The Union Recorder

Homepage

December 27, 2013

Target: Customers' encrypted PINs were stolen

ATLANTA — Target said Friday that debit-card PINs were among the financial information stolen from millions of customers who shopped at the retailer earlier this month.

The company said the stolen personal identification numbers, which customers type into keypads to make secure transactions, were encrypted and that this strongly reduces risk to customers. In addition to the encrypted PINs, customer names, credit and debit card numbers, card expiration dates and the embedded code on the magnetic strip on back of the cards were stolen from about 40 million credit and debit cards used at Target stores between Nov. 27 and Dec. 15.

Security experts say it's the second-largest theft of card accounts in U.S. history, surpassed only by a scam that began in 2005 involving retailer TJX Cos.

"We remain confident that PIN numbers are safe and secure," spokeswoman Molly Snyder said in an emailed statement Friday. "The PIN information was fully encrypted at the keypad, remained encrypted within our system, and remained encrypted when it was removed from our systems."

However, Gartner security analyst Avivah Litan said Friday that the PINs for the affected cards are vulnerable and people should change their codes since such data has been decrypted, or unlocked, before. In 2009 computer hacker Albert Gonzalez pleaded guilty to conspiracy, wire fraud and other charges after masterminding debit and credit card breaches in 2005 that targeted retailers such as T.J. Maxx, Barnes & Noble and OfficeMax. Gonzalez's group was able to unlock encrypted data. Litan said changes have been made since then to make decrypting more difficult but "nothing is infallible."

"It's not impossible, not unprecedented (and) has been done before," she said.

Besides changing your PIN, Litan says shoppers should instead opt to use their signature to approve transactions because it is safer. Still, she said Target did "as much as could be reasonably expected" in this case.

Text Only
Local News
04-16 Craig Center update_file.jpg

The Georgia Department of Behavioral Health & Developmental Disabilities decided the Craig Nursing Center won’t close June 30, instead postponing the date to Aug. 31. The state is trying to remedy inadequate supervision of individuals with developmental disabilities transitioning to community group homes highlighted in a recent independent review.

Features
UR_20140412_B001.jpg

Business
Local Yolkal Cafe.JPG

The Local Yolkal Café celebrates its one-year anniversary as downtown Milledgeville's only breakfast, brunch and lunch restaurant.

Local Sports
04-10 GMC Prep Baseball 1.JPG

Dalton Threatt led the Bulldogs on the mound in yesterday’s loss to FPD at home. The senior pitched over five innings against the Vikings.

Editorials
Columns
Letters
Local Weather Radar
Poll
AP Video
Facebook
Twitter Updates
Follow us on twitter
Parade
Magazine

Click HERE to read all your Parade favorites including Hollywood Wire, Celebrity interviews and photo galleries, Food recipes and cooking tips, Games and lots more.
Stocks
NDN Video