Questions- (Each question 100-150 words) I need 2 sets - No plagiarism
monitoring, and identity theft insurance for affected con-
sumers. In October 2013 a data breach at Adobe exposed
the account information of up to 152 million users—the
largest data breach in history. No costs have yet been
reported, but according to the Ponemon 2013 Cost of Data Breach Study, the average cost of a breached account is $188 (Ponemon Institute, 2013). In August
2014, fraudsters targeted customers of JPMorgan Chase,
the No. 1 U.S. bank by assets. The massive phishing
campaign, called Smash and Grab, was unusual because it collected customers’ login data and also infected PCs
with Dyre, a banking trojan that lifted login data for
other institutions. The bank was not able to identify who
was behind the Smash and Grab attack. In Chapter 5, you will learn about devastating cyber-
threats, data breaches, fraud, damages caused by cyber-
criminals’ aggressive tactics—and how organizations
defend against them.
C A S E 5 . 1 O P E N I N G C A S E BlackPOS Malware Steals Target’s Customer Data
Target is a major discount retailer in the United States (Figure 5.1). Target’s man-
agement admitted that 40 million credit and debit card accounts were exposed
between November 27 and December 15, 2013. During that peak holiday shopping
season, hackers captured credit card data from the stores’ point-of-sale (POS)
payment terminals (Figure 5.2).
Target disclosed the breach on December 19, 2013; then on January 10, 2014,
the retailer also reported that hackers stole 40 million credit card numbers along
with the personal information of another 70 million customers. The incident scared
shoppers away, affecting the company’s profits throughout 2014.
142
Figure 5.1 Target data breach overview.
HOW THE ATTACK WAS CARRIED OUT
Several experts believe that POS malware bought from the criminal underground
was responsible. Malware, short for malicious software, are computer programs whose code causes disruption, destruction, or other devious action. Malware named
BlackPOS is sold on the black market for $1,800 or more. The malware is adver- tised on Internet underground forums under the generic name Dump Memory Grabber by Ree. BlackPOS is malware designed to be installed on POS devices in
2nd largest retail discounter in the
United States.
4Q 2013 profit dropped 46% and
sales revenue fell 5.3% after
breach was disclosed.
Company Profile Hackers installed malware,
probably bought from a criminal
underground website, on Target’s
POS terminals to capture data
from credit and debit cards and
transmit back to the hackers.
Data Breach
Personal and financial data from
up to 70 million customers stolen
by hackers using malware.
Estimated the breach to cost
from $400 million to $450 million.
Extent of the Breach and Costs
Target
c05CybersecurityAndRiskManagement.indd Page 142 10/29/14 10:58 AM f-w-204a /208/WB01490/9781118897782/ch05/text_s
CASE 5.1 Opening Case 143
order to record data from credit and debit cards swiped through the infected device.
Specifically, the malware identifies the process associated with the credit card
reader and steals payment card Track 1 and Track 2 data from its memory. These
are the data stored on the magnetic strip of payment cards that were used to clone
or create counterfeit cards.
More feature-rich versions of BlackPOS selling for roughly $2,300 provide
encryption support for stolen data. The BlackPOS creator is not confirmed, but
experts tracking the malware suggest that the hacker may be based in Russia or
Ukraine. The U.S. Secret Service estimated that the type of malware that led to
Target’s breach has affected over 1,000 U.S. businesses.
Figure 5.2 POS payment terminal. Malware-infected POS terminals caused Target’s data breach.
FINANCIAL IMPACT OF THE DATA BREACH
In February 2014 Target reported that its 2013 fourth-quarter (4Q) profit dropped
46 percent and sales revenue fell 5.3 percent. A few months later, in May 2014,
Target estimated that technological changes to harden its IT security would cost
more than $100 million in addition to $61 million incurred in breach-related
expenses in Q4 2013. These costs and damages harmed the company’s profitability.
Gregg Steinhafel, chairman, president, and CEO of Target, tried to reassure
customers and investors, saying, “As we plan for the new fiscal year, we will continue
to work tirelessly to win back the confidence of our guests. . . . We are encouraged
that sales trends have improved in recent weeks” (D’Innocenzio, 2014).
Six months after the breach, it still was not clear when Target would fully
recover. A security analyst at the tech firm Gartner estimated the costs of the breach
to range from $400 million to $450 million. That includes the bills associated with
fines from credit card companies and services for its customers like free credit card
report monitoring. Target also faced at least 70 lawsuits related to privacy invasion
and negligence, alleging Target did not take proper steps to protect consumer data.
TARGET BRUSHED OFF WARNINGS
According to financial services firm Cowen Group’s note to investors, criminals
were able to hack into Target’s database due to a lack of security, which might have
been a result of underinvestment by senior management.
Target’s cybersecurity staff had also warned management to review the security
of its payment card system at least two months before the breach. At the time of
the warning, Target was updating the payment terminals, which makes them more
vulnerable to attack, in preparation for the holiday season. Data security was not a
top priority. Months before the attack, the federal government and private research
firms were also warning companies about the emergence of new types of malware
© A
le p
h S
tu d
io /S
h u
tt e
rs to
ck
c05CybersecurityAndRiskManagement.indd Page 143 10/29/14 10:58 AM f-w-204a /208/WB01490/9781118897782/ch05/text_s
144 Chapter 5 Cybersecurity and Risk Management
(malicious computer code) targeting payment terminals. However, because of
numerous security warnings that retailers receive every week, it is difficult to identify
or decide which ones are the most urgent.
EXECUTIVE FALLOUT On May 5, 2014, CEO Steinhafel resigned from all his positions effective immedi- ately, after extensive discussions with the board of directors. Steinhafel had been
CEO since 2008 and a Target employee for 35 years. The company stated that
Steinhafel and board members had mutually decided that it was time for Target
to continue under new leadership. Target shares were down close to 3 percent in
morning trading following the news.
Steinhafel’s untimely exit was the second significant executive fallout from the
data breach. In April 2014 Target’s CIO had also been replaced.
Sources: Compiled from D’Innocenzio (2014), Yadron et al. (2014), Krebs on Security (2014), Sharf (2014), O’Connor (2014), and Kratsas (2014).
Questions 1. Was cybersecurity a priority at Target? Explain. 2. How did lax security impact Target’s sales revenue and profi t performance? 3. According to experts, how was the data breach executed? 4. In addition to the data theft, what else was damaged by this incident? 5. Was this cybersecurity incident foreseeable? Was it avoidable? 6. Why might management not treat cyberthreats as a top priority? 7. Research recent news concerning this data breach. Has Target recovered
from it? Explain. 8. Assuming that the CEO and CIO were forced to resign, what message
does that send to senior management at U.S. companies?
Since 2013 the number of data records stolen by hackers has increased at an alarm-
ing rate, as shown in Figure 5.3. In fact, 2013 has been dubbed the “Year of the
Breach” because there were 2,164 reported data breaches that exposed an estimated 823 million records. Almost half of the 2013 breaches occurred in the United
States, where the largest number of records were exposed—more than 540 million
data records or 66 percent. Table 5.1 lists the top seven biggest data breaches
5.1 The Face and Future of Cyberthreats
Figure 5.3 Number of reported data records breached worldwide, 2009–2013.
900
600
800
700
300
400
500
200
100
0
2009
M il li o
n
2010 2011 2012 2013
193M
95M
413M
264M
823M
c05CybersecurityAndRiskManagement.indd Page 144 10/29/14 10:58 AM f-w-204a /208/WB01490/9781118897782/ch05/text_s