Slashdot Mirror


Kmart Says Its Payment System Was Hacked

wiredmikey writes Kmart is the latest large U.S. retailer to experience a breach of its payment systems, joining a fast growing club dealing successful hack attacks. The company said that on Thursday, Oct. 9, its IT team detected that its payment data systems had been breached, and that debit and credit card numbers appear to have been compromised. A company spokesperson told SecurityWeek that they are not able to provide a figure on the number of customers impacted. The spokesperson said that based on the forensic investigation to date, no personal information, no debit card PIN numbers, no email addresses and no social security numbers were obtained by the attackers.

101 comments

  1. social security? wtf by Spy+Handler · · Score: 4, Insightful

    why would Kmart even have your social security number?

    1. Re:social security? wtf by MasterOfGoingFaster · · Score: 4, Informative

      why would Kmart even have your social security number?

      Uh... Employees?

      --
      Place nail here >+
    2. Re:social security? wtf by Anonymous Coward · · Score: 1

      Kmart credit cards?

    3. Re:social security? wtf by retroworks · · Score: 0

      FTFA "The spokesperson said that based on the forensic investigation to date, no personal information, no debit card PIN numbers, no email addresses and no social security numbers were obtained by the attackers."

      --
      Gently reply
    4. Re:social security? wtf by Anonymous Coward · · Score: 1

      FTFA "The spokesperson said that based on the forensic investigation to date, no personal information, no debit card PIN numbers, no email addresses and no social security numbers were obtained by the attackers."

      Must be trure, if a spokesperson said it was.

    5. Re:social security? wtf by Vellmont · · Score: 1

      Most stores these days have their own store credit cards. To apply for them you give them your SS#.

      --
      AccountKiller
    6. Re:social security? wtf by lister+king+of+smeg · · Score: 2

      why would Kmart even have your social security number?

      Because they ask for it to look up your Sears credit card if you don't have it with you. Yes it is stupid

      --
      ---Saying gnome 3 is better than windows 8 not so much a compliment as it is damning with light praise.
    7. Re: social security? wtf by EthanV2 · · Score: 1

      I'd like to know what has actually been leaked, since everything in that list is generally stuff that would be leaked in a breach of a payment system.

    8. Re:social security? wtf by Anonymous Coward · · Score: 0

      Uh... POS terminals can process credit card applications.

    9. Re: social security? wtf by bill_mcgonigle · · Score: 1

      If you even go in to buy a candy bar they will ask you to apply for a credit card at the register. Even if you are eleven years old (happened to my daughter last week). Then they give you seven feet of receipt material with coupons, surveys, and a copy of the Magna Carta.

      They are so going out of business. I would be short on the stock.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
  2. So this affects... by BUL2294 · · Score: 4, Funny

    ...nobody.

    --
    Windows 3.1x calc: 3.11 - 3.10 = 0.00
    1. Re:So this affects... by Anonymous Coward · · Score: 0

      me....

      It is usually 2-3 dollars cheaper on everything than my local grocery story for many items I use. It is also closer than wally world.

      So I use it. Guess I am getting a new credit card...

    2. Re:So this affects... by Anonymous Coward · · Score: 1

      So this affects nobody.

      Not quite. I have elderly relatives that live in a rural area that, for some reason, only has a K-Mart. No Target, no Wal-Mart, and very little by way of decent local shopping. The closest Wal-Mart is almost an hour's drive away, and Target is closer to two, so if you live there and want something that isn't groceries, you basically have no choice but to go to K-Mart. (As you might expect, it's a piss-poor example of a store, because there's absolutely no reason to care. It's not like the shoppers have a choice.)

      I'm not looking forward to having to explain to them what happened and why it affects them. They've already had to deal with their bank account being cleaned out in the past after some online vendor they used got breached. Hopefully doesn't happen again.

    3. Re:So this affects... by reboot246 · · Score: 1

      Advise them to pay cash for whatever they buy in brick and mortar stores, plus limit online buying to only when necessary.

    4. Re:So this affects... by Anonymous Coward · · Score: 0

      Been there, done that, suggestions and advice don't work. Thanks for trying to offer ideas, though.

