Retailer says that credit and debit card numbers compromised On the same day that Dairy Queen announced their own malware-based data breach, Kmart (owned by Sears Holdings Corp.) reported the discovery that credit and debit cards were compromised after criminals installed malware on their payment systems.According to the company, IT staff discovered the malware on Thursday (October 9). Additional investigation into the matter revealed that their systems were infected in early September.The data compromised by the POS malware is commonly referred to as Track 2 data, which would enable a criminal to clone the customer’s card. However, other personal information was not exposed.“Based on the forensic investigation to date, no personal information, no debit card PIN numbers [sic], no email addresses and no social security numbers were obtained by those criminally responsible,” Kmart said in a statement. The incident only affects in-store shoppers only, as Kmart.com was not part of the breached systems. In response, Kmart says they’re offering customers credit monitoring (888-488-5978).Kmart didn’t name the malware detected, but given the pattern in recent months, it’s likely that they, like Dairy Queen, were compromised by a variant of Backoff – a family of malware that targets POS systems. In July, the US Secret Service warned retailers about Backoff, advising them that criminals were targeting poorly protected instances of RDP, including services from Microsoft, Apple, Chrome, Splashtop 2, Pulseway, LogMeIn, and Join.Me.At the time of the initial warning, criminals had targeted some 600 businesses with Backoff.On Thursday, Dairy Queen said that Backoff was responsible for POS compromises at nearly 400 stores. Kmart said that their investigation is ongoing, and that they are working with federal authorities. Related content news Gwinnett Medical Center investigating possible data breach After being contacted by Salted Hash, Gwinnett Medical Center has confirmed they're investigating a security incident By Steve Ragan Oct 02, 2018 6 mins Regulation Data Breach Hacking news Facebook: 30 million accounts impacted by security flaw (updated) In a blog post, Facebook’s VP of product management Guy Rosen said the attackers exploited a flaw in the website's 'View As' function By Steve Ragan Sep 28, 2018 4 mins Data Breach Security news Scammers pose as CNN's Wolf Blitzer, target security professionals Did they really think this would work? By Steve Ragan Sep 04, 2018 2 mins Phishing Social Engineering Security news Congress pushes MITRE to fix CVE program, suggests regular reviews and stable funding After a year of investigation into the Common Vulnerabilities and Exposures (CVE) program, the Energy and Commerce Committee has some suggestions as to how it can be improved By Steve Ragan Aug 27, 2018 3 mins Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe