{"id":77488,"date":"2015-07-09T21:28:02","date_gmt":"2015-07-10T01:28:02","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-07-31T17:01:03","modified_gmt":"2021-07-31T21:01:03","slug":"data-breach-is-no-monkey-business","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/data-breach-is-no-monkey-business\/","title":{"rendered":"Data Breach Is No Monkey Business"},"content":{"rendered":"<p>Re<img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-98579\" title=\"Data Breach Is No Monkey Business\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/monkey_at_computer.jpg?resize=102%2C90&#038;ssl=1\" alt=\"Data Breach Is No Monkey Business\" width=\"102\" height=\"90\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/monkey_at_computer.jpg?resize=150%2C133&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/monkey_at_computer.jpg?resize=75%2C66&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/monkey_at_computer.jpg?w=200&amp;ssl=1 200w\" sizes=\"auto, (max-width: 102px) 100vw, 102px\" \/>ports are emerging that zoo\u2019s across the nation have fallen victim to a <strong>POS attack and data breach<\/strong>. <a href=\"http:\/\/www.mlive.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>MLive<\/em><\/a> <a href=\"http:\/\/www.mlive.com\/news\/detroit\/index.ssf\/2015\/07\/credit_card_data_breach_at_det_1.html#incart_river_news\" target=\"_blank\" rel=\"noopener noreferrer\">warns<\/a> anyone who made a purchase with a credit card at gift shops at the <strong><a href=\"http:\/\/www.detroitzoo.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">Detroit Zoo<\/a><\/strong> between March 23 and June 25, 2015, might be in danger of having the <strong>credit card information stolen<\/strong>. The Detroit Zoo posted a <a href=\"https:\/\/web.archive.org\/web\/20150905055319\/http:\/\/www.detroitzoo.org\/Plan\/shopping-in-the-zoo\" target=\"_blank\" rel=\"noopener noreferrer\">notice<\/a> which claims that the only systems hacked were those run by Denver-based <a href=\"https:\/\/web.archive.org\/web\/20240511202344\/http:\/\/www.kmssa.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Service Systems Associates<\/strong><\/a>, the third-party responsible for running the systems at the Detroit\u00a0Zoo&#8217;s retail stands.<\/p>\n<p><a href=\"http:\/\/www.detroitzoo.org\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-98582\" title=\"Detroit Zoo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Det_zoo_logoi.gif?resize=205%2C54&#038;ssl=1\" alt=\"Detroit Zoo\" width=\"205\" height=\"54\" \/><\/a>SSA posted a <a href=\"https:\/\/web.archive.org\/web\/20160712140443\/http:\/\/www.kmssa.com:80\/creditcardbreach\/\" target=\"_blank\" rel=\"noopener noreferrer\">notice<\/a> on their site confirming a breach but no other details. Officials are investigating data breaches of the point-of-sale systems at nine or more U.S. zoos, including the Detroit Zoo. <em>MLive<\/em> reports that hackers gained access to card holders&#8217; names, expiration dates, <a href=\"https:\/\/web.archive.org\/web\/20191101014229\/https:\/\/searchfinancialsecurity.techtarget.com\/definition\/card-verification-value\" target=\"_blank\" rel=\"noopener noreferrer\">CVV security codes<\/a> in addition to the credit and debit card numbers.<\/p>\n<p>Sources claim the malware has been since identified and removed from the systems, though the case remains under investigation. In response, A separate credit card processing system was installed after the Zoo learned of the breach. Gerry VanAcker, Detroit Zoological Society chief operating officer, said in a\u00a0release:<\/p>\n<p style=\"text-align: justify; padding-left: 30px;\"><em>We are obviously concerned that the vendor&#8217;s system was compromised,&#8221; s &#8220;Transactions made since June 26 are not affected by the previous breach, and it is safe to use a credit or debit card at SSA&#8217;s retail locations.