      Problem is one of them is way too trusting and does stupid things because it was safe in the 50s or some shit like that. I don't know the logic, really, but it's problematic. As in "Oh god how did you get 50 viruses already" problematic. Had to set that one up with a chromebook because he kept absolutely destroying windows installs every few months no matter what was done. Can't do remote support easily either because of how shitty rural internet is. So, chromebook!

      Point is, "use cash instead" and "if you want or need to use a card, use one with a limit instead of the debit card" stuff just goes in one ear, out the other, barely slows down on the way through. Best part is he's the one that handles all the finances usually because of an outdated "this is the man's job" mentality, so the more cautious one that SHOULD be handling it doesn't get to.

      I'm actually surprised that they've only had a problem once before, all things considered. Hopefully the luck keeps up.

  3. BLUE LIGHT SPECIAL !! by Anonymous Coward · · Score: 0

    Come and get it hackers !!

    1. Re:BLUE LIGHT SPECIAL !! by Tablizer · · Score: 1

      Blue Screen Special

    2. Re:BLUE LIGHT SPECIAL !! by Anonymous Coward · · Score: 0

      What does this have to do with the blue screen?

    3. Re:BLUE LIGHT SPECIAL !! by plover · · Score: 1

      "ATTENTION K-MART HACKERS!

      We have a special deal for you under the flashing blue screen. Credit card numbers, all you can stuff in a ZIP file. The blue screen will only be there for the next month or so, so hurry on over and check out the checkouts."

      --
      John
    4. Re:BLUE LIGHT SPECIAL !! by NotQuiteReal · · Score: 1

      umm... the color blue? Loose associations come easily to those who drink-n-post.

      --
      This issue is a bit more complicated than you think.
  4. It would be quicker by Coditor · · Score: 5, Funny

    to list who hasn't been hacked yet. I wonder if these big companies buy their security systems at K-Mart.

  5. Officials estimates losses by jpellino · · Score: 5, Funny

    in the dozens of dollars.

    --
    "Win treats sysadmins better than users. Mac treats users better than sysadmins. Linux treats everyone like sysadmins."
  6. Also at krebsonsecuritycom by manu0601 · · Score: 4, Informative
  7. Dairy Queen hacked too by Anonymous Coward · · Score: 0

    News came out earlier today dairy queens in Colorado area were hacked.
     

    1. Re:Dairy Queen hacked too by Anonymous Coward · · Score: 0

      Rural cross-dressers got hacked? What were they after, gingham dress patterns?

    2. Re: Dairy Queen hacked too by Anonymous Coward · · Score: 0

      Kmart? Dairy Queen? Who the fuck goes to these shit establishments anyways?

  8. hacking-envy by turkeydance · · Score: 2

    if your company hasn't been hacked...well, that sucks for you.

  9. Does K-Mart use the same stuff as Sears? by mlts · · Score: 4, Interesting

    Sears, last time I checked was a definite IBM AIX shop with the point of sale terminals being a tad more than IBM 3151 VTs, except with a credit scanner and cash drawer. Is K-Mart on a different system, or do both Sears and K-Mart use the same POS these days?

    Malware on Windows is one thing... nailing AIX systems actually would be an accomplishment.

    1. Re:Does K-Mart use the same stuff as Sears? by ArchieBunker · · Score: 1

      Kmart has newer registers but the screen where you swipe credit cards looks like OS/2 or Win 3.1 judging by the hourglass displayed.

      --
      Only the State obtains its revenue by coercion. - Murray Rothbard
    2. Re:Does K-Mart use the same stuff as Sears? by Anonymous Coward · · Score: 0

      OPSM's patient record system looks like something written in Curses or Turbo Vision (remember that little Borland oddity?).

    3. Re:Does K-Mart use the same stuff as Sears? by execthis · · Score: 3, Interesting

      Based on what the article says about what happened - that it was actual POS malware - I still am not able to figure out a methodology that would enable such an attack to work.

      Let's say someone manages to put malware on a POS device. Ok. But now how would that malware be able to communicate any information to the thieves? I cannot imagine that the POS device is just sitting on the 'net without a strict firewall in front of it allowing it access to one - and only one - address: that of the company that provides the line/aggregates the data which feeds ultimately to the merchant account provider who handles the transactions for the company.

      If the POS malware tries to "phone home" with data, it should never ever be able to connect.

