Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It

Other discussions not related to the Permanent Portfolio

Moderator: Global Moderator

Post Reply
User avatar
MachineGhost
Executive Member
Executive Member
Posts: 10054
Joined: Sat Nov 12, 2011 9:31 am

Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It

Post by MachineGhost »

It’s a measure of how common these crimes have become, and how conventional the hackers’ approach in this case, that Target was prepared for such an attack. Six months earlier the company began installing a $1.6 million malware detection tool made by the computer security firm FireEye (FEYE), whose customers also include the CIA and the Pentagon. Target had a team of security specialists in Bangalore to monitor its computers around the clock. If Bangalore noticed anything suspicious, Target’s security operations center in Minneapolis would be notified.

On Saturday, Nov. 30, the hackers had set their traps and had just one thing to do before starting the attack: plan the data’s escape route. As they uploaded exfiltration malware to move stolen credit card numbers—first to staging points spread around the U.S. to cover their tracks, then into their computers in Russia—FireEye spotted them. Bangalore got an alert and flagged the security team in Minneapolis. And then …

Nothing happened.


http://www.businessweek.com/articles/20 ... -card-data
"All generous minds have a horror of what are commonly called 'Facts'. They are the brute beasts of the intellectual domain." -- Thomas Hobbes

Disclaimer: I am not a broker, dealer, investment advisor, physician, theologian or prophet.  I should not be considered as legally permitted to render such advice!
ns3
Executive Member
Executive Member
Posts: 274
Joined: Thu Jan 09, 2014 8:46 pm

Re: Missed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It

Post by ns3 »

To understand how a big company like Target could make a major investment in security software and then ignore the warnings it issued from Bangalore you would have to work at a company like mine.
Post Reply