Target breach notifications are a perfect example of what not to do

It's bad enough that Target allowed more than 100 million accounts to be compromised, but its response is an exercise in poor judgment

Hopefully your company will never be the victim of a massive data breach. If it is, though, and customer data is compromised, make sure you don't follow Target's lead when it comes to notifying customers. Target's customer notification efforts are wrong on almost every level.

Customers are conditioned to not click on links in email messages. In the wake of a massive data breach like Target experienced, phishing scams often try to exploit the heightened awareness by sending out emails that look very legitimate.

Security experts warn users to specifically avoid such emails following a data breach, and remind users that a legitimate, reputable company would not send you an email and ask you to click on a link.

Apparently, Target did not get that memo.

James Lyne, global head of security for Sophos, received an email from Target--although he claims that he is not even a Target customer. There are apparently many people receiving breach notification emails from Target who did not shop at Target and are not affected by the breach.

Lyne dissected the email in a post on Forbes, breaking down point by point all the ways Target failed. It uses a shady subdomain--"target.bfi0.com" rather than just "target.com"--and directs users to click on a link comprised of endless gibberish. The email is distributed using a ridiculously suspicious-looking email address. In a nutshell, there is nothing about the legitimate breach notification email from Target that differentiates it in any way from a reasonably well-crafted phishing attack.

"What hope do users have of making a decision about the legitimacy of emails when the good guys behave like this?" asks Lyne. "Target needs to look closely at how it rebuilds consumer trust and suspicious looking emails is not going to help."

Try this

If you ever find your company in the unfortunate position of needing to notify customers of a data breach and possible compromise of personal information, this is not how you do it. The notification email should originate from a domain that is instantly identifiable as your company. If your Web domain is "pcworld.com", the notification email should come from "<SomeRelevantAddress>@pcworld.com".

The notification should be just that--a notification. It should clearly state the facts of the incident, and explain in simple terms what information is potentially compromised, and what customers can do to determine if they're affected, and what they should do to protect themselves and their personal data. It can provide a phone number for customers to call, but it should not contain a link that customers are expected to click on for any reason.

We can excuse Target to some extent for being the unfortunate victim of such a massive data breach. It's response to the breach, however, and these very shady customer notification emails, are inexcusable.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Latest Videos

Conversations over a cuppa with CMO: ABC's Leisa Bacon

In this episode of Conversations over a Cuppa with CMO, ABC's director of audiences, Leisa Bacon, shares how she's navigated the COVID-19 crisis, the milestones and adaptability it's ushered in, and what sustained lessons there are for marketers as we start to recover.

More Videos

Hi everyone! Hope you are doing well. I just came across your website and I have to say that your work is really appreciative. Your conte...

Rochie Grey

Will 3D printing be good for retail?

Read more

Zero proof spiritsUsa since 2011 www.arkaybeverages.com🤪🤟

Sylvie

How this alcohol-free spirits brand rode the health and wellness wave

Read more

okay this a good newsmaybe i gonna try it

kenzopoker1

CMO's top 8 martech stories for the week - 9 July 2020

Read more

Very insightful. Executive leaders can let middle managers decide on the best course of action for the business and once these plans are ...

Abi TCA

CMOs: Let middle managers lead radical innovation

Read more

One failing brand tying up with another failing brand!

Realist

Binge and The Iconic launch Inactivewear clothing line

Read more

Blog Posts

MYOD Dataset: Building a DAM

In my first article in this MYOD [Make Your Organisation Data-Driven] series, I articulated a one-line approach to successfully injecting data into your organisation’s DNA: Using a Dataset -> Skillset -> Mindset framework. This will take your people and processes on a journey to data actualisation.

Kshira Saagar

Group director of data science, Global Fashion Group

Business quiet? Now is the time to review your owned assets

For businesses and advertiser categories currently experiencing a slowdown in consumer activity, now is the optimal time to get started on projects that have been of high importance, but low urgency.

Olia Krivtchoun

CX discipline leader, Spark Foundry

Bottoms up: Lockdown lessons for an inverted marketing world

The effects of the coronavirus slammed the brakes on retail sales in pubs, clubs and restaurants. Fever-Tree’s Australia GM Andy Gaunt explains what they have learnt from some tricky months of trading

Andy Gaunt

General manager, Fever-Tree Australia and New Zealand

Sign in