      So the issue to me becomes more than whether a POS device actually got malware on it - what kind of setup could exist such that the device would ever have the opportunity to connect with any other host than the predesignated one it is allowed to???

    4. Re:Does K-Mart use the same stuff as Sears? by Anonymous Coward · · Score: 0

      Why would it be an accomplishment? Why do people think proprietary unix or even mainframes are impenetrable?

    5. Re:Does K-Mart use the same stuff as Sears? by Anonymous Coward · · Score: 2, Informative

      It would be an accomplishment. Mainframe OSes, AIX, and Solaris have an impeccable record for security these days (before 2000, different story, as Sun was often bashed... but with MS as the absolute focus for the bad guys with OS X and Linux trailing), hacking an AIX box is a lot more difficult than Windows.

      1: AIX has trustchk. If the executable isn't signed, it doesn't run. Linux doesn't have this functionality, and has to be done in userland. Even modified libraries won't load. Of course, this functionality is limiting, but for a static system like a cash register, it is useful.

      2: AIX has a far better patch install system than anything out there. You can reject a patch and go back to the previous update. No other OS is this possible without restoring or reinstalling. Once confident with a patch, you can commit it and free the space.

      3: AIX has both VMs (LPARs) and partitions (WPARs). It is easy to separate applications for defense in depth.

      4: SELinux's functionality is far expanded in AIX and Solaris. Solaris 11 has no root user by default. Root is just a schmuck like every other UID. This can be changed, but hacking UID 0 means little. AIX, root can be completely removed to the point where one reboots a LPAR or machine to a service partition for updates, and boots back. This keeps users completely separated and unless there is a way to find a hole to get into kernel space on the POWER architecture, a library attack like Shellshock won't do much, if anything.

      All and all, Linux is great, and has made light-years of improvements. But Solaris and AIX have not stood still, and are still ahead as enterprise-grade operating systems. For 99% of use cases, Linux is fine. However, there are items (like the need for ZFS which is at best stitched on Linux) where Solaris and AIX are musts.

      Of course, the downside of AIX is that it is IBM, and thus insanely expensive... but you do get what you pay for.

    6. Re:Does K-Mart use the same stuff as Sears? by plover · · Score: 1

      While it's possible (unlikely in these days of PCI) that a POS register could have a direct route to the internet, it's also likely that the registers weren't the only machines in their system that were hacked. It is probable that the criminals found a little-used server in K-Mart's HQ systems, compromised it, and set up what's called a "dump site." The registers are then configured to exfiltrate their data to this internal HQ server, perhaps by periodic FTP, and the hackers had the HQ server send batches of data out to the internet at a later time.

      --
      John
    7. Re:Does K-Mart use the same stuff as Sears? by execthis · · Score: 1

      I was thinking that the only possibilities for the theft to happen would have to be either a) there's an administrative access to the POS systems which was breached, kind of similar to what you are saying; or b) there's some manipulation of the physical infrastructre at (a) store(s) in addition to POS malware. For example some malicious host could be inserted in the pathway of communication of the POS systems. My guess is that that isn't too likely.

      More likely is something like a), or what you suggest. There was a breach in the firewall, most likely something that was permitted for administrative purposes but turned out to sloppy/insecure.

      Too bad with security breaches like this one doesn't generally get an opportunity to look at the topology involved and see what actually happened with the breach. It would be a very interesting thing to study.

  10. My shopping is becoming limited by Anonymous Coward · · Score: 1, Insightful

    As an IT security guy, I really find all these cracks disheartening. I guess the IT staff at these places don't really understand that security is a process, not a product. You cannot throw up a router with some ACLs and firewall or two and expect to be secure. Neither can you not make constant audits of your backend payment systems and expect security.

    I've already stopped shopping at Target permanently because of their debacle. I stopped shopping at Walmart this week due to their cancelling health benefits for all part time workers despite being able to afford it and then some. Who is next to not pay attention to their security posture?

    1. Re:My shopping is becoming limited by ArcadeMan · · Score: 2

      Can't you pay with regular, non-computerized cash?

    2. Re:My shopping is becoming limited by mlts · · Score: 0

      I wouldn't blame the IT staff. A lot of places have PHBs that feel that security has no ROI, so give token (at best) funding to security.

