<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; Hannaford</title>
	<atom:link href="http://www.endpoint-security.info/tag/hannaford/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Fri, 03 Sep 2010 13:39:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Data theft record: 130 million card accounts stolen by Albert Gonzales</title>
		<link>http://www.endpoint-security.info/2009/08/24/data-theft-record-130-million-card-accounts-stolen-by-albert-gonzales/</link>
		<comments>http://www.endpoint-security.info/2009/08/24/data-theft-record-130-million-card-accounts-stolen-by-albert-gonzales/#comments</comments>
		<pubDate>Mon, 24 Aug 2009 05:29:18 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Albert Gonzales]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Hannaford]]></category>
		<category><![CDATA[Heartland]]></category>
		<category><![CDATA[TJX]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=282</guid>
		<description><![CDATA[Security magazines and news sites have been raving about the case of Albert Gonzales. This man holds a record no one is really proud of: he has been charged with the largest number of stolen credit and debit cards accounts, about 130 million of them. The story of Gonzales is rather complicated. After being indicted [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F08%2F24%2Fdata-theft-record-130-million-card-accounts-stolen-by-albert-gonzales%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F08%2F24%2Fdata-theft-record-130-million-card-accounts-stolen-by-albert-gonzales%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Security magazines and news sites have been raving about <a title="Heartland breach supect" href="http://www.theregister.co.uk/2009/08/17/heartland_payment_suspect/" target="_blank">the case of Albert Gonzales</a>. This man holds a record no one is really proud of: he has been charged with the largest number of stolen credit and debit cards accounts, about 130 million of them.</p>
<p>The story of Gonzales is rather complicated. After being indicted in May in the TJX breach – the one thought to be the largest in history until recently, it is said Gonzales has worked with the authorities to help them find all those involved in breaches he had taken part in.<a title="Gonzales'Attorney Statement" href="http://www.theregister.co.uk/2009/08/20/albert_gonzalez_attorney/" target="_blank"> While his defense lawyer was looking forward to a settlement</a>, new charges have surfaced. The federal authorities have charged him for attacks that breached credit card processor Heartland Payment Systems, retailers 7-Eleven and Hannaford Brothers, and a couple of other companies.</p>
<p>Gonzales seems to be behind <a title="Breaches Gonzales was involved in" href="http://www.securityfocus.com/news/11557?ref=rss" target="_blank">all the largest data heists of the past few years</a>:</p>
<ul>
<li>130 million credit and debit card accounts taken from Heartland Payment Systems&#8217; servers</li>
<li>at least 94 million credit and debit card accounts stolen from TJX</li>
<li>4.2 million accounts were stolen from Hannaford&#8217;s servers</li>
</ul>
<p><a title="Mega-Breaches based on common attacks" href="http://www.darkreading.com/database_security/security/attacks/showArticle.jhtml?articleID=219400495&amp;cid=RSSfeed" target="_blank">According to DarkReading</a>, all the attacks Gonzales was involved in used familiar, easy to prevent methods to obtain the information they wanted:</p>
<blockquote><p>While the attacks appear to be phased-in and coordinated, the attackers didn&#8217;t employ any hacks that the victim organizations could not have defended against, experts say. SQL injection, for instance, is the most commonly exploited flaw in Web attacks, according to data from the Web Hacking Incident Database.</p></blockquote>
<p>Fortunately, Gonzales is being held responsible for the breaches. Let’s just hope no one gets their minds on setting a new record! Apparently, it’s easy to achieve.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2009/08/30/all-time-record-hacker-pleads-guilty/" rel="bookmark" class="crp_title">All-time-record hacker pleads guilty</a></li><li><a href="http://www.endpoint-security.info/2008/03/31/thieves-planted-malware-on-300-hannaford-servers/" rel="bookmark" class="crp_title">Thieves Planted Malware on 300 Hannaford Servers</a></li><li><a href="http://www.endpoint-security.info/2008/05/20/tjx-suspect-charged-along-with-2-other-hackers/" rel="bookmark" class="crp_title">TJX Suspect Charged Along With 2 Other Hackers</a></li><li><a href="http://www.endpoint-security.info/2008/04/01/hannaford-an-inside-job/" rel="bookmark" class="crp_title">Hannaford &#8211; An Inside Job</a></li><li><a href="http://www.endpoint-security.info/2008/03/18/second-largest-security-breach-recently-exposed/" rel="bookmark" class="crp_title">Second Largest Security Breach Recently Exposed</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/08/24/data-theft-record-130-million-card-accounts-stolen-by-albert-gonzales/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Hannaford &#8211; An Inside Job</title>
		<link>http://www.endpoint-security.info/2008/04/01/hannaford-an-inside-job/</link>
		<comments>http://www.endpoint-security.info/2008/04/01/hannaford-an-inside-job/#comments</comments>
		<pubDate>Tue, 01 Apr 2008 15:44:12 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Hannaford]]></category>
		<category><![CDATA[IT security]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/2008/04/01/hannaford-an-inside-job/</guid>
		<description><![CDATA[Recent details on the Hannaford security breach point to an inside job. It appears Hannaford employees are most likely to have planned and then infected over 300 servers of the grocery chain. Experts said the breach should serve as a big lesson for retailers: It&#8217;s as important to limit the network access of employees and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F04%2F01%2Fhannaford-an-inside-job%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F04%2F01%2Fhannaford-an-inside-job%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1307486,00.html" title="Search Security Article" target="_blank">Recent details on the Hannaford security breach</a> point to an inside job. It appears Hannaford employees are most likely to have planned and then infected over 300 servers of the grocery chain.</p>
