Boston Herald

CREDIT CARD DATA BREACH HITS SAKS

Northeast stores vulnerable

-

A data breach at department store chains Saks Fifth Avenue, Saks Off Fifth and Lord & Taylor has compromise­d the personal informatio­n of customers who shopped at the stores.

The chains’ parent company, Canada-based Hudson’s Bay Co., announced the breach of its store payment systems yesterday.

The company said it was investigat­ing and taking steps to contain the attack.

The disclosure came after New York-based security firm Gemini Advisory LLC revealed yesterday that a hacking group known as JokerStash or Fin7 began trying to sell a stash of up to 5 million stolen credit and debit cards on dark websites last week. The security firm confirmed with several banks that many of the compromise­d records came from Saks and Lord & Taylor customers.

Hudson’s Bay said in a statement that it “deeply regrets any inconvenie­nce or concern this may cause,” but it hasn’t said how many Saks or Lord & Taylor stores or customers were affected. The company said there’s no indication that the breach affected its online shopping websites or other brands, including the Home Outfitters chain or Hudson’s Bay stores in Canada.

The company says customers won’t be liable for fraudulent charges. It plans to offer free credit monitoring and other identity protection services.

There is evidence that the breach began about a year ago, said Dmitry Chorine, Gemini Advisory’s co-founder and chief technology officer. He said the prolific hacking group has previously targeted major hotel and restaurant chains.

Chorine said the hackers’ method is to send cleverly crafted phishing emails to company employees, especially managers, supervisor­s and other key decisionma­kers. Once an employee clicks on attachment, which is often made to look like an invoice, the system gets infected.

“For an entire year, criminals were able to sit on the network of Lord & Taylor and Saks and steal data,” he said.

Chorine said most of the stolen credit cards appear to have been obtained from stores in the New York City metropolit­an area and other Northeast U.S. states.

 ?? STAFF PHOTO BY CHRISTOPHE­R EVANS ?? SYSTEMS STRUGGLE: The Saks Fifth Avenue location at the Prudential Center in Boston is seen yesterday. The parent company of the famed retail outlet announced it has been hit by a data breach.
STAFF PHOTO BY CHRISTOPHE­R EVANS SYSTEMS STRUGGLE: The Saks Fifth Avenue location at the Prudential Center in Boston is seen yesterday. The parent company of the famed retail outlet announced it has been hit by a data breach.

Newspapers in English

Newspapers from United States