Friday, 1 August 2014

Sandwich Chain Jimmy John’s Investigating Breach Claims

Sources at a growing number of financial institutions in the United States say they are tracking a pattern of fraud that indicates nationwide sandwich chain Jimmy John’s may be the latest retailer dealing with a breach involving customer credit card data. The company says it is working with authorities on an investigation.
jjohnsMultiple financial institutions tell KrebsOnSecurity that they are seeing fraud on cards that have all recently been used at Jimmy John’s locations.
Champaign, Ill.-based Jimmy John’s initially did not return calls seeking comment for two days. Today, however, a spokesperson for the company said in a short emailed statement that “Jimmy John’s is currently working with the proper authorities and investigating the situation. We will provide an update as soon as we have additional information.”
The unauthorized card activity witnessed by various financial institutions contacted by this author is tied to so-called “card-present” fraud, where the fraudsters are able to create counterfeit copies of stolen credit cards.
Beyond ATM skimmers, the most prevalent sources of card-present fraud are payment terminals in retail stores that have been compromised by malicious software. This was the case with mass compromises at previous nationwide retailers including Target, Neiman Marcus, Michaels, White LodgingP.F. Chang’s, Sally Beauty and Goodwill Industries (all breaches first reported on this blog).
According to the company’s Wikipedia page, there are more than 1,900 Jimmy John’s stores in at least 43 states. Nearly all Jimmy John’s locations (~98 percent) are franchisee-owned, meaning they are independently operated and may not depend on common information technology infrastructure.
However, multiple stores contacted by this author said they ran point-of-sale systems made by Signature Systems Inc. The company’s PDQ QSR point-of-sale product is apparently recommended as the standard payment solution for new Jimmy John’s franchise owners nationwide. Signature Systems did not immediately return calls for comment.
Reports of a possible card compromise at Jimmy John’s comes amid news that the Delaware Restaurant Association is warning its members about a new remote-access breach that appears to have been the result of compromised point-of-sale software.
Update: An earlier version of this story incorrectly stated that Jimmy John’s was based in Charleston, Ill.; rather, it was founded there. The copy above has been corrected.

Anonymous Group Takes Down Mossad’s Website Over Gaza Conflict

anonymous 440 years prison
The hacktivist group Anonymous has reportedly taken down the official website of the Israeli intelligence agency Mossad against Israel’s military incursion in Gaza, which has resulted in hundreds of civilian casualties. The government of Israel has yet to comment on the Mossad hack attack.
The ‘Hacktivists’ were able to take down Mossad’s website in a Distributed Denial of Service <(DDoS) attack early morning, claims a statement on one of the Anonymous hacker’s Twitter account. The attack on the website is supposed to be severe as it has been over 10 hours and the site is still down at the time of writing.
The Anonymous group has already targeted a number of other Israeli organizations as part of a campaign titled “Operation Save Gaza” in the mission to stop this “massacre.”
Anonymous group has also claimed responsibility of taking down multiple Israeli government sites following the death of one of the organization’s members. The member named Tayeb Abu Shehada, a 22-year-old, was killed during a protest in the village of Huwwara in the West Bank by Israeli forces over the weekend.
The hacktivist group launched a hacking campaign Operation Save Gaza against Israeli government coinciding with the Israel’s Operation Protective Edge on July 7. Since then, Anonymous group have taken down “thousands” of Israeli-based websites including Israel’s Defence Ministry and the Tel Aviv Police websites.
We are calling upon the Anonymous collective, and the elite hacker groups to join our crusade, and to wage cyber war against the state of Israel once more,” said a public statement from the group posted online last Friday. “As a collective ‘Anonymous’ does not hate Israel, it hates that Israel’s government is committing genocide & slaughtering unarmed people in Gaza to obtain more land at the border.
As the news broke that hundreds of “Israeli government home pages have been replaced by graphics, slogans, and auto-playing audio files,” Anonymous claimed responsibility for the attacks, further releasing 170 log-in details last Monday which they claimed belonged to Israeli officials.
Two years ago, the same group launched hundreds of attacks on Israeli sites with #OpIsrael targeting Israeli websites, during the Israeli Defense Force’s (IDF) previous operation ‘Pillar of Defense’ in Gaza.
The Israeli Foreign Ministry’s data was completely wiped out and the group was able to leak the data of 5,000 Israeli officials as well as hacked into the Israeli Deputy Premier’s Facebook and Twitter accounts, thereby replacing it with pro-Palestinian messages.
Also a year back, the group claimed to have attacked 100,000 websites, stating that their attacks had caused $3 billion in damages to Israel.