The 2014 Neiman Marcus credit card data breach and security failures
✍️ How to write this paper — guide & tools ▾
¶ … 2014 business fraud situation that struck the Neiman Marcus Group. Topics discussed in this paper include a summary of the situation, control issues, and how losses could have been mitigated.
Business Fraud Background
Business frauds are pervasive. They can occur anywhere, with anyone, and take any form; some examples of business fraud are: no-risk-guaranteed internet offers, a contractor pocketing deposits for an individual's home repairs and vanishing, or false advertising of a product/service (Lee). While prevention is the best way to save oneself from fraudulent business transactions, even those customers who are extremely watchful and hesitant may get fooled. Those who get swindled generally feel overly embarrassed and avoid reporting the fraud.
The Case/Control Issues
In 2014, Dallas-based luxury retailer, Neiman Marcus's credit-card database was raided by hackers. As per an internal investigation of the organization, the hackers triggered alarms on the security systems of the company around 60,000 times when they stole into the network (Elgin, et.al, 2014). Though they visited the company's systems over and over again for no less than 8 months and stole card data from July to October 2014, this activity went unnoticed by the firm. On some days, hundreds of alarms would be activated, as the software employed for stealing cards would be automatically deleted daily from Neiman Marcus's payment records, and required constant reloading.
A spokesperson for the company, Ginger Reeder maintains that the highly professional hackers named their hacking software almost identically to Neiman Marcus's payment software, causing all 60,000 alerts to go unnoticed among the flood of data the security team had to review routinely. She further says that the alerts that popped up throughout a three and half month period would, typically, have been no more than 1% of daily alerts showing up on the security system, which is hit daily by thousands of entries (Elgin, et.al, 2014). Investigation launched by the company revealed that the actual number of credit cards whose data was stolen by hackers was lesser than the 1.1 million estimated and quoted originally by the firm. Reeder claims that the latest estimate revealed that fewer than 350,000 cards of customers were exposed, and about 9,200 of these have been used illegally since the incident.
The company also faced control issues. For instance, the report states that Neiman Marcus' centralized security network, which logged suspicious activity, pointed out a program's abnormal behavior, but failed to identify the code as malicious, thereby failing to erase it. Investigators also discovered that the feature in the system for automatically blocking flagged suspicious activity was disabled as maintenance (e.g. patching security defects) would have been hampered by it (Elgin, et.al, 2014). The retailer's point-of-sales system design, based on the hub-and-spoke model, was easy for hackers to work through; the POS system connects payment registers of individual Neiman Marcus retail outlets to one central computer, which processes transactions. This arrangement enabled hackers to quickly reload their hacking software onto several registers daily. Furthermore, hackers took over a weak server, which enabled them to get around the security barriers of the POS system; the server, through a general-purpose linkage, connected to Neiman Marcus 'POS' system as well as the Internet. In November 2014, new regulations were issued to companies asking them to rigorously test their networks' security.
Loss Mitigation
Theft of credit card information from Neiman Marcus' customers rekindled demands for securer debit and credit cards, like those of Europe and other countries; some congressmen and government communities have begun renewed talks for strengthening consumer protection legislations. The credit card and retail sectors have turned their focus to EMV (Eurocard, MasterCard and Visa) technology, after the biggest-ever U.S. retail hack on Target, during which 40 million credit card numbers were stolen. Cards that use EMV technology are embedded with a tiny chip, which generates a new secret code at the time of each transaction, rendering card counterfeiting, which accompanied the Target hacking, virtually impossible (Harris, et.al, 2014). One among the last nations to incorporate EMV technology is the U.S. Consulting company, Celent, reports that 81% of European credit cards come with EMV chips. Nations that have incorporated EMV have recorded a drastic fall in credit card scams. Since the year 2002, frauds per credit card transactions in Britain have fallen 57%; contrastingly, a sharp increase (70%) in fraud in the U.S. has been reported by Celent from 2004-2010. The U.S. accounts for only 27% of the world's credit card-based transactions, but records 47% of world card fraud, as per a payment industry newsletter, TheNilson Report (Harris, et.al, 2014). Revealing the state of affairs, an executive of MasterCard, Chris McWilton says that while most of the advanced world has adopted updated technology (with regards to card security systems), the U.S. still uses the 1960s'"magnetic stripe technology" thus becoming an easy target for fraudsters. If the U.S. would readily develop and accept new technology, a lot of its card frauds problems could be solved.
Create your account
Always verify citation format against your institution’s current style guide requirements.