Senate investigators accused Target on Tuesday of making serious missteps that allowed hackers to steal millions of credit card numbers from its system.
Target “missed a number of opportunities”¦ to stop the attackers and prevent the massive data breach,” the Senate Commerce Committee aides wrote in a report.
The findings could expose Target to a lawsuit from the Federal Trade Commission, which has sued dozens of companies in recent years for failing to adequately protect customer data from hackers.
Molly Snyder, a Target spokeswoman, said the company’s investigation is ongoing.
“With the benefit of hindsight, we are investigating whether, if different judgments had been made the outcome may have been different,” she said.
The hackers stole credit card numbers for as many as 40 million Target customers between Nov. 27 and Dec. 15 of last year, according to the retailer. The hackers obtained other personal information such as names and addresses for another estimated 70 million customers.
The report comes ahead of Wednesday’s Senate Commerce Committee hearing which will feature testimony from John Mulligan, Target’s chief financial officer, and FTC Chairwoman Edith Ramirez.
The report details how the hackers breached Target’s system and identifies numerous points where Target could have prevent the theft of its customers’ data.
Target gave access to its network to a small Pennsylvania heating and air conditioning vendor, Fazio Mechanical Services, which had “weak security,” according to the report.
The hackers used malware to infiltrate the vendor and then used the vendor’s credentials to access Target’s system, the investors found. Even then, Target could have disrupted the hack if it responded to its internal alerts.
“Target appears to have failed to respond to multiple warnings from the company’s anti-intrusion software regarding the escape routes the attackers planned to use to exfiltrate data from Target’s network,” the Senate aides wrote.
In public financial filings, Target has acknowledged that it is under investigation by the FTC and state attorneys general over the breach.
Senate Commerce Committee Chairman Jay Rockefeller is pushing legislation that would expand the FTC’s ability to crack down on companies for inadequate data security. His bill, the Data Security and Breach Notification Act, would give the FTC the authority to set data security rules and the power to fine companies for violations.
The legislation would also set a national standard requiring companies to notify customers in the event of a breach.
“While Congress deserves its share of the blame for inaction, I am increasingly frustrated by industry’s disingenuous attempts at negotiations,” the West Virginia Democrat said in a statement. “It’s time for industry to work with us on legislation that reinforces the basic protections American consumers have a right to count on.”
What We're Following See More »
Foreign Policy takes a look at the future of mining the estimated "100,000 near-Earth objects—including asteroids and comets—in the neighborhood of our planet. Some of these NEOs, as they’re called, are small. Others are substantial and potentially packed full of water and various important minerals, such as nickel, cobalt, and iron. One day, advocates believe, those objects will be tapped by variations on the equipment used in the coal mines of Kentucky or in the diamond mines of Africa. And for immense gain: According to industry experts, the contents of a single asteroid could be worth trillions of dollars." But the technology to get us there is only the first step. Experts say "a multinational body might emerge" to manage rights to NEOs, as well as a body of law, including an international court.
Not to be outdone by Jeffrey Goldberg's recent piece in The Atlantic about President Obama's foreign policy, the New York Times Magazine checks in with a longread on the president's economic legacy. In it, Obama is cognizant that the economic reality--73 straight months of growth--isn't matched by public perceptions. Some of that, he says, is due to a constant drumbeat from the right that "that denies any progress." But he also accepts some blame himself. “I mean, the truth of the matter is that if we had been able to more effectively communicate all the steps we had taken to the swing voter,” he said, “then we might have maintained a majority in the House or the Senate.”
Ronald Reagan's children and political allies took to the media and Twitter this week to chide funnyman Will Ferrell for his plans to play a dementia-addled Reagan in his second term in a new comedy entitled Reagan. In an open letter, Reagan's daughter Patti Davis tells Ferrell, who's also a producer on the movie, “Perhaps for your comedy you would like to visit some dementia facilities. I have—I didn’t find anything comedic there, and my hope would be that if you’re a decent human being, you wouldn’t either.” Michael Reagan, the president's son, tweeted, "What an Outrag....Alzheimers is not joke...It kills..You should be ashamed all of you." And former Rep. Joe Walsh called it an example of "Hollywood taking a shot at conservatives again."
In a sign that she’s ready to put a longer-than-expected primary battle behind her, former Secretary of State Hillary Clinton (D) is no longer going on the air in upcoming primary states. “Team Clinton hasn’t spent a single cent in … California, Indiana, Kentucky, Oregon and West Virginia, while” Sen. Bernie Sanders’ (I-VT) “campaign has spent a little more than $1 million in those same states.” Meanwhile, Sen. Jeff Merkley (D-OR), Sanders’ "lone backer in the Senate, said the candidate should end his presidential campaign if he’s losing to Hillary Clinton after the primary season concludes in June, breaking sharply with the candidate who is vowing to take his insurgent bid to the party convention in Philadelphia.”
The team behind the bestselling "Clinton Cash"—author Peter Schweizer and Breitbart's Stephen Bannon—is turning the book into a movie that will have its U.S. premiere just before the Democratic National Convention this summer. The film will get its global debut "next month in Cannes, France, during the Cannes Film Festival. (The movie is not a part of the festival, but will be shown at a screening arranged for distributors)." Bloomberg has a trailer up, pointing out that it's "less Ken Burns than Jerry Bruckheimer, featuring blood-drenched money, radical madrassas, and ominous footage of the Clintons."