News of a security breach at Caribou Coffee Company didn't much surprise Mark Lanterman, one of the nation's foremost computer forensics experts.
Lanterman isn't involved in the Caribou investigation, but it's the kind of thing the Harvard educated, former law enforcement officer sees frequently in his work helping businesses, municipalities, law enforcement agencies and others hunt down cyber thieves.
"When these breaches occur, it means there's a weakness somewhere in the system," said Lanterman, who launched his Minnetonka-based company, Computer Forensic Services, in 1998, and has trained lawyers and U.S. Supreme Court justices.
"Often retailers will have a small IT department that just can't keep up with making sure every single system is up-to-date. It just takes one computer to be missed and the criminals will take advantage of that."
Caribou said Thursday that debit and credit card data from 265 of its company-owned coffee stores in Minnesota and 10 other states was accessed, affecting customers who shopped there between Aug. 28 and Dec. 3.
Store employees were to have been trained on how to help customers, but one working at a store in downtown Minneapolis hadn't heard about the breach, while an employee at another store was able to provide a toll free number.
It took Caribou nearly three weeks to alert customers that their credit card data may have been stolen.
"Companies go into disbelief," Lanterman said. "They don't like the fallout of having to publicly announce, 'We're not perfect. We had a data breach.' "