Assignment 3: Target Data Breach

Great Essays
In the year 2013, one of the biggest retail data breaches in history occurred, where Target lost the credit and debit cards of over 40 million customers, along with the personal information of 70 million customers. It all started right before Thanksgiving on November 27, when someone installed malware in Target’s security and payments system that was designed to steal every credit card used at the company’s many stores throughout the United States. When a shopping item was scanned and the cashier processed the credit card number, the malware would apprehend the number, then store it on a Target server hijacked by the hackers (Riley). This went unnoticed for three days until the hackers uploaded extraction malware to move the stolen data, and …show more content…
In addition, they failed to respond to multiple automated warnings from the company 's antivirus software, that the attackers were installing malicious software and making escape routes for the information they planned to steal (Bloomberg). And during their Congressional hearings, Target admitted it was true that security software did detected potentially malicious activity during the massive data breach, but its staff decided not to take immediate action. With situations like this, it shows how important it is to have a trained workforce with time to appropriately analyze logs that would have uncovered the malware and allowed them to network traffic to lessen losses had the breach still occurred. In the end, Target has felt the impact of this breach for a long time, from having to restructure its security system to making a settlement, where a 10 million dollar fund will be established for victims of the attack. Likewise, after an event like this, let’s hope Target has shown fellow retailers and other enterprises how to avoid this

Related Documents

  • Improved Essays

    On December 2014, Anthem’s databased was compromised by someone that used their credentials to run a query. The breach was not discovered until January 2015. Anthem Inc. security breach was made public in February 2015, and affected at least 80 millions of people. Anthem was at the moment the second-largest health insurance company in the nation. Their president and CEO, Joseph Swedish said to the media: “Anthem was the target of a very sophisticated external cyber-attack.…

    • 552 Words
    • 3 Pages
    Improved Essays
  • Great Essays

    Target Attacker Timeline Date 1: 10/8/2013. (Estimated date) Reconnaissance and scanning: Attackers acquired Fazio Mechanical Firm’s user code and password through a phishing email containing a Trojan called Citadel, a password sniffing bot program. The phished credentials provided access to Target’s payment system network. Extensive reconnaissance and scanning would have been needed in order to identify Fazio Mechanical as a Target vendor, and acquire the emails of employees that possessed the login credentials necessary to access Target’s systems. Date 2: November 11th 2013 (Around 34 days after date 1) Exploitation: Attackers first breach Target’s system.…

    • 591 Words
    • 3 Pages
    Great Essays
  • Decent Essays

    Based on their interpretation and evaluation of that activity, the team determined that it did not warrant immediate follow up," said Target spokeswoman Molly Snyder via email. Target had all the measures to fight against such incidents. For example fireeye was designed…

    • 332 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    Well before the breach on Target, the company had already been receiving alerts. Evidently, the company’s million-dollar investment of FireEye’s did what it was supposed to do by alerting Target on numerous occasions (Riley, M., Elgin, B., Lawrence, D.). The worst part about this attack was that it was done by “script kiddies”, which is a person who basically uses other people’s scripts and codes to hack into computers. Overall Target had what they needed as far as security tools to keep this from happening, but an employee didn’t do what was necessary. It could very well be that the staff was not properly trained on roles and responsibility; this in turn led to the passivity of the alerts that were sent.…

    • 216 Words
    • 1 Pages
    Improved Essays
  • Decent Essays

    Target Executive Summary

    • 343 Words
    • 2 Pages

    In December 2013, criminals forced their way into systems, gaining access to guest credit and debit card information. It was determined that certain guest information was also taken, for example, the information included names, mailing addresses, email addresses or phone numbers. The massive data breaches at Target were broken into the retailer's network using login credentials stolen from a heating, ventilation and air conditioning company. The hackers first tested the data-stealing malware on a small number of cash registers. The cost of the breach was far reaching to Target, customers, employees and banks.…

    • 343 Words
    • 2 Pages
    Decent Essays
  • Improved Essays

    Data breaches caused by illegal hacking at Target were in themselves tragedies and worrisome events; not only for the company, but for the customers in general who shop at the store locations nation-wide. However, considering various steps taken by Target upon realization of the breaches, it is hard to defend or picture exact wrongful doings or violation of laws by Target. Let’s keep in mind that electronic data and information breaches are hard to prevent; this is mostly due to interconnectivities of globally devices. As such, laws do not persecute companies for hackers breaking into their networks; instead, there are laws binding companies to put required secure methods and practices in place to mitigate hacking or data thefts; also, once a breach is noticed, laws require that such incident be reported immediately and those affected be notified. Here's what happened after; "Target alerted authorities and financial institutions immediately after we discovered and confirmed the unauthorized access, and we are putting our full resources behind these efforts.…

