On July 21, 2014, Brian Krebs (once again) broke the news of a potentially major retail breach. Goodwill Industries and its 165 independent agencies across North America appear to be the most recent victims in the seemingly plagued retail industry.
The news is reminiscent of the events back in January of this year when details of Target’s data breach were emerging along with reports of breaches at other retailers. At the time Bitsight raised the concern that the Target breach was likely a harbinger of more breach announcements to follow.
Since then, Bitsight has continued to observe evidence of system compromise inside hundreds of retailers over the course of the year. Based on our data and analysis, we observed that there were many retailers with poor performance and that this downward trend has continued into the second half of 2014, as the chart below depicts.

While consumers wait for details to emerge around this latest incident, we thought it would be a good moment to reflect back on some of the major retail breaches we’ve seen this year.
January
- Neiman Marcus: An unknown number of customer credit and debit cards were compromised in an intrusion at the company’s card processor.
- T-Mobile USA: An undisclosed number of customers were affected when names, addresses, SSNs and driver’s license numbers were exposed on servers managed by a third party supplier.
February
- Home Depot: 20,000 employee names, DOBs and SSNs were stolen by three former employees and used to open fraudulent accounts.
March
- Spec’s Wine, Spirits & Finer Foods: 500,000 customers’ names, credit card numbers and card expiration dates from 34 stores were exposed over the course of a year and a half.
- Sally Beauty Holdings: 282,000 credit and debit cards were stolen through network intrusion and put up for sale on an underground crime store.
April
- Michael’s Stores: 2.6 million credit and debit card numbers were compromised in a data security attack.
May