Company Credential

Retailers exposed when employee reuse ID

The retail industry has taken hard hits from cyber attackers over the last several years, thanks to the highly publicized Target and Home Depot hacks along with hundreds of other incidents—there were nearly 160 retail breaches confirmed in the most recent, annual Data Breach Investigations Report from Verizon—the industry accounts for about 14 percent of all lost or stolen data records since 2013, according to an ongoing tally published by BreachLevelIndex.com. Among all sectors, that’s second only to the technology industry.

To lend further insight into the topic, Digital Shadows conducted an analysis of the top 1,000 companies on the Forbes Global 2000 list. With Digital Shadows SearchLight proprietary tool, the company was able to continuously monitor and collect corporate email/password breaches between April 2014 and June 2016 on social media, forums, “dark web” sources, criminal sites and “paste sites.”

Here are some results from businesses in the retail sector:

  • There were an estimated 157,000 unique breached email and password combinations linked to retailers. The personal and household goods subsector accounted for the most (36 percent), followed by apparel (22 percent), food (21 percent) and discount stores (10 percent).
  • Many retail employees and execs re-use their corporate emails for non-business or “unofficial business” outlets such as social media. Therefore, it should come as no surprise that social media sites represented a wealth of the breaches, including LinkedIn (with more than 72,500 occurrences) and MySpace (more than 30,740).
  • Outside of social media, we found nearly 42,000 leaks connected to Adobe and just over 3,200 to iMesh. Ashley Madison and other dating websites served as the source for more than 5,570 leaks—leaks which expose employees’ personally identifiable information (PII), partial credit card numbers and even their sexual preferences.

Why Data Breaches Matter

Our analysis probably comes as good news to cyber criminals, who are eager to leverage credential breaches to target the employees’ organizations. Here are five incidents and trends which illustrate how:

Account takeover. The alleged re-use of passwords stolen during a LinkedIn breach led to a Dropbox attack. Workers neglect to change passwords for years, using them for multiple services, making it too easy for hackers to take advantage.

Spear-phishing. In June 2016, Germany’s Computer Emergency Response Team for federal agencies (known as CERT-Bund) reportedly detected spear phishing emails sent to executives. Threat actors crafted personalized emails using the target’s first name, last name, job role and company name to send malicious, macro-enabled Microsoft Word documents.

Credential-stuffing. This occurs when adversaries automatically inject breached user name and password pairs in order to fraudulently gain access to accounts. The adversaries then hijack the account for a variety of purposes, such as spamming in-boxes, stealing funds and accessing PII.

Post-breach extortion. Hackers collected more than 200,000 corporate email addresses during the 2015 Ashley Madison attack. The cyber criminals then tried to extort victims, threatening to reveal the information to victims’ partners if they didn’t send payments via Bitcoin.

Spam emails. These credentials are valuable for spam campaigns, easily swiping email addresses.

Companies Need a Plan

Enterprises must protect themselves from compromises linked to breached email accounts and passwords. Here are best practices to consider:

  • Develop clearly stated policies to determine which kinds of external services are allowable for corporate email accounts.
  • Deploy an enterprise password management solution for secure storage/sharing and password creation/diversity.
  • Proactively monitor for “credential dumps” relevant to your accounts.
  • Establish multi-factor authentication for external corporate services.
  • Evaluate and document any internal services that aren’t federated for faster and more complete incident response.
  • Implement an emergency password reset process to include all user accounts.
  • Through user behavior analytics tools, import compromised identity information while detecting suspicious activity.
  • Train your employees – and then train them some more.

By fully identifying and mitigating the practices which leave businesses vulnerable—and then investing in employee awareness training—you’ll greatly reduce risk while cultivating a more educated workforce. That’s a win-win proposition in the age of cyber exposure.

This article originally appeared in the May 2017 issue of Security Today.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.