Target hit: hackers snag 40 million credit card accounts

Updated happygeek 3 Tallied Votes 414 Views Share

US retail giant Target that hackers gained access to payment card data that could mean 40 million credit and debit card accounts are at risk. An official statement says that the retailer is "aware of unauthorized access to payment card data that may have impacted certain guests making credit and debit card purchases in its U.S. stores" and is now working with law enforcement and financial institutions having "identified and resolved the issue".

The accounts in question were targeted, no excuse for the pun, between November 27th and December 15th in order to hit the increasingly busy seasonal shopping period. Gavin Millard, Technical Director at security experts Tripwire says that the two most worrying aspect to the breach "are time frame, because it occurred on the busiest shopping period in the US calendar year when millions flood to the big box retailers and the fact that the “track data” was captured, enabling the attackers to create counterfeit cards."

Meanwhile, Mark Bower, vice president at Voltage Security thinks that sadly this massive security breach is simply a reflection of the times we live in. "The size, scale and coordination required for this attack illustrates the lengths that attackers will go to steal valuable credit and debit information including card track data and CVV codes – the ultimate prize" Bower says. Typically there are two points in the retail chain where attacks take place – the POS or the payment switching back end. "POS systems are often the weak link in the chain and vulnerable" Bower continues "They often run a standard OS and are thus subject to exploits and zero-day attacks if exposed to a malware delivery channel such as a browser, a compromised POS management system, patch system or worse, from an insider."

The problem with POS and checkout systems during the seasonal shopping rush is that they are, pretty much, in constant use and therefore less frequently patched and updated. In turn, this leaves them more vulnerable to malware compromise impacting massive amounts of cardholder data. Although we don't yet know if this was the case at Target. If the breach was further up the chain, perhaps in the authorization and settlement switching systems in the retail back end, then the track data and CVV codes should never have been stored – even if encrypted. "There’s no need" Bower warns "and it’s forbidden under PCI DSS, yet sadly still happens."

Dani AI

Generated

A short, practical addendum to the discussion started by — and to the points raised by and — focused on what operators and affected parties can do right after a large retail payment incident. The advice below avoids repeating the incident details already posted and instead gives concrete, actionable steps and cautionary notes that remain useful long after the headlines fade.

Recommended actions for operators and IT/security teams:

  • Segment the payment environment from corporate and vendor networks; enforce deny-by-default firewall rules and remove admin tools from transactional segments.
  • Harden checkout endpoints with image-based provisioning and application allowlisting; remove or disable nonessential services and local admin accounts.
  • Adopt crypto-based protections that encrypt card data at the moment of capture and use tokenization for any stored values; validate every third‑party gateway or integrator against their attestation.
  • Lock down remote/vendor access: require multi-factor authentication, use audited jump hosts, and log all remote sessions for later review.
  • Improve detection: forward endpoint and network telemetry into a central SIEM/EDR, enable file-integrity checks, and create alerts for unusual memory reads or unexpected processes on checkout systems.
  • Keep an accurate inventory of hardware/software, implement a tested patch/maintenance cadence outside peak hours, and conduct regular penetration testing that includes vendor access paths.

Incident-response checklist (first 24–72 hours):

  • Isolate suspect devices, collect volatile memory and full disk images, and preserve network capture and remote-access logs.
  • Engage a forensic team experienced in payment-system investigations; notify acquiring bank(s) and card-brand contacts per contractual obligations.
  • Rotate credentials, reimage confirmed-compromised systems from known-good images, and maintain compensating controls until independent validation is complete.

Guidance for consumers and cardholders:

  • Enroll in transaction alerts and consider virtual/tokenized payment methods for online purchases; follow issuer instructions on card replacements and dispute suspicious entries. As observed, chip-based cards reduce in-person cloning but do not remove the need for strong backend protections and monitoring.

These steps assume compromise is possible and prioritize rapid containment, evidence preservation, and restoring trust while minimizing business disruption.

meta.quota 14 Newbie Poster

US should switch from mag strip to pinNchip tech ... just like the Uks .. much better dont you think ?

<M/> 170 Why so serious? Featured Poster

Well, you can't blame them... they were the biggest target out there ;)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.