      As it stands now, most companies will not suffer much even with a critical breach. PCI-DSS3 is only for the little guys, and HIPAA, SOX, FERPA, and other regs are lightly enforced if that. The people who suffer are end users, and that doesn't really matter.

      Even with a good security staff in place, there is also the fact that you can't win a war with just defense. Ultimately, a network similar to SIPRNet or NIPRNet is needed, something that is not part of the Internet and has defense both by a centralized party, and at the endpoints, where machines communicating with each other is prearranged beforehand to minimize the damage of what a compromised box can do.

    3. Re:My shopping is becoming limited by Anonymous Coward · · Score: 1

      And, don't forget that the IT staff often have to allow a big, gaping hole in the firewall to allow the vendor(s) to update your POS software per contract.

    4. Re:My shopping is becoming limited by networkzombie · · Score: 1

      As an IT security guy, I don't used my credit card at Target, Sears, Kmart, Walmart, Home Depot, or any of the large targets (no pun intended). I use cash at those places (and gas stations) because it is obvious they were employing on the cheap. Low paid employees+massive transactions=easy target. They are the low hanging fruit. I use my credit card at Newegg and my favorite small restaurant where I know the owner. At least if they get hacked I will get an apology. When I setup my customers/clients to accept credit cards, I fill out the mandatory PCI compliance form for them. What a joke! Half the time the never follow up, like they say they have to, and the form basically asks if you have antivirus on the computer. Can I get an audit please? Where does the tax money go?

    5. Re:My shopping is becoming limited by mlts · · Score: 3, Insightful

      Very true. I'm reminded of one vendor that as part of the contract got their own direct connect to company LANs in order to directly service/support their software. I always worried that all it took was some compromise on the vendor's side, and it was a big gaping hole that could be easily nailed. The vendor was pretty much protected (part of the software contract), so if they got hacked, it was pretty much game over.

      I did stick in a firewall though. The vendor had unfettered access to their machines... but no unrelated boxes, and their machines were also sectioned off. However, it was like putting a bandaid on a bullet wound, because of all the things their software touched.

      Point of sale systems are not rocket science. We had better quality of code when game companies made Playstation 1 CDs (as they could not be updated, so what was released was it.) It might just be time to return to that finished quality of code... but still have an update mechanism. An update mechanism that requires not just signed firmware, but someone physically pressing a button (so the software can't be remotely updated.)

    6. Re:My shopping is becoming limited by RussR42 · · Score: 1

      You could try. But if the police see you with cash, they'll take it away.

    7. Re:My shopping is becoming limited by Anonymous Coward · · Score: 0

      "Sir, how much money do you have in the car?" Because, who uses cash these days except for 'criminals'?! https://www.youtube.com/watch?v=3kEpZWGgJks

  11. Wow, K-Mart by Anonymous Coward · · Score: 0

    Who even knew that was still a thing?

    I think the last time I saw an actual K-Mart store was in the early 1990s, and they were on the way out even back then.

  12. It's a Pin, Chip! by rmdingler · · Score: 1

    It's too bad someone hasn't come up with a way to make credit cards that cannot be compromised in this manner.

    --
    Happiness in intelligent people is the rarest thing I know.

    Ernest Hemingway

    1. Re:It's a Pin, Chip! by Anonymous Coward · · Score: 0

      How does that chip help when you are shopping online?

    2. Re:It's a Pin, Chip! by ShanghaiBill · · Score: 2

      How does that chip help when you are shopping online?

      You insert it into a device attached to the USB on your computer. The chip is queried and authenticated in real time as you make your purchase. I have a bank account in China, and that is how it works there to do online transactions.

    3. Re:It's a Pin, Chip! by Anonymous Coward · · Score: 0

      Shopping online at K-mart?

    4. Re:It's a Pin, Chip! by Anonymous Coward · · Score: 0

      You insert it into a device attached to the USB on your computer. The chip is queried and authenticated in real time as you make your purchase. I have a bank account in China, and that is how it works there to do online transactions.

      I have seen the tragedy that is trying Dialup, Printing, Bluetooth, wifi (the latter, for the first decade) and to a lesser extent, 3D support. Supposedly trade secrecy, DRM and patents make reverse-engineering these very hard. We're not even talking about 3G radios in our Linux phones. So now that we're in the right mindset, and talking cold, hard, electronic cash (plastic)...

      Woud such a chip device ever be allowed to have Linux drivers, considering how hard everything is getting hacked today, even without their existance?

    5. Re:It's a Pin, Chip! by Rich0 · · Score: 1

      Woud such a chip device ever be allowed to have Linux drivers, considering how hard everything is getting hacked today, even without their existance?

      I don't know how Chip/PIN was actually implemented, but if the makers had half a brain there would be no reason not to make the drivers/protocols/etc completely open. There is no reason that the system should have to rely on the security of the POS terminal - the crypto happens on the smartcard and all the terminal should do is relay stuff between the bank and the card. In fact, I don't get why they don't just put the keypad on the card itself, making the PIN harder to steal, as well as the credential on the chip.

    6. Re:It's a Pin, Chip! by ShanghaiBill · · Score: 1

      I don't get why they don't just put the keypad on the card itself

      In the near future, they will, because "the card" will be your cellphone.

    7. Re:It's a Pin, Chip! by Rich0 · · Score: 1

      I don't get why they don't just put the keypad on the card itself

      In the near future, they will, because "the card" will be your cellphone.

      The problem with this is that it is actually not easy to ensure that the path between the TPM and the phone touchscreen isn't compromised. You can secure the credentials in the TPM, but the PIN is harder to secure when it is entered on a device intended for general-purpose computing.

  13. Should retailers store credit card details? by Midnight+Thunder · · Score: 1

    Beyond transactions, I wonder whether retailers should even be storing credit card information? Surely debating this problem to the credit card companies would be better? The only thing combines should be keep is maybe some sort of public key value for the credit card, which can only be unlocked with a user provide value. The private key would be in the hands of the credit card company to access your account.

    I am thinking on the fly here, but the main gist is the less credit card details stored by non-credit card companies the better. These retailers could secure their systems better, but maybe they shouldn't be holding on to certain critical information either? We need to review what financial data is held in light of these issues.

    In Europe you have a one time key for your online payments, that requires a special calculator looking device. Probably not the best solution, but not a terrible one either - it's just inconvenient and not necessarily clear to the non-tech savie.

    --
    Jumpstart the tartan drive.
    1. Re:Should retailers store credit card details? by Anonymous Coward · · Score: 0

      Of course they shouldn't... But when you go to return something it lets them do it without swiping your card again.

    2. Re:Should retailers store credit card details? by Teresita · · Score: 2

      In other news, people who actually have credit cards go to K-Mart...

    3. Re:Should retailers store credit card details? by Anonymous Coward · · Score: 0

      > Beyond transactions, I wonder whether retailers should even be storing credit card information?

      They don't. All the big hacks so far have been at or near the point-of-sale using RAM scrapers (and other malware too).

    4. Re:Should retailers store credit card details? by jtownatpunk.net · · Score: 1

      I guess you missed the part where it's the payment systems that are being compromised in recent hacks. The way our credit/debit system works, the retailer must have your account information for as long as it takes to process the transaction. When it's the terminal where you swipe your card that's compromised and passing a copy of your data to thieves, what can you (the consumer) do?

      I wrote up a description of a payment system which never gives account information to retailers a while back but can't find it now. Basically a USB doohickey with biometric authentication (fingerprint scanner with pulse check), a small display, and a couple-three buttons. You plug it into the payment terminal (no wireless, goddamnit!) and, it makes a secure connection to the payment processor and indicates that you are conducting a transaction with Retailer XYZ. Retailer XYZ's payment terminal connects to the payment processor and says it's conducting a transaction with and you owe $119.37. The payment processor communicates the total to your doohickey via its secure connection which shows you the amount requested and asks if you for authorization to transfer $119.37 to Retailer XYZ from your primary payment account. You say yes/other account/no and the transaction either continues or is cancelled.

      As long as the payment processor is secure, you're good. While that's still an issue, it reduces the points of failure significantly. It could also be used for all your authentication needs. Computers, online accounts, game consoles, secure buildings, etc. Secondary verification could also be added with SMS or a smartphone app.