<\/em><\/p>\n<p><em><a href=\"https:\/\/web.archive.org\/web\/20130425014808\/http:\/\/www.riskafrica.com:80\/fraud-a-growing-problem-in-africa\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-98584 size-medium\" title=\"Data thief\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_thief.jpg?resize=100%2C150&#038;ssl=1\" alt=\"Data thief\" width=\"100\" height=\"150\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_thief.jpg?resize=100%2C150&amp;ssl=1 100w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_thief.jpg?resize=50%2C75&amp;ssl=1 50w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_thief.jpg?w=200&amp;ssl=1 200w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/><\/a><a href=\"https:\/\/krebsonsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Krebs on Security<\/a><\/em> <a href=\"https:\/\/krebsonsecurity.com\/2015\/07\/credit-card-breach-at-a-zoo-near-you\/\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> that the attack is widespread. Mr. Krebs cites financial industry sources that say the breach likely involves <strong>SSA concession and gift shops<\/strong> at zoo locations in Alabama, Arizona, California, Florida, Hawaii, Idaho, Indiana, Minnesota, Ohio, Oklahoma. Pennsylvania, South Caroline, Texas, and Tennessee.<\/p>\n<p>Systems used at the Detroit Zoo for tickets food sales and membership sales were not affected by the breach and remain secure. Anyone who made a purchase via credit or debit card at a Zoo gift shop should check their bank statements immediately.<\/p>\n<p>Those who expect that their identity has been stolen are asked to contact one of the consumer reporting agencies and place a fraud alert on their credit report.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em>Why don&#8217;t these POS companies give a damn? I have covered POS data breaches a <a href=\"https:\/\/wp.me\/p2wgaW-iyk\" target=\"_blank\" rel=\"noopener\">number<\/a> of <a href=\"https:\/\/wp.me\/p2wgaW-jLM\" target=\"_blank\" rel=\"noopener\">times<\/a> from the <a href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a>. POS breaches have been the largest source of data disclosure for at least 3 years. Of course, we know the answer, follow the money. <\/em><\/p>\n<p><em>F<a href=\"https:\/\/www.bullguard.com\/blog\/2014\/03\/pos-system-hacks-malware-target.html\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-98587 size-medium\" title=\"POS system\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pos_system.jpg?resize=150%2C101&#038;ssl=1\" alt=\"POS system\" width=\"150\" height=\"101\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pos_system.jpg?resize=150%2C101&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pos_system.jpg?resize=75%2C51&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pos_system.jpg?w=300&amp;ssl=1 300w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>irms like SSA have no accountability. There are no costs or fines or even a demerit on their permanent record when they get breached. It is less costly for companies like SSA to allow a breach to happen than it is to update their systems and stop the attackers.<\/em><\/p>\n<p><em>Maybe that will change in the future. Beginning in October 2015 firms like SSA that have not yet installed card readers which accept more secure chip-based cards will <a href=\"https:\/\/web.archive.org\/web\/20201117224740\/http:\/\/blogs.wsj.com\/corporate-intelligence\/2014\/02\/06\/october-2015-the-end-of-the-swipe-and-sign-credit-card\/\" target=\"_blank\" rel=\"noopener noreferrer\">assume responsibility<\/a> for the cost of fraud from counterfeit cards. \u00a0&#8211; maybe.<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"http:\/\/www.denverpost.com\/business\/ci_28460864\/colorado-springs-zoo-gift-store-part-credit-card\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Colorado Springs zoo gift store part of credit card security breach<\/a> (denverpost.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Another POS hack and data breach this time it is Service Systems Assoc. at the Detroit Zoo check your bills see if you are a victim<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3277,2442,125,2494,166,2495,23,19,951,2206,4],"class_list":["post-77488","post","type-post","status-publish","format-standard","hentry","category-security","tag-3277","tag-credit-card","tag-data-breach","tag-debit-card","tag-detroit","tag-detroit-zoo","tag-malware","tag-michigan","tag-pii","tag-pos","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/77488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=77488"}],"version-history":[{"count":11,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/77488\/revisions"}],"predecessor-version":[{"id":131717,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/77488\/revisions\/131717"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=77488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=77488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=77488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}