Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Daily News Digest – 17th February 2014

by The Gurus
February 17, 2014
in Opinions & Analysis
Share on FacebookShare on Twitter

After US retailer Target was the victim of a massive breach at the start of this year, UK retailers would not have been breathing a sigh of relief at the news in case the same thing befalls them.
 
As it turns out, one of the UK’s premier retailers has suffered a data breach with 2,239 loyalty card holders’ details published. Being in the headlines of the security press is nothing new for Tesco, after it was revealed that it sent passwords in plain text in 2012 and subsequently faced an investigation from the Information Commissioner, it faced a similar problem last week.
 
As we reported, Tesco said that the data was stolen from other sites after hackers were believed to have trawled lists of previously hacked accounts from other sites for matching login and password details for Tesco.com.
 
Hunt said: “The problem is that Tesco’s security profile makes this sort of attack simple. Their approach to security provides numerous avenues for attackers to easily verify the existence of accounts and then establish their passwords.”
 
Hunt, who set up the aggregation website haveibeenpwned.com to allow users to check their email address against 160 million breached records, said that the accounts did not come from any of the sources he had worked with.
 
“What would concern me if I was in Tesco’s shoes is that clearly someone has a workable attack vector that’s exploiting their accounts. Whether they’re brute forcing accounts one by one or simply testing for reused credentials from other breaches, the fact remains that accounts have been compromised en masse. I would not for a moment assume that the extent of the damage is only a couple of thousand accounts, that’s almost certainly only the tip of the iceberg,” he said.
 
“Many of the serious security problems that Tesco had in mid-2012 remain both in terms of discrete risks I called out (such as password strength), and as a cultural approach to security in general. There are still numerous easily observable risks discoverable simply by browsing the website, who knows what might lie beneath that and is readily discoverable with a little probing.”
 
Trey Ford, global security strategist at Rapid7, said that this highlights the dangers of people reusing passwords and other security credentials across multiple accounts, and while it does not indicate that Tesco was breached, this was about consumer behaviour. “People continue to reuse passwords and other credentials across multiple sites, making it easy for attackers to compromise them. It’s essential to learn the lesson from this incident before the cost becomes greater.”
 
Going by some of the opinions that appeared in my inbox, the blame should be laid at the feet of the retailer. Tim ‘TK’ Keanini, CTO of Lancope, said that if retailers “would spend half the time on cyber security analytics as they spend on consumer analytics predicting buying patterns, the cybercriminals would have a very hard time being successful as their behaviour could be predicted and retailers would have more effective defences”.
 
Elsewhere, Jason Hart, vice president of cloud solutions at SafeNet, said that this should serve as a reminder to all retailers of the threat posed by data breaches as this is not the first time that super
markets have fallen foul to a cyber attack.
 
Calum MacLeod, VP of EMEA at Lieberman Software Corporation, said that Tesco is typical of retailers who continue to invest in the minimum security to keep auditors happy and invest in technologies that don’t solve real problems but tick compliance boxes. “There’s no point in buying technology that never gets implemented either because it is not fit for purpose or ends up costing astronomical fees to implement.”
 
As for the victim, well apart from us the citizens, the retailer said that it closed all of the affected accounts, improved security and now requires customers to use their unique Clubcard number to login. The affected citizens, whom I suspect is a small percentage of the total number of Clubcard holders, will receive some benefits but will be left with a sour feeling in their mouths at the apparent misuse of their data.
 
As shoppers and consumers we are encouraged to sign up for accounts and loyalty cards with retailers, but if our data is not secure then would we continue to do so? For the retailers, these are likely to create databases of hundreds of thousands, if not millions of users who sign up for an account and assume it is safe. Retailers we have put our trust in you, but we are feeling decidedly unsafe.

Tags: Breachpassword
ShareTweet
Previous Post

NHS voices security concerns over database

Next Post

Merkel and Hollande Propose a European Internet

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol