Target declined to act on early alerts of cyber breach

Advertisement
By Reuters | Updated: 14 March 2014 10:59 IST
Target Corp's security software detected potentially malicious activity during last year's massive data breach, but its staff decided not to take immediate action, the No. 3. U.S. retailer said on Thursday.

"With the benefit of hindsight, we are investigating whether if different judgments had been made the outcome may have been different," company spokeswoman Molly Snyder said in a statement.

The disclosure came after Bloomberg Businessweek reported on Thursday that Target's security team in Bangalore had received alerts from a FireEye Inc security system on November 30 after the attack was launched and sent them to Target headquarters in Minneapolis.

(Also see: Target hackers stole encrypted bank PINs: Report)

Advertisement

The FireEye reports indicated malicious software had appeared in the system, according to a person whom Bloomberg Businessweek had consulted on Target's investigation but was not authorized to speak publicly on the matter.

Advertisement

The alert from FireEye labeled the threat with the generic name "malware.binary," according to Bloomberg Businessweek. Two security experts who advise organizations in responding to cyber attacks and both have experience using FireEye technology said that security personnel typically don't get excited about such generic alerts because FireEye does not provide much information about those threats.

The experts said that they believed it was likely that Target's security team received hundreds of such alerts on a daily basis, which would have made it tough to have singled out that threat as being particularly malicious.

Advertisement

"They are bombarded with alerts. They get so many that they just don't respond to everything," said Shane Shook, an executive with Cylance Inc. "It is completely understandable how this happened."

John Strand, owner of Black Hills Information Security, said that it was easy to paint Target as being incompetent, given the severity of the breach, but that it was not fair to do so.

Advertisement

"Target is a huge organization. They probably get hundreds of these alerts a day," he said. "We can always look for someone to blame. Sometimes it just doesn't work that way."

Target Chief Financial Officer John Mulligan told a congressional committee in February that the company only began investigating after on December 12, when the U.S. Justice Department warned the company about suspicious activity involving payment cards. Within three days, nearly all the malicious software had been removed from Target's cash registers, he said.

Follow up didn't seem warranted
"Through our investigation, we learned that after these criminals entered our network, a small amount of their activity was logged and surfaced to our team. That activity was evaluated and acted upon," Snyder said. "Based on their interpretation and evaluation of that activity, the team determined that it did not warrant immediate follow up."

Target shares fell 2 percent to $59.86 in late afternoon trading on the New York Stock Exchange after the company released the statement.

Some 40 million payment card records were stolen from the retailer, along with 70 million other records with customer information such as addresses and telephone numbers.

(Also see: Target says data breach affected 70 million customers)

Congress is investigating the breach along with lapses at other retailers, and credit card companies were pushing for better security.

Target also faces dozens of potential class-action lawsuits and action from banks that could seek reimbursement for millions of dollars in losses due to fraud and the cost of card replacements.

(Also see: Post-Target breach, US retail trade group calls for tougher security measures)

A spokesman for FireEye declined to comment. FireEye shares were up 1.8 percent at $79.05 on Nasdaq.

Representatives for the U.S. Secret Service and Verizon Communications Inc, which are investigating Target's breach, declined to comment.

FireEye has a function that automatically deletes malicious software, but it had been turned off by Target's security team before the hackers' attack, the Bloomberg report said, citing two people who audited FireEye's role after the breach.

Shook and Strand said that the vast majority of FireEye's customers turn off that functionality because it is known for incorrectly flagging data as malware, which can halt email and Web traffic for business users.

"FireEye is cutting edge," Strand said. "But it takes love and care and feeding. You have to watch it and monitor it."

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Sale 2025: OnePlus 13s, OnePlus Nord 5 Deals Revealed
  2. iPhone 16 Pro, iPhone 16 Pro Max Offers Listed Ahead of Flipkart Sale
  3. OnePlus 13 Gets Big Price Cut at Amazon Great Indian Festival Sale
  4. Nothing OS 4.0 Based Android 16 Announced With Extra Dark Mode, AI Dashboard
  5. Instamart Sale: iPhone 16, OnePlus 13R at Jaw-Dropping Prices
  6. Redmi 15R 5G With MediaTek Dimensity 6300 SoC, 6,000mAh Battery Launched
  7. iPhone 17 Series, iPhone Air Pre-Order Discounts Announced by Retailers in India
  1. Xbox Game Pass Wave 2 Titles for September Include RoadCraft, Frostpunk 2 and Hades
  2. Government Makes Cybersecurity Audits Mandatory for Crypto Exchanges Due to Rising Risks
  3. Apple's OLED MacBook Pro Model Could Feature a Touchscreen, Analyst Says
  4. CMF Headphone Pro India Launch Date Set for September 29; Design Teased
  5. Nothing OS 4.0 Announced; Brings New AI Dashboard to Track AI Usage, Extra Dark Mode and More
  6. Meta Connect 2025 Tomorrow: How to Watch Livestream, Expected Announcements
  7. Solar Storm From Hidden Magnetic Island on the Sun Surprises Scientists
  8. UK, US to Deepen Cooperation on Digital Assets Amidst US President Donald Trump’s State Visit
  9. ISRO Chairman Opens OrbitAID Research Facility to Boost On-Orbit Servicing in India
  10. Assassin's Creed IV: Black Flag Remake Will Reportedly Feature RPG Mechanics, Launch in Early 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.