<blockquote><p>Experts said the breach should serve as a big lesson for retailers: It&#8217;s as important to limit the network access of employees and regularly monitor system activity as it is to purchase security technology to block attacks from the outside. Furthermore, it&#8217;s foolish for a company to consider itself bulletproof because they achieved PCI DSS compliance, as Hannaford&#8217;s claims it did.</p>
<p>&#8220;The overarching conclusion I have that keeps getting reinforced is that the low-hanging fruit is inside the company and insiders are always getting more network privileges,&#8221; said Mark MacAuley, a York, Maine-based IT security consultant who shops at Hannaford&#8217;s regularly. &#8220;I don&#8217;t see how anyone at Hannaford could get that level of access unless they were a very well-known entity.&#8221;</p></blockquote>
<p>The Hannaford data breach has exposed over 4 million credit card accounts, thus being the second largest breach ever reported.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/03/31/thieves-planted-malware-on-300-hannaford-servers/" rel="bookmark" class="crp_title">Thieves Planted Malware on 300 Hannaford Servers</a></li><li><a href="http://www.endpoint-security.info/2008/03/18/second-largest-security-breach-recently-exposed/" rel="bookmark" class="crp_title">Second Largest Security Breach Recently Exposed</a></li><li><a href="http://www.endpoint-security.info/2008/04/27/credit-cart-info-of-wisebuy-customers-stolen/" rel="bookmark" class="crp_title">Credit Card Info of WiseBuy Customers Stolen</a></li><li><a href="http://www.endpoint-security.info/2009/08/24/data-theft-record-130-million-card-accounts-stolen-by-albert-gonzales/" rel="bookmark" class="crp_title">Data theft record: 130 million card accounts stolen by Albert Gonzales</a></li><li><a href="http://www.endpoint-security.info/2009/06/26/data-breach-costs-tjx-settles-for-9-75-million-dollars/" rel="bookmark" class="crp_title">Data breach costs: TJX settles for 9.75 million dollars</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/04/01/hannaford-an-inside-job/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thieves Planted Malware on 300 Hannaford Servers</title>
		<link>http://www.endpoint-security.info/2008/03/31/thieves-planted-malware-on-300-hannaford-servers/</link>
		<comments>http://www.endpoint-security.info/2008/03/31/thieves-planted-malware-on-300-hannaford-servers/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 19:12:07 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Hannaford]]></category>
		<category><![CDATA[IT security]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/2008/03/31/thieves-planted-malware-on-300-hannaford-servers/</guid>
		<description><![CDATA[Since it made security magazines&#8217; headlines, the Hannaford data breach that exposed 4.2 million credit card accounts still ranks high in the news. The question on everyone&#8217;s mind is how it could all happen. According to the latest article published by The Register on the topic, the thieves behind the breach installed a sophisticated malicious [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F03%2F31%2Fthieves-planted-malware-on-300-hannaford-servers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F03%2F31%2Fthieves-planted-malware-on-300-hannaford-servers%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Since it made security magazines&#8217; headlines, <a href="http://www.endpoint-security.info/2008/03/18/second-largest-security-breach-recently-exposed/" title="Hannaford breach" target="_blank">the Hannaford data breach</a> that exposed 4.2 million credit card accounts still ranks high in the news. The question on everyone&#8217;s mind is how it could all happen. According to the <a href="http://www.theregister.co.uk/2008/03/28/massive_credit_card_breach_explained/" title="Hannaford story" target="_blank">latest article published by The Register</a> on the topic, the thieves behind the breach installed a sophisticated malicious software on over 300 servers in at least 6 states belonging to the Hannaford grocery chain.</p>
<p>What the malware did was to intercept credit card data while customers paid for purchases using plastic and then transmit the information overseas. While Hannaford has disclosed the number of servers on which the malware has been detected, they are yet to disclose how it got there. Security experts are quite puzzled by this incident, as they regard Hannaford as a legal and standard compliant company.</p>
<blockquote><p>Security experts have been eager to figure out how thieves siphoned the data out of Hannaford Brothers Cos. network because the company is believed to have been following payment card industry (PCI) rules. If the east coast chain&#8217;s systems were vulnerable, plenty of other retailers may be open to the same attack, the experts have warned.</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/04/01/hannaford-an-inside-job/" rel="bookmark" class="crp_title">Hannaford &#8211; An Inside Job</a></li><li><a href="http://www.endpoint-security.info/2008/03/18/second-largest-security-breach-recently-exposed/" rel="bookmark" class="crp_title">Second Largest Security Breach Recently Exposed</a></li><li><a href="http://www.endpoint-security.info/2008/04/27/credit-cart-info-of-wisebuy-customers-stolen/" rel="bookmark" class="crp_title">Credit Card Info of WiseBuy Customers Stolen</a></li><li><a href="http://www.endpoint-security.info/2009/08/24/data-theft-record-130-million-card-accounts-stolen-by-albert-gonzales/" rel="bookmark" class="crp_title">Data theft record: 130 million card accounts stolen by Albert Gonzales</a></li><li><a href="http://www.endpoint-security.info/2009/08/30/all-time-record-hacker-pleads-guilty/" rel="bookmark" class="crp_title">All-time-record hacker pleads guilty</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/03/31/thieves-planted-malware-on-300-hannaford-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
