A First: PCI Compliance Mandated for State's Merchants
Should individual states mandate that businesses comply with the Payment Card Industry's Data Security Standard (PCI DSS)? The answer is "yes," according to Nevada, which has passed a new law that, as of next year, requires businesses to comply with PCI when collecting or transmitting payment card information.
As states rush to adopt or strengthen privacy legislation, Nevada's move is seen by some observers as a potential "game-changer." But they question whether states should be in the business of mandating compliance with an industry standard.
Editor's Note: More good news for HomeATM as our PCI 2.0 Certified Safe-T-PIN instantaneously encrypts Track 2 data for transmissions between Zones 1-4 (click the illustration below to enlarge and read the description of Zones 1-5 in the end-to-end-encryption process) and the Safe-T-PIN's integrated PIN Pad instantaneously encrypts the PIN for Zones 1-5. HomeATM does all that for about half the cost of other Point of Sale Terminals that encrypt Track 2 data (and we include the PIN Pad!) I'll have more on this "game-changing" historic law tomorrow.
For example...how will this law affect online merchants who have their corporate offices in Nevada?
Online scams targeting the financial sector are on the rise in Africa as more people access online banking services and mobile banking.
Phishing attacks are mainly occurring in South Africa where online banking is common, while mobile money theft is common in other parts of Africa where Internet penetration is still low. As a result of the increase, South Africa's Absa bank, the largest in Sub Saharan Africa announced Tuesday that its Internet banking customers can download security software to curb cybersecurity attacks. (See "How to Spot an E-Mail Scam.")
A phishing attack aimed at Absa customers features a plain, yet clever unsolicited message instructing them to follow a link and confirm their account information as a way for criminals to obtain passwords and user IDs. Continue Reading at PC World
I blogged a warning about this last week, but here's more information on the Michael Jackson death probe spam. Your online banking credentials are at risk...(unless of course your bank utilizes the HomeATM PCI 2.0 Certified Safe-T-PIN for 2FA two-factor-authentication log-in, in which case your bank numbers and password wouldn't be on your PC for the MJ Malware to mal. Bank issues card, Bank issues PIN, Bank issues Safe-T-PIN and you swipe your card, enter your PIN and it's all instantaneously encrypted, including the Track 2 data. We make the MJ malware threat not scary...
Washington: Beware of any emails regarding the investigation into King of Pop Michael Jackson's death, for they may be spam messages that infect computers with a virus able to steal bank account numbers and passwords.
Experts at the University of Alabama at Birmingham (UAB) have revealed that they began tracking the celebrity-focused spam early on June 30.
"We've been tracking the cyber criminals behind this spam and the associated virus for many weeks, but it is just today that they have shifted their strategy by embedding their virus into an e-mail that claims to link you to a Web site that will reveal Michael Jackson's killer," said Gary Warner, UAB's director of research in computer forensics.
"The spam related to this virus has taken many forms, including e-cards, shipment tracking links and, most recently, a fake update to Microsoft Outlook, but with the high interest in Michael Jackson's death the cyber criminals decided to change their delivery method to capitalize on that," he added.
The message in the Jackson virus spam reads "Michael Jackson was killed ... but who killed Michael Jackson." Warner said that anyone who clicks on the message won't find an answer to the question. "If you click on that e-mail and go to the page the cyber criminals have linked to the message, your computer is immediately infected with malware," he said. He warned that the malware is capable of stealing bank account information and passwords from computer hard drives.
The virus also will redirect certain Google searches performed on an infected computer, meaning the malware inserts links to other virus-infected pages into the top positions of search results. That, according to Warner, means that search results that unsuspecting users would otherwise think valid are actually portals to other virus programs and malware.
OfficialWire: Multilevel Marketing (MLM) Payouts Made Easy With CredoCard.com
Multilevel Marketing (MLM) Payouts Made Easy With CredoCard.com
CredoCard.com specializes in branded and co-branded debit card programs, white label programs, software and payment integration programs, and turnkey payment solutions Published on July 06, 2009
by CredoCard.com Press Office (OfficialWire) VIENNA, AUSTRIA
CredoCard.com specializes in branded and cobranded debit card programs, white label programs, software and payment integration programs, and turnkey payment solutions. We offer the co-branded services to our client base in following regions:
1. Africa 2. North America 3. South America 4. Asia 5. Caribbean 6. Latin America 7. Middle East 8. European Union 9. Europe
We have an extensive range of service for Multilevel Marketing Companies (MLM). Our cobranded card programs are made through self-issuance, straight partnership or the transition of a private label portfolio.
Co-branded debit cards from Credocard lead to stronger brand attachment and customer loyalty. Cobranding signifies placing the MasterCard or Visa Card logo on a simple debit card or credit card. Hence, the card gets a double identity or two brands. This gives your MLM Company a higher recognition, as Visa and MasterCard are well-known names in the credit card sector.
The Credocard holders enjoy a galore of benefits as listed below:
1. The cobranded debit cards allow easy cash outs from ATMs 2. A cardholder does not require a bank account or credit checks to accept the payment worldwide. 3. Credocard holders enjoy a global acceptance, as they are partners with well-known names like MasterCard and Visa Card. These names are extremely popular with the brand loyal customers. 4. The cardholder can have an easy access to the fund transferred on their card at ATMs, shops or restaurants.
Multilevel marketing is very popular with people seeking flexible businesses or part-time businesses. It is a type of business, where a distributor network is needed to build the business. In this business model, the payouts occur at more than one level. Direct deposits to a bank account or mailing a commission check is comparatively simple. But, a distributor abroad, who may not have a bank account, have to wait longer to cash their checks.
Electronic fund transfer services made available are faster and less expensive as compared to the traditional methods of checks and wire transfers. But, the most efficient way to transfer funds is through cobranded debit cards offered by Credocard.