      Gotta do something because individual retailers all being responsible for their own security clearly isn't working. I lost my account number of 15 years thanks to the Home Depot crap. :P

    5. Re:Should retailers store credit card details? by Anonymous Coward · · Score: 0

      That's done with the transaction ID on the receipt...

    6. Re:Should retailers store credit card details? by Anonymous Coward · · Score: 0

      There's no need for payment terminals or their connected PoS terminals to even know the customer's card number and expiry dates. That they have this information in the clear at all is why these machines are so attractive to attackers. If chip-and-pin were actually done properly the communications would be encrypted end-to-end (i.e.: from the payment processor all the way down to the card and back). It's not like the PIC 16F84s embedded in the cards now *can't* actually do encryption for Crissake!

    7. Re:Should retailers store credit card details? by tlhIngan · · Score: 1

      I am thinking on the fly here, but the main gist is the less credit card details stored by non-credit card companies the better. These retailers could secure their systems better, but maybe they shouldn't be holding on to certain critical information either? We need to review what financial data is held in light of these issues.

      In Europe you have a one time key for your online payments, that requires a special calculator looking device. Probably not the best solution, but not a terrible one either - it's just inconvenient and not necessarily clear to the non-tech savie.

      It's all Apple's fault. I mean, three big targets hit? It certainly sounds like a recipe for promoting Apple Pay, to be honest.

      (And no, Apple Pay is nothing special - it's just an implementation of EMV. What makes it "better" is nothing - it's just an implementation of EMV, including the fact that when you register a card, Apple contacts the bank and returns a virtual credit card number (the "token") which is stored in the phone. That token cannot be linked back to a real credit card except at the institution that issued the token. All you need to do is either delete the link or delete the token or both that render it invalid for future purchases. It's also why Apple can't see your transactions, and how banks know when you use Apple Pay - it's basically just a glorified credit card. Google Wallet, OTOH, puts Google in the middle - retailers bill Google and Google bills you, so Google knows every transaction you make).

      And yes, it's why Apple Pay works with basically everyone - deep down, all it is is a virtual credit card. If you accept Visa/MC/Amex, Apple Pay means zero effort on your part to support. To support Google Wallet means actually having to have your payment processor support Google.

      And since it can't be linked, when something like this happens, you cancel the token and get a new one issued.

      Yes, it's all Apple's fault. You can bet Apple is paying hackers to do these breaches to promote h ow safe Apple Pay is since you can easily "fix it" in 5 minutes.

  14. Pharmacy by breman · · Score: 1

    maybe they were going for the medical records, I heard that's big business these days.

  15. This is good news by Anonymous Coward · · Score: 0

    Force everybody back to good old paper and ink. These damn contraptions are not ready for the market yet.

  16. Cash is king by AndyKron · · Score: 2

    That's why I use cash

    1. Re:Cash is king by un1nsp1red · · Score: 1

      Plus, it makes you look like a baller.

    2. Re:Cash is king by Anonymous Coward · · Score: 0

      That's why I use cash

      Hopefully you don't look "ethnic". Look up "civil forfeiture" or "stop and seize" some time.

  17. Re:never happens at NiggerMart by Anonymous Coward · · Score: 0

    Seek help penis envy is a serious condition son.

  18. This is terrible by Ghoser777 · · Score: 2

    That's 10 more people who have had their personal information compromised.

    --
    James Tiberius Kirk: "Spock, the women on your planet are logical. No other planet in the galaxy can make that claim."
  19. joining a fast growing club dealing successful hac by Anonymous Coward · · Score: 0

    "joining a fast growing club dealing successful hack attacks"??

    Kmart was dealing the attacks? Wow, does no one proofread anymore?

  20. NSA On The Trail by Anonymous Coward · · Score: 0

    It is just NSA on the trail of Michelle Obama, aka Mr. Michael Jerome Green before the sex change operation.

  21. Protect yourself from crackers the easy way by msobkow · · Score: 2

    Keep a sub-$1 balance in your bank account. :P

    --
    I do not fail; I succeed at finding out what does not work.
    1. Re:Protect yourself from crackers the easy way by Anonymous Coward · · Score: 0

      They can still overdraw your account.

    2. Re:Protect yourself from crackers the easy way by msobkow · · Score: 1

      Not when you don't have overdraft protection.

