Marks & Spencer
Attackers posed as someone who worked with the retailer and got a third party, reportedly its outsourced help desk, to reset a password. No exploit to get in — a sophisticated impersonation. (Source: BleepingComputer)
The retailers breached in recent years have something in common with Target a decade earlier: the attackers did not break in. They logged in — through a vendor, a shared store login or an account that outlived the season. The three incidents below all share that entry.
Attackers posed as someone who worked with the retailer and got a third party, reportedly its outsourced help desk, to reset a password. No exploit to get in — a sophisticated impersonation. (Source: BleepingComputer)
Customer contact data exposed through a third-party customer service provider; no passwords or payment details were involved. (Source: The Register)
The breach that set the pattern more than a decade ago: an HVAC contractor's credential, a flat network behind it, and too little segmentation to stop the move from vendor access to payment systems. (Source: KrebsOnSecurity)
Hundreds of stores, thousands of seasonal staff and a cardholder environment PCI-DSS expects you to keep separate. The gap is almost always the same: a credential with more reach than anyone checked, in a store network nobody was watching.
If any answer is "no" or "I would have to ask", that is the blind spot.
The two-page PDF adds the full account of each incident and the control that would have stopped it. Name and work email, and it comes straight back.
The sector page: identity security for retail. The service that closes the gap: PAM implementation. And a free audit is 30 minutes with a certified engineer on your own environment, findings in writing: Get a free audit.
Name and work email. The two-page PDF covers each incident in full and the control that would have stopped it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.