Welcome | Sign In
ECommerceTimes.com
Customer Data

Feds Throw Book at 11 Customer Data Theft Suspects

Print Version
E-Mail Article
Reprints
Feds Throw Book at 11 Customer Data Theft Suspects

The Department of Justice has mounted a massive prosecution to take down an identity theft ring that purloined millions of records from retailers and stole millions from their customers -- but the effort may do little to diminish the scale of the threat that's still out there.


The Department of Justice has charged 11 people with the theft of millions of account numbers from a long list of U.S. big box retailers including TJ Maxx, OfficeMax, Barnes & Noble, Boston Market, BJ's Wholesale Club, Forever 21, DSW, Dave & Buster's and Sports Authority.

Albert "Segvec" Gonzalez was the ringleader, according to the indictments, which were unsealed in San Diego and Boston. He is being held in New York on charges of computer fraud, wire fraud, access-device fraud, aggravated identity theft and conspiracy -- a roll call of crimes that could net him life in prison if he's convicted.

Others named in the indictment include three Americans, three Ukrainians, two Chinese nationals and two Eastern Europeans from Belarus and Estonia.

The account information was sold to other criminals who were able to cash out tens of millions of dollars, according to the indictments. Banks in Eastern Europe allegedly laundered the money.

The activities attributed to this group are at the center of the largest and most complex identity theft case ever built in the U.S., according to the prosecutors.

"If nothing else, this shows that data breaches and identity theft have become global crimes," Matt Cullina, CEO of Identity Theft 911, told CRM Buyer.

The sheer scale of this case, he said, will hopefully serve as a wake-up call to retailers that have not implemented necessary security precautions.

"There are too many retailers out there that are simply unprepared for this kind of crime, both in preventing it and then in how to notify customers," he remarked.

Low-Tech Access

The breathtaking scale of the hack attack belies the low-tech means by which the identity thieves were able to acquire the information. Essentially, they hacked into unsecured or minimally secured WiFi networks from the retail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse stores' parking lots -- a threat risk that was well known back in 2001. In one case, they were able to access the retailers' corporate database from a local wireless connection.

This crime wave -- and its subsequent public unveiling -- have left the retailers red-faced and, in the case of TJX, much poorer. The company has already agreed to pay more than US$60 million to credit card networks to settle complaints -- one of the largest settlements on record. Its IT operations will also be audited every two years for the next 20 years.

All told, the store will spend more than $150 million in costs related to the breach, said Phil Neray, VP at Guardium.

The attackers took advantage of some sophisticated technologies, he told CRM Buyer. Sniffer programs were installed on point-of-sale devices in many of the stores, for example. One hacker was able to access data in TJX's main data center in Framingham, Neray noted, through a wireless access point in Miami. Even that could have been prevented, though, if the retailer had properly segmented its network and installed monitoring technology in the data center.

One potential plus from this event, Neray suggested, is that the industry's understanding of what constitutes reasonable and appropriate security is likely to broaden.

Right now, retailers' security is abysmal, Michael Maloof of TriGeo Network Security told CRM Buyer. "Wireless systems can be easily secured -- if only by walking through a store's parking lot with a laptop to make sure you are not transmitting."

Customer data theft may be even more rampant than this particular case indicates. "Many stores don't know they have been hacked until complaints are made," Maloof commented.

The level of attacks is probably far higher than retailers or consumers want to acknowledge, echoed Jay Valentine, vice president of TDI.

"Companies are getting hacked internally -- particularly retailers -- every day," he told CRM Buyer. "The dirty little secret is that IT security people know it but are powerless to stop it, so they do nothing."

Consumer Issue

The charges no doubt will revive the debate over when -- and in how much detail -- a retailer should inform customers that their accounts might have been compromised.

"What we are seeing are cases in which disclosure by the retailer happens only after a period of weeks or months," Paul Davie, COO and cofounder of database security provider Secerno, told CRM Buyer.

"Ethically, these retailers need to let customers know if their data has been compromised as quickly as possible, so they can change credit cards and track for fraudulent charges."


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network