      --
      I do not fail; I succeed at finding out what does not work.
  22. Shady practices. by Anonymous Coward · · Score: 1

    Last I knew - K-Mart's parent corporation Sears, rolled all their "Sears" cards over to Citibank. When I started getting suprize charges from "Sears Home Health" and called the number on the back of the "Sears" card to complain/dispute the charges - they told me "This is Citibank - if you have a dispute - dispute it with the company who charged it". I was like "this is a Sears card - I got a charge from Sears - I am calling Sears". Turns out - sometime magically three different companies - none of whom wanted to easily reverse any charges.

    Long story short - I am sure that K-Mart merely decided to adopted a new business practice selling customers' social security numbers to Nigerian scammers or something. It would be pretty par-for-the-course for them.

  23. The compromise is not the news... by Anonymous Coward · · Score: 0

    The real news is that K-Mart is still around.

  24. What is in common between these retailers? by Anonymous Coward · · Score: 0

    they run Microsoft and are retailers that are not allowed to sell in India, but has off-shored to there.
    Russia and China can buy off somebody for less than $100K to release a bug within the network.
    Later, the Russia/Chinese then leave a trail indicating other means, even though it is not likely, and would require millions for the Russian/Chinese to do.

  25. Doubtful forensics and common sense by ruir · · Score: 1

    I wonder if they have been hacked for months wether their systems and forensics are reliable enough to say for sure any personal data is not at risk. I doubt a lot they have systems in places to be able to say that with a 100% security margin. As for the current hacked systems being hacked or/with malware, anyone with common sense should not use Windows to drive critical systems.

  26. Nope by Anonymous Coward · · Score: 0

    Banks/companies will reimburse you for the lost money. Where your concern should be, is for your FULL Identification.
    Do NOT go with any of the 1 year BS life-lock policies that these companies offer you. Lifelock and others will continue to sell your information to companies like Target, Sears, Walmart, etc who then target you with spam, along with the crackers that go your info. These companies will off-shore that information where it will be used to target your with spam, and make it easy to grab it again, by a new and different set of crackers.
    Instead, go to all 4 credit bureaus and put a LOCK on your ID. If anybody or ANY COMPANY attempts to access your information, they are blocked. Simple as that. If you need to get a loan, CC, etc, then and only then, unlock it temporarily and only for that company.

  27. HACK ATTACK by darkain · · Score: 1

    Am I the only onw who thinks "Hack Attack" would be an awesome band name !?

  28. Get your act together by Anonymous Coward · · Score: 0

    Why don't people get their act together? It's rather depressing

    1. Re:Get your act together by Anonymous Coward · · Score: 0

      Riiiiggghhhhtttt. It has nothing to do with incompetent staff or management of the hacked companies or the criminals that hacked them.
      Obviously, MSNBC hacked your brain.

  29. almost said my company, would be a Target by raymorris · · Score: 5, Funny

    I almost mentioned the name of my company as the one that hasn't been hacked. We take security very seriously. No Microsoft products are allowed on the premises, employees are armed, etc.

    Then I realized posting that could make us a Target.

    1. Re:almost said my company, would be a Target by Gazzonyx · · Score: 1

      I almost mentioned the name of my company as the one that hasn't been hacked. We take security very seriously. No Microsoft products are allowed on the premises, employees are armed, etc.

      Then I realized posting that could make us a Target.

      Well played, sir. Well played.

      --

      If I mod you up, it doesn't necessarily mean I agree with what you've said, sorry.

  30. Re:Kmart? wtf by JWSmythe · · Score: 1

    That's pretty much what I was thinking. I thought they had all closed a few years ago.

    --
    Serious? Seriousness is well above my pay grade.
  31. Re:Kmart? wtf by Anonymous Coward · · Score: 0

    Who the fuck shops at Kmart anyways? LOL

    Apparently nobody with enough money or credit to posses a credit card.
    I suppose a customer list might be interesting to a collection agency, or a bounty hunter going after bail jumpers, but it's certainly not where you'd go looking if you're interested in stealing identities or credit information.

  32. Irresponsible corporation by Anonymous Coward · · Score: 0

    They need to be held responsible for this with hefty fines, investigations, and boycotting!!!

