BreachExchange mailing list archives

SCHNUCKS RELEASES DETAILS OF CARD ISSUE AS INVESTIGATION NEARS END


From: Erica Absetz <erica () riskbasedsecurity com>
Date: Tue, 16 Apr 2013 10:03:26 -0400

http://www.schnucks.com/pressreleases/pressrelease.asp?id=219

ST. LOUIS – Leaders of St. Louis-based Schnuck Markets, Inc., today
announced that between December 2012 and March 29, 2013, approximately
2.4 million credit and debit cards used at 79 of its 100 stores may
have been compromised.  The company emphasizes that only the card
number and expiration date would have been accessed – not the
cardholder’s name, address or any other identifying information.



Schnucks has posted a list of the 79 stores and specific dates for
each store at www.schnucks.com.  In addition, Schnucks has distributed
a timeline of the actions taken to investigate, find, contain, and
share information about the cyber-attack, as well as a personal video
message from Chairman and CEO Scott Schnuck.



“On behalf of myself, the Schnuck family, and all of our 15,000
teammates, I apologize to everyone affected by this incident,” said
Scott Schnuck. “Over the years, technology has helped us deliver
superior customer service, but it also introduces risks that we have
actively worked to manage through compliance audits, encryption
technology and various other security measures.”



“We’ve worked hard to provide a secure transaction environment for our
customers and, today I make a personal pledge to you that we will be
relentless in maintaining the security of our payment processing
system. We expect that the actions we have taken and will take in the
future will send a clear signal that our customers may continue to
trust us,” said Schnuck.



Schnucks has worked with its payment processor to make sure all
potentially affected card numbers are sent to the credit card
companies so that they may continue sending alerts to the issuing
banks.  Those banks will then be able to take steps to protect their
cardholders, such as adding enhanced transaction monitoring or
reissuing a new card.  Many banks have already taken these steps.



“Customers have asked me if it is safe to shop at Schnucks,” continued
Schnuck. “Yes, we believe it is, and we will work hard to keep it that
way.”



Schnucks has created a dedicated call center for customers if they
have additional questions about what happened and steps they can take
to protect themselves. Please call 1-888-414-8022, Monday – Friday, 9
a.m. – 5 p.m. and through the weekend Saturday and Sunday, April
20-21, from 9 a.m. – 4 p.m.



Schnucks provided the Secret Service and FBI with information about
the methods and tools used by the attacker and has worked and will
continue to partner with law enforcement to apprehend those
responsible.
_______________________________________________
Dataloss-discuss Mailing List (dataloss-discuss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security equips organizations with security intelligence, risk
management services and on-demand security solutions to establish
customized risk-based programs to address information security and
compliance challenges. 

Tenable Network Security (http://www.tenable.com/)
Tenable Network Security provides a suite of solutions which unify real-time
vulnerability, event and compliance monitoring into a single, role-based, interface
for administrators, auditors and risk managers to evaluate, communicate and
report needed information for effective decision making and systems management.


Current thread: