ITB BLOG

Millions of Target customers should expect a surprise in their inboxes

What was already a catastrophically large security breach became ridiculously monumental today as Target notified the public that an additional 30 million customers have been added to the previous total of 40 million victims.

In Target parlance, ‘guests’ are customers, visitors, online shoppers and anyone who still dares to darken their steps in light of the new announcement – which the company says may account for up to six per cent in the drop in sales for the quarter.

For the rest of us, store visitors are at least browsers and at most, shoppers. Until they make a purchase, that is, at which point they become ‘customers’.

And customers, 70 million of them, are being notified that their names, credit and debit card numbers, card expiration dates, debit card PINs and even the code on their card’s magnetic strip has been stolen.

The bad news? The potential for fraud. Targeted, credit and debit card fraud. Identity theft and unauthorized online purchases. Scams of all kinds can be perpetrated with detailed customer profiles, and the Target breach is one of the richest treasure troves of contact details we have seen so far.

The other bad news? Victims can expect phishing emails to come in waves, from Target. Or rather, from what appears to be a legitimate source at Target.

How do we know? Because Target has announced that if you’re on the victims’ list and your email address is on file, they will contact you. And they described what it will look like:

Much of this data is partial in nature, but in cases where Target has an email address, we will attempt to contact affected guests. This communication will be informational, including tips to guard against consumer scams. Target will not ask those guests to provide any personal information as part of that communication. In addition, guests can find the tips at Target.com/databreach.

So American victims’ inboxes may soon be populated with phishing messages that look something not quite unlike this:

Subject: Important message regarding the security of your Target account

Body: Dear John Doe,

Target today announced updates on its continuing investigation into the recent data breach and its expected fourth quarter financial performance.

As part of Target’s ongoing forensic investigation, it has been determined that certain guest information — separate from the payment card data previously disclosed — was taken during the data breach.

This theft is not a new breach, but was uncovered as part of the ongoing investigation. At this time, the investigation has determined that the stolen information includes names, mailing addresses, phone numbers or email addresses for up to 70 million individuals.

I know that it is frustrating for our guests to learn that this information was taken and we are truly sorry they are having to endure this.

It will then draw the reader’s attention to the next paragraph:

As a valued guest, you will have zero liability for the cost of any fraudulent charges arising from the breach if you enroll into our free credit monitoring and identity theft protection program as soon as possible. Please note that the sooner you sign up, the faster we can activate your fraud protection. It only takes 4 minutes and is entirely voluntary. Click the following link or go to this site to sign up: Target.com/FraudProtect.

Once you have enrolled, you will receive a confirmation email that will also include simple tips and best practices you can use to protect your entire family against this kind of breach.

Sincerely,

Gregg Steinhafel, CEO
Target Brands, Inc.

Out of 70 million guests, it is safe to assume that at least a few million will have their email addresses on file. But guess what? The rest can be reached by phone, or reached by good old snail mail. And those emails don’t need to include a link to click on, but instead, a phone number to call. Addressing victims by name and even including the last four digits of their card number will go a long way towards earning the trust of both discerning and unsuspecting ‘guests’ alike.

The above link is benign, and a nod to a little known site that I used to enjoy working into conversations, but the risk of infecting computers and conning users is not only real, but imminent.

And that, above all, should be the message that is communicated to U.S. and Canadian shoppers alike.

Is this pure speculation? No. People are already getting defrauded as I’m typing this. Both Target and members of the media should focus on clarifying what the impact of this breach will be on individuals. They need to make it as real as possible to maximize the chances of defusing these malicious attempts before users instinctively react to them. Because by then, it may be too late.

Claudiu Popa
Claudiu Popahttp://www.SecurityandPrivacy.ca
Claudiu Popa is a security and privacy advisor to Canadian enterprises, associations and agencies. He is an author, speaker and lecturer. Connect with him on Twitter @datarisk, Facebook, G+ or LinkedIn.

Would you recommend this article?

Share

Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.


Jim Love, Chief Content Officer, IT World Canada

Featured Download

Latest Blogs

ITB in your inbox

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.