Menu DaniWeb
Log In Sign Up
  • Read
  • Contribute
  • Meet
  1. Forums
  2. Hardware and Software
  3. Information Security
  4. News Stories
  5. News Story

SuperValu breach confirmed, security expert suggests Target link

12 Years Ago happygeek 1 Tallied Votes 340 Views Share

SuperValu has confirmed that is has, indeed, suffered a data breach. The supermarket company stated that what it calls a "criminal intrusion into the portion of its computer network that processes payment card transactions for some of its retail food stores, including some of its associated stand-alone liquor stores" may have resulted in "the theft of account numbers, and in some cases also the expiration date, other numerical information and/or the cardholder’s name, from payment cards used at some point of sale systems at some of the Company’s owned and franchised stores."

If you thought that was a bit of a mouthful as far as breach disclosures go, you probably wouldn't want to read the paragraph that follows and which states that the company "has not determined that any such cardholder data was in fact stolen by the intruder" and that it has no evidence to suggest the same. It goes on to say it's making the announcement "out of an abundance of caution." Cut through the cautious, and at times confusing, language and at least you can appreciate that SuperValu is doing the right thing. How timely it has been in doing that is harder to fathom.

The statement says that the earliest period the data could have been compromised was June 22nd, through to July 17th at the latest. What isn't 100% clear is exactly when the breach was discovered, although SuperValu does state it "took immediate steps to secure the affected part of its network" and that "an investigation supported by third-party data forensics experts is on-going to understand the nature and scope of the incident." What is clearer, however, is that 180 stores and stand-alone liquor outlets appear to have been involved including those operated under the banners of Cub Foods, Farm Fresh, Hornbacher’s, Shop ’n Save and Shoppers Food & Pharmacy banners. SuperValu states that it doesn't believe any of its 'Save-A-Lot' stores were impacted.

George Anderson, Director at security vendor Webroot, says he thinks "it’s actually refreshing to see how well SuperValu has handled the incident." Anderson cites numerous companies which have experienced harsh criticism for covering up breaches and not being transparent with customers, leaving them vulnerable to phishing attacks. "SuperValu on the other hand" he reckons "is a brilliant example of how a breach should be managed – openly providing information, informing customers, opening the investigation and offering free identity management service for those who could have been affected by the breach. Such actions show that the company has the right attitude to cyber security – accepting the fact that a cyber-attack is a matter of time, rather than a possibility and ensuring the right mitigation plans are put in place should the worse happen."

Meanwhile, Steve Hultquist who is chief evangelist at RedSeal Networks, say that this attack looks similar to the one that hit Target last year. "Retailers were warned at the time that more of them had likely been attacked" Hultquist explains "these breaches continue to demonstrate the sophistication of the attackers and the reward they receive being worth the investment they make in their attacks."

Investments which mean organizations must likewise increase their defensive investments, especially in the analysis of potential attack vectors. "Simply reacting while attacks are in progress is insufficient" Hultquist warns, concluding "each enterprise must know its network security architecture and have automated analysis to ensure that the entire end-to-end network complies with its policies. Not doing so is effectively agreeing to be attacked in unknown ways and having to deal with the impacts of a breach."

cybersecurity storage:data-protection
About the Author
Member Avatar for happygeek
happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

A freelance technology journalist for 30 years, I have been a Contributing Editor at PC Pro (one of the best selling computer magazines in the UK) for most of them. As well as currently contributing to Forbes.com, The Times and Sunday Times via Raconteur…

Dani AI

Generated 9 Months Ago

Good summary, . A few practical follow-ups that aren’t in the original post — focused on what incident responders, retail operators and cardholders should do next, and on the artifacts investigators usually look for.

Immediate incident-response priorities:

  • Isolate affected POS/network segments but keep devices powered for volatile evidence collection. Capture live memory before powering down, then image disks and export relevant log files.
  • Pull remote-access logs, firewall/IDS logs, DNS and proxy logs for the suspected window and the two weeks before it. Preserve vendor/third‑party account credentials and access records for forensic review.
  • Engage a qualified PCI forensic investigator and notify card brands and law enforcement as required; do not overwrite logs during triage.

