Q&A: What Home Depot customers can now expect
By Byron Acohido
If you’re one of the millions of folks who used a payment card at a Home Depot store this past spring or summer your identity may be at risk. ThirdCertainty asked Chris Camejo, director of assessment services at NTT Com Security, to outline the go-forward ramifications of the Home Depot breach.
3C: What should anyone who shopped at Home Depot in the past few months expect next?
Camejo: Home Depot’s customers should be checking their credit and debit card statements carefully to make sure there are no fraudulent purchases or withdrawals, and they shouldn’t be surprised if their card gets shut off and/or replaced with little or no notice. I’m sure Home Depot and the banks are frantically trying to identify those accounts so that they can cancel the stolen cards before they lose any more money to fraud.
3C: What are the data thieves up to?
The thieves are selling the stolen cards on black market websites right now. At this point it’s basically a race to see how many fraudulent transactions the carders can run through before the banks figure out which cards were affected and replace them. I’m sure Home Depot and the banks are frantically trying to identify those accounts so that they can cancel the stolen cards before they lose any more money to fraud.
3C: How useful are the free consulting services merchants offer to customers when a big breach gets disclosed.
Camejo: Home Depot is offering the usual ‘free identity theft monitoring’ which is pointless in a way. Identity theft monitoring is to check if someone is opening new lines of credit in your name which would require a SSN. There’s no need to do that when the attacker has stolen the line of credit you’ve already opened.
3C: Home Depot must now meet data loss disclosure laws in 47 states. How onerous is that going to be?
Camejo: Most of the laws are fairly similar so notifying people shouldn’t be too bad once they actually identify all of the people that were affected. One of the loopholes in the disclosure laws is that the disclosure can be delayed if requested by law enforcement and the Secret Service typically gets involved in these big fraud cases. I wouldn’t be surprised if much of the information is kept under wraps so that they can try to nail the perpetrators.
3C: So far Target, PF Chang, UPS, Goodwill, P. F. Chang’s, Sally Beauty, Michael’s, Neiman Marcus and now Home Depot have disclosed breaches. What does this suggest about the true scope of breaches of major chains?
Camejo: It’s not very surprising, big companies handle lots of transactions and are therefore enticing targets, it takes much less effort to break into one network and steal 40 million accounts than it does to break into 400 networks and steal 100,000 accounts each. These large companies are also at a disadvantage because they’re so big: every system that is attached to a network is another potential vulnerability that can be exploited, and these big companies likely have many more systems than small and medium merchants.
3C: Anything else?
Camejo: Home Depot and Target are moving to chip-and-pin payment systems. Unfortunately this alone won’t solve much. Chip cards send their data to the terminal unencrypted just like magstripe cards and could be captured in nearly the same way. The captured card data may not be usable at another chip-and-pin merchant, but it can be used to make online purchases or cloned onto a magstripe card and used at a merchant that doesn’t support chip-and-pin.