Questions- (Each question 100-150 words) I need 2 sets - No plagiarism

profilerkbangari
MISWeek5.pdf

monitoring, and identity theft insurance for affected con-

sumers. In October 2013 a data breach at Adobe exposed

the account information of up to 152 million users—the

largest data breach in history. No costs have yet been

reported, but according to the Ponemon 2013 Cost of Data Breach Study, the average cost of a breached account is $188 (Ponemon Institute, 2013). In August

2014, fraudsters targeted customers of JPMorgan Chase,

the No. 1 U.S. bank by assets. The massive phishing

campaign, called Smash and Grab, was unusual because it collected customers’ login data and also infected PCs

with Dyre, a banking trojan that lifted login data for

other institutions. The bank was not able to identify who

was behind the Smash and Grab attack. In Chapter 5, you will learn about devastating cyber-

threats, data breaches, fraud, damages caused by cyber-

criminals’ aggressive tactics—and how organizations

defend against them.

C A S E 5 . 1 O P E N I N G C A S E BlackPOS Malware Steals Target’s Customer Data

Target is a major discount retailer in the United States (Figure 5.1). Target’s man-

agement admitted that 40 million credit and debit card accounts were exposed

between November 27 and December 15, 2013. During that peak holiday shopping

season, hackers captured credit card data from the stores’ point-of-sale (POS)

payment terminals (Figure 5.2).

Target disclosed the breach on December 19, 2013; then on January 10, 2014,

the retailer also reported that hackers stole 40 million credit card numbers along

with the personal information of another 70 million customers. The incident scared

shoppers away, affecting the company’s profits throughout 2014.

142

Figure 5.1 Target data breach overview.

HOW THE ATTACK WAS CARRIED OUT

Several experts believe that POS malware bought from the criminal underground

was responsible. Malware, short for malicious software, are computer programs whose code causes disruption, destruction, or other devious action. Malware named

BlackPOS is sold on the black market for $1,800 or more. The malware is adver- tised on Internet underground forums under the generic name Dump Memory Grabber by Ree. BlackPOS is malware designed to be installed on POS devices in

2nd largest retail discounter in the

United States.

4Q 2013 profit dropped 46% and

sales revenue fell 5.3% after

breach was disclosed.

Company Profile Hackers installed malware,

probably bought from a criminal

underground website, on Target’s

POS terminals to capture data

from credit and debit cards and

transmit back to the hackers.

Data Breach

Personal and financial data from

up to 70 million customers stolen

by hackers using malware.

Estimated the breach to cost

from $400 million to $450 million.

Extent of the Breach and Costs

Target

c05CybersecurityAndRiskManagement.indd Page 142 10/29/14 10:58 AM f-w-204a /208/WB01490/9781118897782/ch05/text_s

CASE 5.1 Opening Case 143

order to record data from credit and debit cards swiped through the infected device.

Specifically, the malware identifies the process associated with the credit card

reader and steals payment card Track 1 and Track 2 data from its memory. These

are the data stored on the magnetic strip of payment cards that were used to clone

or create counterfeit cards.

More feature-rich versions of BlackPOS selling for roughly $2,300 provide

encryption support for stolen data. The BlackPOS creator is not confirmed, but

experts tracking the malware suggest that the hacker may be based in Russia or

Ukraine. The U.S. Secret Service estimated that the type of malware that led to

Target’s breach has affected over 1,000 U.S. businesses.

Figure 5.2 POS payment terminal. Malware-infected POS terminals caused Target’s data breach.

FINANCIAL IMPACT OF THE DATA BREACH

In February 2014 Target reported that its 2013 fourth-quarter (4Q) profit dropped

46 percent and sales revenue fell 5.3 percent. A few months later, in May 2014,

Target estimated that technological changes to harden its IT security would cost

more than $100 million in addition to $61 million incurred in breach-related

expenses in Q4 2013. These costs and damages harmed the company’s profitability.

Gregg Steinhafel, chairman, president, and CEO of Target, tried to reassure

customers and investors, saying, “As we plan for the new fiscal year, we will continue

to work tirelessly to win back the confidence of our guests. . . . We are encouraged

that sales trends have improved in recent weeks” (D’Innocenzio, 2014).

Six months after the breach, it still was not clear when Target would fully

recover. A security analyst at the tech firm Gartner estimated the costs of the breach

to range from $400 million to $450 million. That includes the bills associated with

fines from credit card companies and services for its customers like free credit card

report monitoring. Target also faced at least 70 lawsuits related to privacy invasion

and negligence, alleging Target did not take proper steps to protect consumer data.

TARGET BRUSHED OFF WARNINGS

According to financial services firm Cowen Group’s note to investors, criminals

were able to hack into Target’s database due to a lack of security, which might have

been a result of underinvestment by senior management.

Target’s cybersecurity staff had also warned management to review the security

of its payment card system at least two months before the breach. At the time of

the warning, Target was updating the payment terminals, which makes them more

vulnerable to attack, in preparation for the holiday season. Data security was not a

top priority. Months before the attack, the federal government and private research

firms were also warning companies about the emergence of new types of malware

© A

le p

h S

tu d

io /S

h u

tt e

rs to

ck

c05CybersecurityAndRiskManagement.indd Page 143 10/29/14 10:58 AM f-w-204a /208/WB01490/9781118897782/ch05/text_s

144 Chapter 5 Cybersecurity and Risk Management

(malicious computer code) targeting payment terminals. However, because of

numerous security warnings that retailers receive every week, it is difficult to identify

or decide which ones are the most urgent.

EXECUTIVE FALLOUT On May 5, 2014, CEO Steinhafel resigned from all his positions effective immedi- ately, after extensive discussions with the board of directors. Steinhafel had been

CEO since 2008 and a Target employee for 35 years. The company stated that

Steinhafel and board members had mutually decided that it was time for Target

to continue under new leadership. Target shares were down close to 3 percent in

morning trading following the news.

Steinhafel’s untimely exit was the second significant executive fallout from the

data breach. In April 2014 Target’s CIO had also been replaced.

Sources: Compiled from D’Innocenzio (2014), Yadron et al. (2014), Krebs on Security (2014), Sharf (2014), O’Connor (2014), and Kratsas (2014).

Questions 1. Was cybersecurity a priority at Target? Explain. 2. How did lax security impact Target’s sales revenue and profi t performance? 3. According to experts, how was the data breach executed? 4. In addition to the data theft, what else was damaged by this incident? 5. Was this cybersecurity incident foreseeable? Was it avoidable? 6. Why might management not treat cyberthreats as a top priority? 7. Research recent news concerning this data breach. Has Target recovered

from it? Explain. 8. Assuming that the CEO and CIO were forced to resign, what message

does that send to senior management at U.S. companies?

Since 2013 the number of data records stolen by hackers has increased at an alarm-

ing rate, as shown in Figure 5.3. In fact, 2013 has been dubbed the “Year of the

Breach” because there were 2,164 reported data breaches that exposed an estimated 823 million records. Almost half of the 2013 breaches occurred in the United

States, where the largest number of records were exposed—more than 540 million

data records or 66 percent. Table 5.1 lists the top seven biggest data breaches

5.1 The Face and Future of Cyberthreats

Figure 5.3 Number of reported data records breached worldwide, 2009–2013.

900

600

800

700

300

400

500

200

100

0

2009

M il li o

n

2010 2011 2012 2013

193M

95M

413M

264M

823M

c05CybersecurityAndRiskManagement.indd Page 144 10/29/14 10:58 AM f-w-204a /208/WB01490/9781118897782/ch05/text_s