Filling the Breach

Aug 11, 2008 12:00 PM, By MICHAEL GARRY

Hannaford Bros. and others have learned much about improving card security since the chain’s massive breach earlier this year, but will it be enough?


         Subscribe in NewsGator Online   Subscribe in Bloglines

On March 17 of this year, Hannaford Bros., Scarborough, Maine, stunned the food retailing industry when it announced that a data breach at the checkout lanes of its stores had exposed 4.2 million credit and debit cards to fraudulent misuse. About 1,800 cases of actual card fraud were linked to the breach.

While other food retailers have also been struck by data thieves — notably at Stop & Shop last year, and more recently at Lunardi's and BJ's Wholesale Club — the Hannaford breach is one of the largest to hit a supermarket chain.

The breach affected cards used at Hannaford's 165 stores in New England, as well as at 106 Florida stores operated by Tampa-based Sweetbay, whose IT operations are overseen by Hannaford, and at some independently owned Northeast stores that carry Hannaford products. Both Hannaford and Sweetbay are divisions of Belgium-based Delhaize Group.

Most surprising — and disconcerting — was that the breach occurred despite Hannaford's compliance with Payment Card Industry (PCI) Data Security Standards, which Visa, MasterCard and other card associations established as a major line of defense against security intrusions.

Meanwhile, the U.S. Secret Service, which is leading the criminal investigation into the breach, has not yet announced any arrests. Class action suits filed by consumers against Hannaford, which allege that the chain failed to adequately safeguard card data, are pending in U.S. Federal Court in Portland, Maine.

What has Hannaford — and, by extension, food retailers as a whole — learned from this experience?

For one thing, the breach exposed a weakness in Hannaford's card processing procedure that it has since addressed. The chain discovered that malware installed on its store servers was able to gather credit card numbers as the data was being transmitted from the card-swipe PIN pad across its private network to its centralized payment switch.

“Our customer card information is now encrypted from the [PIN pad] in the lane and remains encrypted the entire time it is on our network,” said Carol Eleazer, vice president of marketing for Hannaford, who has served as the company's spokesperson on the breach. In the past, the data was encrypted during “part of the trip” through Hannaford's private processing network, she noted. PCI standards require encryption for data in transit on public networks but not on private ones.

Hannaford is in the process of rolling out new PIN pads, the MX830 terminal from VeriFone, San Jose, Calif., and is expected to finish in October. As part of that rollout, the chain is implementing what is called TDES (triple data encryption standard) PIN encryption, which Eleazer described as the “highest possible level of PIN encryption.”

Hannaford's current and new PIN pads meet the PCI PED (PIN entry device) data security standard established by the credit card associations for these devices. All transaction terminals sold since January have been upgraded to this standard, said Jeff Wakefield, vice president of marketing, retail systems, for VeriFone.

Subscribe / Renew to Supermarket News

Supermarket News

The most reliable source of industry news and insight...in print and online.

Most Viewed News

Read More News

Retail Analytics
Brian Ross

View All Questions

Refresh: A Whole Health Blog

Bob Vosburgh

Bob Vosburgh:

Read More Refresh

Articles by Market
Retail/Financial
Executive Changes
Grocery/Center Store/
Brands
Health & Wellness
In-Store Bakery/Deli/Meals
Logistics
Marketing
Meat/Seafood/Dairy
Nonfoods/Pharmacy/HBC
Produce/Floral
Specialty/Ethnic
Technology
Key Issues
Food Safety/Recalls
Legislation/Regulations
Sustainability/Green
Resources
Profiles & Rankings
Webinars
White Papers/Studies
Whole Health Blog
Total Access Blog: Expo East
Photo Galleries
RSS
SN Data
Campbell: Innovate
for Impact

Back to Top

Subscribe to SN

Latest Cover

IRI Fast Trends

Not much remains the same in the food-distribution industry, whether it's the marketing of supermarket departments, the advent of new formats or rapidly changing consumer preferences. See what's changing now in the latest IRI Time and Trends report.

SN Daily Update

newsletter image

The food trade’s leading daily news service. Register Here

Upcoming Events

2009 Midwinter Executive Conference,
Jan. 11-13,
Food Marketing Institute,
The Ritz-Carlton, Grande Lakes,
Orlando, Fla.;
202.452.8444.

NRF 98th Annual Convention & Expo,
Jan. 11-14,
National Retail Federation,
Jacob K. Javits Convention Center,
New York;
800.673.4692

View All Upcoming Events

Jobs/Classifieds

View All Classifieds

Premium Content

Cool Running

Cool Running

With the entire country as its laboratory, Wal-Mart Stores has been conducting step-by-step experiments to create the ultimate “green store.”

Changing Diapers

Changing Diapers

At a time when the economy in shambles has been a boon for many store-brand categories, private-label diapers are sporting a serious sag.

Supermarket News Casting Lifelines

Casting Lifelines

For 23 years Food For All, through its checkout register drives at sponsoring supermarkets, has raised funds for countless nonprofit organizations both in the United States and abroad.

Little Luxuries

Little Luxuries

Whether it's cupcakes or cookies, mini-tarts or gourmet brownies, small desserts have become a big draw in many supermarket bakery departments.

Supermarket News Secret's Out

Celebrating Cheese

Specialty cheese is expected to hold its own this holiday season even as shoppers trim their entertaining budgets.