Michaels Stores Investigating Possible Data Breach
tsu doh nimh writes "Michaels Stores Inc., which runs more than 1,250 crafts stores across the United States, said Saturday that it is investigating a possible data breach involving customer cardholder information. According to Brian Krebs, the journalist who broke the story [and, previously] news of the Target and Neiman Marcus breaches, the U.S. Secret Service has confirmed it is investigating. Krebs cited multiple sources in the banking industry saying they were tracking a pattern of fraud on cards that were all recently used at Michaels Stores Inc. In response to that story, Michaels issued a statement saying it 'recently learned of possible fraudulent activity on some U.S. payment cards that had been used at Michaels, suggesting that the Company may have experienced a data security attack.' In 2011, Michaels disclosed that attackers had physically tampered with point-of-sale terminals in multiple stores, but so far there are no indications what might be the cause of the latest breach. Both Target and Neiman Marcus have said the culprit was malicious software designed to steal payment card data, and at least in Target's case that's been shown to be malware made to infect retail cash registers."
Way too easy to commit fraud. Pay cash for small purchases. And stop giving stores your name for loyalty cards or marketing
Seriously... Why have the US banks not rolled Chip & Pin out yet? This wouldn't be an issue if they had, and it's almost certainly costing them a lot more in refunded transactions than a roll out would have.
There is an easy solution to this problem - don't put point of sale systems on a network with external access. At the minimum one should limit the network addresses these systems are allowed to access.
As soon as the cost of chip and pin is less than the cost of security breaches they will switch. My US credit cards have problems in Canada now because everything there expects chip and pin.
Only the State obtains its revenue by coercion. - Murray Rothbard
Sadly until breaches like this occur the more MBAs will listen to those annoying cost centers and view them with value and listen. Reason they are on internet is because the suits said so and the accountants whined about having real time access.
Maybe if congress is involved they can make regulation requiring secure operating systems with ASLR which scramble ram. Windows 7 and MacOSX have it and I think can support it via a patch with 3.0 or higher. Crosses fingers for redhat 7.Also POS equipment is SUPPOSED to be upgraded every 2 to 3 years just like browsers. Guess who says NO? The MBAs who feel if it ain't broke don't fix it. Here here for insurance companies forcing them to follow manufacture requirements
http://saveie6.com/
Put a block on your card to issue a warning as soon as someone buys anything with your credit card other than scrap-booking supplies or boxed wine.
to bad all those nsa snooping computer can't find a hacker...
Because I worked damn hard for that money? Whose right is it for you to tell me what to spend it on?
The data was stolen from the POS device's ram during the brief amount of time it was there. Would Chip and Pin prevent using any of that data later on? Seems like the pin would have to be in mem at some point also, but I don't really know.
Because they have a few stores in Canada as well, so I'm worried.
This is because CONservatives... don't give a damn about security. They never have. They don't care about us peons that are their customers. I bet their upper management is celebrating how they've screwed-over the average Joe. Those GOPpers always enjoy that.
... and ...
the U.S. Secret Service has confirmed it is investigating
I know where this is leading. The attack will be likened to "9/11 on retail", and: ... the "Retail Security Agency" will be created under the DHS; it will buy and operate (on public funds, of course), "nude scanners" at the entry of each retail shop (after all, those POS-es were physically tampered... a nude scanner will certainly help detecting... ummm... POS tampering devices);
...;
... to help the above, those stores will no longer sell liquids in bottles larger than 3.4 ounces - (yay, packaging industry and mayor Bloomberg... no longer sugary soda drinks in large cans);
* the "Providing Appropriate Tools Required to Intercept and Obstruct Tampering of POS bill of 2014" - also know as "the PATRIOT-POS v2014 act";
* it will be required those POS-es be operated from behind reinforced doors, but since the retail industry will complain about the cost...
*
* after a while, the customers will be required to take off their shoes before enter a retail shop
* the stores will no longer allow entry while carrying bottle of liquids more than 3.4 ounces, etc and
*
...
* NSA will intercept and store the transactions recorded at each POS (the Utah stae will need extra energy capacity for the three new secretd NSA data centers). Now, mind you, this will be strictly legal (after all, it's only metadata... not like NSA would intercept any of the money or merchandise exchanged during the shopping), with safeguards implemented by FISA-courts and congressional supervision; you can trust them on that.
(what? you point to my tin-foil hat? Well... you asked to be taken care of, as a peon and average Joe that is their customer).
(grin)
Questions raise, answers kill. Raise questions to stay alive.
this so called card skin game is going to be a few billion more ... i just reported a half dozen fraud charges, made at stores near my home, with my pin. no, did not share or write pin, this is scary. have not used card at any of these admitted breached company.
You might not, but the rest of us have mothers, aunts, sister-in-laws, girlfriends, wives, daughters (and all their male counterparts in some cases) that require us to shop at Michael's at least once a year. Typically around either the first week or two of May, or in the few days running up to Dec. 25.
There was a time, though, that Michael's was a fun place to shop. If you didn't have a Hobby Lobby or the like, it was the best place to buy model rockets and the like.
Someone flopped a steamer in the gene pool.
You have more than you need. I know because you have a computer and free time to post on Slashdot. Why aren't you donating 90% of your pay to hunger relief? Why don't you donate it to the Federal Government for healthcare? After all, failure to do so is murder. I guarantee they'll take your check! Don't know where to send it because you're too lazy to ask? Still murder. You could at least donate it to a local shelter. You don't need more than one set of clothes either. Or a car. You don't need the computer you're staring at right now. Liquidate and donate! Or are you selfish?
So the tech workers have the power to get stuff done and the MBAs take the blame for there mess ups.
CONservatives vs LIEberals or REPTILEcans vs DEMONcrats; you make the call.
Same to you, hypocrite. Sell your computer so we never have to read your shit ever again
Turning a Russian mafia crime scheme into an American political party debate. Do you both have any idea of how stupid you sound? This would not even be relevant if there was an actual difference between party A or party B, which time has shown there is none. Fine, go at each other's throats while your house burns down.
Are there any credit cards in the US that actually offer the "newer" CHIP/PIN cards? I am also assuming that the readers have to recognize these cards as well.....
Because social and infrastructure programs create an environment where capitalism can thrive - When you have a healthy, educated workface along with roads, airports, telecommunications and all the trappings of a modern society you create a scenario that, at its most basic level, creates a culture of people who can actually buy your stuff and at a more advanced level creates a place that fosters entrepreneurship.
There's a reason Germany has a surging economy and Somalia doesn't...
Tu quoque. Hypocrisy is not an argument.
Furthermore, your reply did not make sense, since he doesn't actually believe what he was suggesting. That is, he was using sarcasm!
You could put a frequency broadcaster in the loop, a physical hack. The NSA does.
Michael's outsourced their IT. Interestingly, this is NOT their first time for being cracked. You would think that they would learn.
Anybody a victim of Michael's, Neiman Marcus, or Target? Sue them LARGE.
Until chip and pin, I guess I'll have to carry cash. That waitress at the restaurant taking my card and coming back with it a few minutes later - has always unnerved me.
To serve only self is the ultimate slavery.
The theft of passwords is not the story.
It's the theft of real names, addresses, and such along with user names, and those questions we use to reset our passwords. That can reset Your password elsewhere after You change it.
Whoosh-o-rama! Off topic? Maybe. If any one was a troll, it would be the submitter with a pseudonym phonetically misspelling his pseudonym to look like a Vietnamese name sounding like pseudonym.