Applied IAM

The Privileged Access Blind Spot: Retail

The retailers breached in recent years have something in common with Target a decade earlier: the attackers did not break in. They logged in — through a vendor, a shared store login or an account that outlived the season. The three incidents below all share that entry.

Two pagesPublic reporting onlyFreeWritten by certified engineers
The incidents

Three breaches, one pattern

Marks & Spencer

Attackers posed as someone who worked with the retailer and got a third party, reportedly its outsourced help desk, to reset a password. No exploit to get in — a sophisticated impersonation. (Source: BleepingComputer)

Adidas

Customer contact data exposed through a third-party customer service provider; no passwords or payment details were involved. (Source: The Register)

Target

The breach that set the pattern more than a decade ago: an HVAC contractor's credential, a flat network behind it, and too little segmentation to stop the move from vendor access to payment systems. (Source: KrebsOnSecurity)

The read-across

What the pattern means for you

Hundreds of stores, thousands of seasonal staff and a cardholder environment PCI-DSS expects you to keep separate. The gap is almost always the same: a credential with more reach than anyone checked, in a store network nobody was watching.

Self-check

The 60-second self-check

  • How many accounts from last peak season are still active?
  • Is every login into the cardholder environment individual, with MFA — no shared till or back-office accounts?
  • Which vendors have remote access into store networks, and when was each last reviewed?
  • Does your store manager hold local admin on every device in the building?
  • Has your segmentation been tested this year, or assumed?

If any answer is "no" or "I would have to ask", that is the blind spot.

The full brief

Get the full brief

The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.

Next

Where to go next

The sector page: identity security for retail. The service that closes the gap: PAM implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.

Get the Retail brief

Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.