This is probably one of the better-communicated breaches that I've ever seen. Rather than hiding it for months, or trying to downplay the significance, Target is being painfully honest. They've mentioned the scope (40,000,000), the date range (27 Nov - 15 Dec), and the data (name, number, expiration date, CVV). Good for them.
http://pressroom.target.com/news/tar...-in-u-s-stores
https://corporate.target.com/discove...-to-payment-ca
Compromise of the POS (or would that be p.o.s.? lol) terminals is not unrealistic. Someone on the inside who has access to the POS controller software could have planted a subroutine that siphons the data of every swiped card into some remote database. Push that "update" out to every POS and voila, gold.
http://pressroom.target.com/news/tar...-in-u-s-stores
https://corporate.target.com/discove...-to-payment-ca
Compromise of the POS (or would that be p.o.s.? lol) terminals is not unrealistic. Someone on the inside who has access to the POS controller software could have planted a subroutine that siphons the data of every swiped card into some remote database. Push that "update" out to every POS and voila, gold.
Comment