Hudson’s Bay Co. says Saks Fifth Avenue stores affected by data breach

Some customer payment card information may have been stolen from shoppers

Hudson’s Bay Co. is the latest Canadian company to be hit with a data breach, saying that customer payment card information may have been stolen from shoppers at certain Saks Fifth Avenue, Saks Off Fifth and Lord & Taylor stores in North America.

A spokesperson for retailer would not comment on whether any specific Canadian locations were affected, but did say there is no indication the breach affects any of HBC’s other digital platforms, Hudson’s Bay stores or Home Outfitters locations.

HBC released little information on the breach itself on Sunday, but a New York-based cybersecurity firm said it had analyzed the available data and found that information from five-million credit cards had been compromised.

Gemini Advisory LLC said in a report that the information was stolen from 83 Saks Fifth Avenue or Saks Off Fifth stores, and from all Lord & Taylor locations.

The firm found that three Canadian Saks locations were exposed to the breach: Sherway Gardens in Toronto, Bramalea City Centre in Brampton, Ont. and Pickering Town Centre in Pickering, Ont.

Dmitry Chorine, the co-founder of Gemini Advisory, said his firm works to improve response to data breaches by analyzing stolen data that appears on the so-called dark web.

Chorine said the firm started looking into the breach when they noticed an influx of stolen credit and debit card information being offered for sale on the dark web last week.

Upon analyzing the data, Chorine said they were able to determine that shoppers at all Lord & Taylor and at certain Saks Fifth Avenue locations were at risk of having their information stolen.

“On March 28, we saw a significant spike of stolen credit cards offered for sale on one of the marketplaces,” said Chorine.

“When we checked, we saw there was an advertisement stating that more than five-million credit and debit cards will be offered for sale, and that’s when we decided to research this particular breach.”

The data that Chorine and his team found was being offered on a dark web marketplace operated by a hacking group called JokerStash, which Chorine says has been active in hacking retail and hospitality companies for the past three years.

Gemini Advisory said Sunday that it had found data that had been stolen from as early as March 2017, and as late as March 2018.

He said that only certain Saks Fifth Avenue locations were affected because the outlet was in the process of switching from card-swipe technology to EMV chip technology, which is already commonly used in Canada.

Stores that had already implemented chip machines would likely not be exposed to the data breach, Chorine said.

Chorine urged any consumers who had shopped at Saks Fifth Avenue or Lord & Taylor stores in the past year to take preventative measures against fraud.

“They should probably call their banks and replace their cards,” said Chorine. ”That would probably be the best preventative action they could take, instead of just waiting.”

For now, HBC is asking clients to review their account statements for activity or transactions they don’t recognize.

The company said it’s investigating and taking steps to contain the attack, and clients will not be responsible for any fraudulent charges as a result of the breach.

It said it will offer free identity protection services to those affected once they learn more about the breach.

Salmaan Farooqui, The Canadian Press

Just Posted

Pride Society of the Comox Valley set to kick off week-long celebration

The organization is celebrating Pride Week with a variety of events to bring the community together.

Work continues on Courtenay’s 4th Street Improvement Project

4th street will be closed to traffic between Duncan and Cliffe Avenue

Inside the music: step behind the curtain at the venerable Vancouver Island Music Festival

Big Read: VIMF in the Comox Valley exemplifies the spirit of an Island summer music festival

Cannabis facility planned in Courtenay

Design up to 100,000 square feet

Major private donation to Kus-kus-sum project

Frank and Bobbi Denton, longtime residents of the Comox Valley, have donated… Continue reading

BC Games: Day 3 wrap and closing ceremonies

The torch in the Cowichan Valley has been extinguished as Fort St. John gets ready to host the 2020 BC Winter Games

Bob Castle’s Under the Glacier cartoon for July 19, 2018

Bob Castle’s Under the Glacier cartoon for July 19, 2018… Continue reading

Heat wave hits B.C.’s south coast

Temperatures expected to hit the mid-30s in some areas

Man charged in 2006 B.C. murder extradited to Canada from South Korea

28-year-old Jui-Kai Weng was charged with second-degree murder and attempted murder

Soaring temperatures, high winds could worsen fires in B.C.’s southern Interior

Environment Canada’s forecast for the next week in the southern Interior does not inspire confidence, with temperatures in the 30s and winds gusting over 40 kilometres per hour.

Iran dismisses Trump’s explosive threat to country’s leader

Trump tweeted late on Sunday that hostile threats from Iran could bring dire consequences.

Update: Police probe Toronto shooting that killed 2, injured 12; suspected gunman dead

Paramedics said many of the victims in Danforth, including a child, were rushed to trauma centres

Why do they do it? Coaches guide kids to wins, personal bests at the BC Games

Behind the 2,300 B.C. athletes are the 450 coaches who dedicate time to help train, compete

Government sets full-time salary range for Justin Trudeau’s nanny

At its top range, the order works out to a rate of $21.79 per hour, assuming a 40-hour work week

Most Read