Forensic signals and detection points to check:

  • Evidence of RAM‑scraping behavior (PANs in clear memory), unexpected processes or unsigned executables running alongside POS software, and unusual scheduled tasks or services.
  • Outbound connections to unfamiliar IPs or domains, especially over common ports (HTTP/HTTPS) used for exfiltration; bulk transfers from internal hosts.
  • Lateral movement indicators: admin tool use from non-admin workstations, new user accounts, or unusual RDP/SMB activity.

Mitigation and longer-term hardening:

  • Enforce strong segmentation: POS on its own VLAN with strict egress rules and no general Internet access. Require jump boxes and multi‑factor authentication for any remote vendor access and log everything.
  • Apply allowlisting on POS endpoints, remove unnecessary software, and reduce local admin rights. Centralize logs to a SIEM and create alerts for anomalous POS memory/process behavior.
  • Vendor management: unique, least‑privilege accounts; regular credential rotation; contractually enforced logging and access restrictions.

Cardholders: monitor statements, enable transaction alerts, and contact the card issuer immediately for suspicious charges. Merchants: communicate clearly and promptly with customers about what was affected and which remediation steps were taken; follow up with forensic findings when available.

Be the first to reply
Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.

Sign Up — It's Free!
Recommended Topics
  • Member Avatar Data Privacy Day sucks elephants through a straw, and here's why... 3
  • Member Avatar World Paper Free Day: ignore this paper thin security scare 1
  • Member Avatar Cant connect to any antivrus websites 31
  • Member Avatar Exposed: Indian visa application data accessible to anyone with a web browser 12
  • Member Avatar Multiple Problems with Vista Ultimate 6
  • Member Avatar Tor network hacked by Feds, Silk Road turned into honeypot? 4
  • Member Avatar plz hlp hijack log attached 3
  • Member Avatar Study: People comfortable disclosing info on sketchy-looking sites 3
  • Member Avatar popups in firefox 29
  • Member Avatar privacy preservation in medical data mining/ehr 0
  • Member Avatar Format help 1
  • Member Avatar Data Baby: the secret life of your smartphone 2
  • Member Avatar Vista Virus... can't open anything?!! 4
  • Member Avatar Hard disk showing no drives, where is all data? Can I get my data back? 9
  • Member Avatar Microsoft will not patch Internet Explorer zero-day flaw on Tuesday 3
  • Member Avatar How the hell is the NSA breaking SSL? 5
  • Member Avatar So Slow! 27
  • Member Avatar HELP_RESTORE_FILES.txt seems to have affected on my desktop, need help 7
  • Member Avatar How To Wipe Volume 3
  • Member Avatar Ripples still expanding from NoSQL Database host MongoHQ hack 1
Not what you need?

Reach out to all the awesome people in our information security community by starting your own topic. We equally welcome both specific questions as well as open-ended discussions.

Start New Topic
Topics Feed
Reply to this Topic
Edit Preview

Share Post

Insert Code Block

  • Forums
  • Forum Index
  • Hardware & Software
  • Programming
  • Digital Media
  • Community Center
  • Recent
  • Recommended Topics
  • Newest Topics
  • Latest Topics
  • Latest Posts
  • Latest Comments
  • Top Tags
  • Tools
  • Writing
    • Start New Topic
    • Markdown Syntax
    • Newsletter Archive
  • Social
    • Top Members
    • Meet People
  • APIs
    • Connect API
    • Forum API Docs
    • Topics Feed
  • Resources
  • Community Rules
  • DaniWeb Premium
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Legal
  • Terms of Service
  • Privacy Policy
© 2026 DaniWeb® LLC
© 2026 DaniWeb® LLC
  • FAQ
  • About Us
  • Advertise
  • Contact Us
  • Terms of Service
  • Privacy Policy