Hackers steal 4.2 million card numbers of Hannaford shoppers

New England is again the epicenter of a major retail data breach, with the Hannaford Bros. grocery store chain on Monday disclosing that hackers stole 4.2 million debit and credit card numbers from its computer systems.

The thefts, which occurred while the cards were being verified for purchase, already have resulted in at least 1,800 incidences of fraud, the Scarborough, Maine company said. No personally identifiable information, such as names and addresses, were compromised.

The merchant, which operates more than 150 Hannaford stores in New England and New York, and Sweetbay stores in Florida, detected the attack on Feb. 27 after it was made aware of suspicious credit card activity affecting some customers.

"We sincerely regret this intrusion into our systems, which we believe, are among the strongest in the industry," Hannaford President and Chief Executive Officer Ronald Hodge said in a Monday letter to customers. "The stolen data was limited to credit and debit card numbers and expiration dates, and was illegally accessed from our computer systems during transmission of card authorization."

Hannaford said it encourages customers who have made purchases at its stores during the past three months using credit and debit cards, and who suspect fraudulent activity on those accounts, to notify their card issuers and banks.

The Massachusetts Bankers Association (MBA), which represents 207 banks and savings and loan institutions in the state, said on Monday in a statement that Visa and MasterCard notified some 60 to 70 banks about the breach.

The two credit card brands did not release the name of the compromised merchant to the banks, the MBA said. The association said it is trying to require brands to release the name of the offending retailer.

In December, the MBA and two other bankers groups settled with Framingham, Mass.-based TJX over the discount retailer's record breach in which 45.7 million card numbers were exposed to wireless hackers. Court filings, meanwhile, have placed the number twice as high.

More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.