    Oh wait, it's not Wal-Mart? Nevermind, carry on.

  33. hacking-envy by Anonymous Coward · · Score: 0

    While visiting, Nantucket Parcel Plus, I heard a guy say their POS has a virus, and was fixing.

  34. Tell 'em, Ray! by Anonymous Coward · · Score: 0

    n/t

  35. Oh my stars and garters! by Anonymous Coward · · Score: 0

    Hacking K-Mart is like ... wow, what have you achieved? How would you ever live it down? Big leet haxor hakked K-Mart! Is this data valuable at all? Used to be that I felt sorry for shoplifters caught stealing from ... K-Mart. Can you imagine being in prison and trying to live that down?

  36. Whew! by Anonymous Coward · · Score: 0

    I'd be worried, if I shopped at Kmart in the last 5 years.

  37. K-mart sucks by liquidghondi · · Score: 1

    Dr. Bruner: Well, Raymond? Aren't you more comfortable in your favorite K-Mart clothes? Charlie: Tell him, Ray. Raymond: K-Mart sucks. Dr. Bruner: Oh, I see. Charlie: Hey, Ray: you just made a joke. Raymond: Yeah, a joke. Ha ha ha... ha.

  38. Another day another major data breach... by mschwanke97402 · · Score: 1

    I vote that we force these corporations to take data security and IT in general more seriously. First, cut off their online credit card processing. They can use the old mechanical card swipers for a while. Once they have seriously upgraded their systems, and been independently audited, they can go back online. Require them to submit to thorough systems audits and spot checks for 5 years or so. Perhaps corporate management will get the message that IT may not be a profit center but it is necessary to continued operations.

  39. How do you hack a crank calculator by RubberDogBone · · Score: 2

    KMart is well known for having barely any IT infrastructure, and what they DO have doesn't work well. They are literally one step removed from only hand-crack adding machines.

    How DO you hack that?

    Yes this is a serious question. One of the key differences between Walmart and KMart was how each company approached IT back in the 80s when this stuff became affordable and powerful. Walmart embraced data and wrapped their whole process around it and still uses it quasi-magical ways to glean trends, predict sales, do reorders, and find efficiencies. They extract value from data just like they squeeze their suppliers.

    KMart, on the other hand, looked at computers and laughed and went on laughing for years, not noticing as Walmart out flanked them and eventually drove them into the ground head first. KMart is barely alive now, because they spent decades not having any idea what was even in the stores or what was selling. They didn't know, didn't care, had no way to handle the data even if they had it, and generally treated IT like nothing more than office internet connections to surf Yahoo.

    Baseline Magazine, I believe it was, did a stellar piece on Walmart vs. Kmart and how each handled IT as of about 10 years ago. KMart is not painted on a good light. It's actually amazing an organization as incompetent as KMart is even still in business. .They have never gotten it and still don't.

    Walmart had them beat years before it happened, because Walmart knew all the data. They won the war in the server room. KMart never had a chance and didn't even fight back.

    --
    Sig for hire.
    1. Re:How do you hack a crank calculator by Anonymous Coward · · Score: 0

      Nowadays, you can pretty much buy a WinXP point-of-sales machine and system off the shelf for cheap. Maybe K-Mart finally started trying to get "up-to-date" and got hammered for it.

  40. How do you hack a crank calculator by Anonymous Coward · · Score: 0

    I worked at K-Mart in the 1980s. We were still using the carbon paper charge slips and the manual imprint machine when everyone else had moved to electronic CC transactions. We were still looking up every CC transaction in that paper directory that came out every two weeks with stolen credit card numbers in it. If the purchase was >$50, we had to call in and get an approval. I worked in electronics so I had to call in almost every sale, it was a huge PITA. K-Mart was very short-sighted in the 80s and it cost them everything.

  41. K-Mart Hacked by Gruff+2005 · · Score: 1

    K-Mart knew their system was breached 1 month ago, and only now made it public. Don't shop there never will.

  42. An obvious solution... by Anonymous Coward · · Score: 0

    ...is for credit card companies to issue new numbers to all cards twice a year. Or even issue new three-digit security codes every month or few weeks. Delivery, of course, is the issue, and paper notifications would probably be required until some sort of indirect electronic transmission means - like a PayPal for info -- is developed.