SalemNews.com, Salem, MA

Nation/World

December 28, 2013

Target: Customers' encrypted PINs were stolen

ATLANTA — Target said yesterday that debit-card PINs were among the financial information stolen from millions of customers who shopped at the retailer earlier this month.

The company said the stolen personal identification numbers, which customers type into keypads to make secure transactions, were encrypted and that this strongly reduces risk to customers. In addition to the encrypted PINs, customer names, credit and debit card numbers, card expiration dates and the embedded code on the magnetic strip on back of the cards were stolen from about 40 million credit and debit cards used at Target stores between Nov. 27 and Dec. 15.

Security experts say it’s the second-largest theft of card accounts in U.S. history, surpassed only by a scam that began in 2005 involving retailer TJX Cos.

“We remain confident that PIN numbers are safe and secure,” spokeswoman Molly Snyder said in an emailed statement yesterday. “The PIN information was fully encrypted at the keypad, remained encrypted within our system, and remained encrypted when it was removed from our systems.”

However, Gartner security analyst Avivah Litan said yesterday that the PINs for the affected cards are vulnerable and people should change their codes since such data has been decrypted, or unlocked, before. In 2009 computer hacker Albert Gonzalez pleaded guilty to conspiracy, wire fraud and other charges after masterminding debit and credit card breaches in 2005 that targeted retailers such as T.J. Maxx, Barnes & Noble and OfficeMax. Gonzalez’s group was able to unlock encrypted data. Litan said changes have been made since then to make decrypting more difficult but “nothing is infallible.”

“It’s not impossible, not unprecedented (and) has been done before,” she said.

Besides changing your PIN, Litan says shoppers should instead opt to use their signature to approve transactions because it is safer. Still, she said Target did “as much as could be reasonably expected” in this case.

“It’s a leaky system to begin with,” she said.

Credit card companies in the U.S. plan to replace magnetic strips with digital chips by the fall of 2015, a system already common in Europe and other countries that makes data theft more difficult.

Minneapolis-based Target Corp. said it is still in the early stages of investigating the breach. It has been working with the Secret Service and the Department of Justice.

1
Text Only | Photo Reprints
Nation/World

Local News
  • Baker(1) GOP's Baker to unveil plan to fight drug addiction

    BOSTON (AP) — Republican candidate for governor Charlie Baker has unveiled what he's calling a comprehensive approach to tackling the drug addiction crisis in Massachusetts.

    July 31, 2014 1 Photo

  • 140730_SN_DLE_DEMOLITION5 Demolition of Salem Harbor Station begins

    SALEM -- It all begins with B5. Or ends, depending on how you look at it. Demolition began at Salem Harbor Station Wednesday afternoon, with crews first setting upon one of the power plant's 11 steel tanks. The work was supposed to begin Monday, but

    July 31, 2014 7 Photos

  • Market Basket seeks replacement workers through job fair next week

    Market Basket began advertising a job fair for store managers and assistant managers in a direct shot at the current managers who signed petitions Monday threatening to resign if former CEO Arthur T. Demoulas is not rehired. The ad, which will appear

    July 31, 2014 2 Stories

  • Mary Manning Recovering Salem principal says thanks

    SALEM -- Just about a month before she was set to retire after 25 years as the principal of Collins Middle School, Mary Manning entered the hospital with a life-threatening condition. She hasn't been home since. A month later, in June, friends and co

    July 31, 2014 1 Photo 1 Story

  • Former school janitor Robert Scribner sentenced for assaults in truck

    SALEM -- A now-former Marblehead school janitor was ordered to serve a year in jail Wednesday after pleading guilty to charges that he assaulted and threatened to kill his estranged girlfriend after trapping her in his pickup truck in May. Robert Scr

    July 31, 2014