4.2 million credit and debit cards</source>
    </item>
    <item>
      <title><![CDATA[Data thieves steal credit card data from supermarket chain]]></title>
      <link>http://securityratty.com/article/4c55bd17b8ff34d508e45417aa7cf359</link>
      <guid>http://securityratty.com/article/4c55bd17b8ff34d508e45417aa7cf359</guid>
      <description><![CDATA[Data thieves broke into computers at supermarket chains Hannaford Brothers and Sweetbay, stealing an estimated 4.2 million credit and debit card numbers, Hannaford said...]]></description>
      <content:encoded><![CDATA[Data thieves broke into computers at supermarket chains Hannaford Brothers and Sweetbay, stealing an estimated 4.2 million credit and debit card numbers, Hannaford said Monday.]]></content:encoded>
      <pubDate>Sun, 16 Mar 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data thieves">data thieves</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <category domain="http://securityratty.com/tag/million credit">million credit</category>
      <category domain="http://securityratty.com/tag/sweetbay">sweetbay</category>
      <category domain="http://securityratty.com/tag/hannaford">hannaford</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <source url="http://www.networkworld.com/news/2008/031708-data-thieves-steal-credit-card.html?fsrc=rss-security">Data thieves steal credit card data from supermarket chain</source>
    </item>
  </channel>
</rss>