    • 567 Words
    • 3 Pages
    Improved Essays
  • Decent Essays

    Steinhafel Case Analysis

    • 508 Words
    • 3 Pages

    Greg Steinhafel resigned as CEO of Target following the 2013 data breach. In his resignation, he took full responsibility for the breach, but agreed to stay on board as an advisor during the transition. Target is facing backlash from its customers and has lost millions of dollars to the hackers, customers and banks that had to reimburse their clients following Target's data breach. This breach happened right at "Black Friday" and continued into December 2013. After the breach was discovered, Target and it's board members and financial advisors had to come together to figure out how to prevent this kind of thing from occurring in the future and how to regain the trust of their customers.…

    • 508 Words
    • 3 Pages
    Decent Essays
  • Improved Essays

    In January 2015, just less than two years that Target had expanded to Canada, they had come to the conclusion that they would be closing down all of their 133 stores within the country, laying off 17,600 employees (Scott, 2015). The company’s CEO, Brian Cornell, voiced to the media how tough this decision was to make but how necessary it was for the company, in order to successfully continue their operations within the United States. The main reason Target had to shut down within Canada was because they were incapable of earning any sort of profit until the year 2021 (Scott, 2015). Target had also lost approximately one billion dollars during their first year in business within Canada (Evans, 2015). The most devastating part about this closure was the fact that 17,600 employees, both full and part-time, were going to lose their jobs.…

    • 486 Words
    • 2 Pages
    Improved Essays
  • Improved Essays

    Target Financial Analysis

    • 786 Words
    • 4 Pages

    Target attempted to extend its company to Canada. This created a downfall financially. In 2014, accounts receivables declined. This caused a negative effect on both current and total assets. This…

    • 786 Words
    • 4 Pages
    Improved Essays
  • Improved Essays

    Target Breach Essay

    • 1427 Words
    • 6 Pages

    Target could have truly prevented this attack from happening. However, due to negligence on the company's behalf, the network upgrade was tabled and the consumers suffered that decision. The Target Corporation failed to be good stewards over the consumer's trust, and causing the consumer's sensitive information to be compromised. In hindsight, had the security systems been the top priority the data breach may have been avoided.…

    • 1427 Words
    • 6 Pages
    Improved Essays
  • Improved Essays

    Target Breach

    • 1769 Words
    • 8 Pages

    I believe this was the best move for the company. They could not inform the public before they fixed the problem. Target also released multiple press releases following the incident to keep customers informed on the hack. I believe Target informed the customer’s in a timely manner, but could have done it in a better way. They emailed the customers in regards to the data breech, but so were spammers and other hackers.…

    • 1769 Words
    • 8 Pages
    Improved Essays
  • Improved Essays

    Ackman Case Study Summary

    • 960 Words
    • 4 Pages

    Credit Card Sales Target initially claimed that its credit card business continued to be highly profitable. While accounts receivables that were due by over 60 days…

    • 960 Words
    • 4 Pages
    Improved Essays
  • Great Essays

    C. Common Causes of Data Breach The four common causes of data breaches includes the absence of policy, unencrypted dives, lack of security defenses and insider negligence [22]. Insider negligence of private information is one of the top reasons for a data breach. This includes an employee accident that leads to a data breach, and the use of a third-party that is negligent. For example, in 2009 an unencrypted laptop was stolen from the car of an Oregon Health & Science University employee which exposed the information of about 1,000 patients.…

    • 1541 Words
    • 6 Pages
    Great Essays
  • Superior Essays

    As consumers, we trust corporations with private information like phone numbers, home addresses, SSID numbers, and in some cases interests or search history. Facebook and Google, which are tech giants, sells out your history to companies like Target to advertise merchandise on the internet that is personally tailored to you. Target and other well known stores have been hacked for customer information. A few easy rules to follow to prevent getting hacked are not shopping online and pay with cash as much as possible. According to Lee Rainie, an expert in research in internet, science and technology if one cannot, they are among “91% of Americans who say they do not have control of their personal information online”(Rainie 7).…

    • 1159 Words
    • 5 Pages
    Superior Essays
  • Improved Essays

    Today’s internet has become an integral part of our daily lives. It changed the world in so many positive ways, but it has also a negative side to it. The negative issues that we are facing today with internet are our online privacy and data breaches. Recently, many people were divided in terms of their strong views about the importance of privacy and the exchange “between security needs and personal privacy” (Rainie & Maniam, 2016) as millions of Americans were also affected by online threats and privacy breaches and at the same time concerned with our security. The focus has been on government monitoring, although there are some other significant issues and concerns about how industries use our data.…

    • 952 Words
    • 4 Pages
    Improved Essays