A large East Coast supermarket chain is the latest victim of a major data breach, with as many as four million credit- and debit-card numbers exposed. Hannaford Bros., based in Maine, announced the “containment of a data intrusion into its computer network” that resulted in the theft of data, but added that “no personal information, such as names and addresses, was accessed or obtained.” The company said it is “aware of fewer than 2,000 cases of reported fraud related to this crime.”
Hannaford operates 165 stores along the East Coast and, under the name of Sweetbay Supermarket, another 106 stores in Florida. The company is owned by the Delhaize Group of Brussels, Belgium. Also affected by the breach are an unknown number of independent retailers in the Northeast that sell Hannaford products.
According to a statement from Hannaford, “data was illegally accessed from Hannaford’s computer systems during the card-authorization transmission process.” A statement from Hannaford CEO Ron Hodge said that the stolen data “was limited to credit- and debit-card numbers and expiration dates,” not names or addresses, and that the company “doesn’t know or keep any personally identifiable information from customers.”
Attacks on Data in Transit
“What showed up here was a new trend where criminals are going after data in transit, as opposed to data at rest. I think everybody was caught off-guard by that,” Avivah Litan, a security analyst for Gartner, told us.
Payment Card Industry standards from credit-card issuers mandate that retailers take security measures such as protecting stored cardholder data and encrypting the transmission of data across open networks. Despite the breach, Litan said Hannaford could possibly have been in compliance with PCI standards.
“When you swipe a card, it should be encrypted immediately,” she said, but often it’s not until the data gets to the cash register that encryption happens; in…