Home Depot to pay states $17.5 million over massive 2014 data breach

U.S. states have reached a settlement over the mammoth 2014 Home Depot breach that will net them $17.5 million, plus an agreement from the home improvement retailer to strengthen its data security practices. The breach, which compromised 56 million payment card across the U.S., still ranks among the biggest data breaches ever. It’s been an expensive cleanup. Years after the attack, Home Depot estimated the cost at about $179 million and said it was likely to continue growing. The settlement with 46 states and the District of Columbia adds to the tally. It also comes one month after Home Depot suffered a data breach of its Canadian customers that was much smaller than the 2014 breach that was the subject of the U.S. settlement. “Instead of building a secure system, The Home Depot failed to protect consumers and put their data at risk,” New York Attorney General Letitia James said about the 2014 incident. […]

The post Home Depot to pay states $17.5 million over massive 2014 data breach appeared first on CyberScoop.

Continue reading Home Depot to pay states $17.5 million over massive 2014 data breach

Be Prepared for Increased DDoS Attacks Ahead of Black Friday

Black Friday is prime time for distributed denial-of-service (DDoS) attacks, especially as retail goes online even more than usual in 2020. Forecasters predict e-commerce sales will soar to new heights this holiday season, increasing by as much as 35% year-over-year. This explosion in online shopping brings new challenges to retailers, including managing logistics and supply chains. […]

The post Be Prepared for Increased DDoS Attacks Ahead of Black Friday appeared first on Security Intelligence.

Continue reading Be Prepared for Increased DDoS Attacks Ahead of Black Friday

Double-dipping scammers don’t need malware to grab card numbers and turn a profit, report says

Stolen credit card numbers sometimes spill onto the dark web for the most mundane reason: People carelessly give them up. According to researchers with Gemini Advisory, a China-based e-commerce scam appears to be harvesting payment information not through direct hacks on companies or using pernicious malware to skim data, but with a simpler approach. The fraudsters set up hundreds of websites that appear to sell legitimate goods, but instead capture card numbers for sale on the dark web, Gemini says. It ends up being a double-dip for the crooks: In addition to vending the card data and other information about shoppers in cybercriminal forums, they also collect money for items that are “faulty, counterfeit, or nonexistent,” Gemini says in a report published Thursday. The dark web sales have led to profits upwards of $500,000 over the past six months, but the total take is “likely significantly larger,” considering all the money the scammers […]

The post Double-dipping scammers don’t need malware to grab card numbers and turn a profit, report says appeared first on CyberScoop.

Continue reading Double-dipping scammers don’t need malware to grab card numbers and turn a profit, report says

Online Shoppers Undeterred by COVID as Holiday Shopping Season Shifts Earlier

Holiday shoppers are overcoming worries and restrictions and easily adapting to new shopping norms as the COVID-19 pandemic has invaded our lives and made us overwhelmingly dependent on online and mobile activity. According to an Akamai-commissioned su… Continue reading Online Shoppers Undeterred by COVID as Holiday Shopping Season Shifts Earlier

Online Shoppers Undeterred by COVID as Holiday Shopping Season Shifts Earlier

Holiday shoppers are overcoming worries and restrictions and easily adapting to new shopping norms as the COVID-19 pandemic has invaded our lives and made us overwhelmingly dependent on online and mobile activity. According to an Akamai-commissioned survey of more than 1,000 U.S. consumers conducted between October 31 and November 2, 2020, 73% of shoppers who have started gift hunting have done half to all their shopping online to date. And if they are not finished, 85% of consumers plan to do at least half of the remainder of their holiday shopping online. Continue reading Online Shoppers Undeterred by COVID as Holiday Shopping Season Shifts Earlier

Walmart Gives Up on Stock-Checking Robots

We’ve seen the Jetsons, Star Wars, and Silent Running. In the future, all the menial jobs will be done by robots. But Walmart is reversing plans to have six-foot-tall robots scan store shelves to check stock levels. The robots, from a company called Bossa Nova Robotics, apparently worked well enough …read more

Continue reading Walmart Gives Up on Stock-Checking Robots

Holiday Shopping Craze, COVID-19 Spur Retail Security Storm

Veracode’s Chris Eng discusses the cyber threats facing shoppers who are going online due to the pandemic and the imminent holiday season. Continue reading Holiday Shopping Craze, COVID-19 Spur Retail Security Storm

Is Black Friday a Thing of the Past? Not for Mobile

I recently ordered a new Weber grill from The Home Depot. When it was delivered, I discovered it was the floor model, and it wasn’t the perfect grill I had anticipated. I called the local store, and — long story short — my friends at The Home Depot gave me a significant discount for not letting me know ahead of time that it was the only one left and they didn’t want to disappoint me and not deliver anything. Suddenly, after a little elbow grease, my grill became perfect and I was over the moon. Why? Because we all love a great deal! Continue reading Is Black Friday a Thing of the Past? Not for Mobile

Dickey’s BBQ Breach: Meaty 3M Payment Card Upload Drops on Joker’s Stash

After cybercriminals smoked out 3 million compromised payment cards on the Joker’s Stash marketplace, researchers linked the data to a breach at the popular barbecue franchise. Continue reading Dickey’s BBQ Breach: Meaty 3M Payment Card Upload Drops on Joker’s Stash

Barnes & Noble cyber incident could expose customer shipping addresses, order history

Barnes & Noble told customers it was the victim of a cyberattack that led to “unauthorized and unlawful access” of its corporate systems. Barnes & Noble didn’t detail the entire nature of the “cybersecurity attack” in its email Wednesday, but confirmed that customers’ shipping addresses, billing addresses, email addresses and phone numbers could have been exposed. Payment card information wasn’t compromised as a part of this incident, but customers’ order history may also be exposed, according to Barnes & Noble. “We currently have no evidence of the exposure of any of this data, but we cannot at this stage rule out the possibility,” the bookseller said in its alert to customers. Customers’ access to Nook e-readers has also been interrupted, Barnes & Noble said on Twitter. It was unclear how many customers the incident impacted. Barnes & Noble did not disclose how it discovered the incident, only noting that it was “made aware” of it on Oct. 10. It’s […]

The post Barnes & Noble cyber incident could expose customer shipping addresses, order history appeared first on CyberScoop.

Continue reading Barnes & Noble cyber incident could expose customer shipping addresses, order history