Posts

Showing posts with the label Heartland Payment Systems Breach

Heartland Payment Systems Breach Followup

Banks and credit unions all across the country have been shutting off credit/debit cards and reissuing them. Heartland Payment Systems has been sued by several companies, banks, and individuals. Interestingly, Heartland was compliant with the PCI standards of the day. Heartland has now beefed up its security above and beyond the PCI specs. Whether it will be enough to keep it afloat as a company remains to be seen. In 2005, CardSystemsSolutions, a major payment processor, folded after its breach of 40 million credit card accounts were compromised; the Heartland breach is measured in the hundred million range. And the stolen card numbers are showing up. Already there have been arrests, where card numbers appeared in Visa and MasterCard gift cards. Those arrested, though, do not appear to be the masterminds behind the breach, just criminals who purchased the numbers. Authorities suspect an Eastern European group behind the break-in at Heartland. As the banking industr...

Heartland Payment Systems Breach

On January 20 -- Inauguration Day -- Heartland Payment Systems, which handles over 100 million credit card transactions a month, quietly announced that their forensic auditing teams have uncovered a piece of malicious software buried in their processing system -- a security hole that allowed hackers to capture an unknown number of credit card transactions. At this point, they can't determine exactly when the hole was created, so therefore they can't determine who has been compromised. It was a very sophisticated attack, according to Robert Baldwin, the company's president and CFO. Heartland thinks that the hole has been plugged, but the forensic investigation is continuing. With this late-breaking story, I've read differing reports on the extent of exposure. One report acknowledges that card holder names and numbers were lifted but says that no merchant data or card holder Social Security numbers, or card PINs were involved. Another report felt that enough ...