MLM companies can highly benefitted by the service of www.credocard.com. Some of the services being offered are:
1. With a Credocard, your MLM Company can get a global recognition, as we are associated with names like MasterCard and Visa Card, who are market leaders in the credit card segment. 2. By incorporating our cobranded payment cards into your payout process, you can reduce the cost and hassle of international payments. 3. You can instantly transfer the funds to the card accounts, saving on your precious time and money.
Credocard strategic partners include MasterCard, Visa, ID Data, Metavante and Comodo Group. We have partnership agreement with more than 500 worldwide mobile networks, which offer both mobile payment options and SMS services. Our turnkey solutions include unlimited upgrades for all software and services needed to operate a business platform.
You can get in touch with us for more information on payroll solutions through our co-branded debit card programs, specially designed for MLM clients. Please log on to our web site credocard.com for more information or you may talk to us directly on phone to work out on your specific requirement related to MLM services.
About Credocard Ltd.
Credocard is the industry leader for software and payment integration platforms, turnkey solutions, white label programs and co-branded debit card programs. For more information on our programs please visit www.credocard.com
On July 3rd, the ZDNet Blogs reported that eyewonder.com, a digital advertising provider, has infected some popular sites via, what they call, a "malvertising" campaign. Here's an excerpt, you can read the full story by clicking the link at the end of the excerpt:
Is the EyeWonder attack a typical malvertising campaign where malicious content is pushed on legitimate sites through the ad network, or did their web site actually got compromised in the ongoing Cold Fusion web sites compromise attack?
Daniel Wolfe writes for Bank Technology News and asks whether Facebook should promote their own proprietary payment...
American Banker | Monday, July 6, 2009 by Daniel Wolf
Could Facebook credits become the currency of the Internet?
Facebook Inc.'s popular social networking site already has a small toehold in payments through its virtual gift shop, and is reportedly trying to expand the system.
The company claims more than 200 million active users worldwide who trade gossip and keep in touch with friends through its Web site, and analysts said this vast audience might welcome a way to interact commercially as well.
However, they warn that Facebook's efforts to promote an alternative currency may be unnecessary and that demand for a Facebook payments system will likely be minimal unless there is a corresponding market for products or services available through the site.
Offering more payments services through Facebook could be popular with users, "but the recipient would have to see value in Facebook credits," said Bruce Cundiff, a director of payments research and consulting for Javelin Strategy and Research of Pleasanton, Calif. "That's the big issue: are they valuable when they're no longer dollars?"
People can use credit cards now to purchase 10 credits for a dollar through the site's virtual gift shop, and can spend the credits on inexpensive digital novelties such as playful icons sent to one another's Facebook pages, including images of birthday cakes, balloons and sock monkeys — the electronic equivalent of a greeting card.
In recent months the Palo Alto, Calif., company has also opened up its payments system to eight software developers that offer games, calendar tools and other simple applications; (fluff)Friends, for example, lets people buy gifts for digital pets.
Facebook did not respond to numerous attempts to contact the company, and it has said little to date about its payments strategy.
LONDON (Reuters) - A deadline is needed to ensure full switchover to a single pan-EU system of bank payments and help industry and public authorities plan ahead, a top European Central Bank official said on Monday.
The European Union's executive European Commission has launched a public consultation on whether such an end date is needed and, if so, when it should be.
The EU has adopted a law to introduce a single euro payments area (Sepa) so that consumers can send and receive payments in euros and use their payment cards anywhere in the 27-nation bloc, all from one bank account.
The aim is to exploit the single currency to boost competition and choice in services to bring down prices for the EU's 495 million consumers. National payments systems would be shut down with transactions moved to the new Sepa system.
The introduction of direct debit under Sepa was on track for November 2009, she said, but there was still not enough competition in cross-border cards where MasterCard (MA.N) and Visa Europe dominate. "Competition concerns are an on-going concern," she said.
Here's an interesting story from Vanguard regarding the battle for supremacy between the two biggest card companies in Nigeria. (search the HomeATM blog for more on Interswitch)
Valucard, Interswitch in Battle for Supremacy - Finance Jul 6, 2009 By Babajide Komolafe
The wave of competition caught up with the two card giants in Nigeria last week as they make claims of superiority over each others products, Babajide Komolafe writes
The market was taken by surprise last week when the two card giants, Valucard and Interswitch, traded claims of authenticity of their cards opening in what could be better described as an exercise in perfect de-marketing.
The whole exercise was to enable one of them gain an upper hand in an intense competition for the market for chip and PIN, Europay, MasterCard and Visa (EMV) compliant payment cards in the country.
Valucard had last week dismissed Interswitch’s Verve cards claim to be EMV compliant saying its Visa and VPay cards are the only EMV compliant cards in the country. Interswitch in a swift reaction said Valucard claims is a lie and unnecessary de-marketing. It said the truth is that its Verve card is an EMV compliant card with more features than any other in the world. Interestingly both Valucard and Interswitch are owned by consortium of banks with some banks belonging to both consortia.
EMV is an international e-payment standard developed by Europay, MasterCard and Visa to maximize e-payment security by replacing the current and fraud prone magnetic stripe cards with EMV Chip and PIN cards Chip (EMV).
It represents the latest in payment card technology. Unlike the magnetic strip card that can be cloned by fraudsters, chip and PIN (EMV) cards cannot be cloned as a result it is considered safer and more secure.
Against this background the Central Bank of Nigeria (CBN) directed banks to stop issuing magnetic strip cards and migrate to chip and PIN (EMV) cards on or before April 30th this year.
Consequently, last year Interswitch Nigeria Limited, the sole switching company to Nigerian banks with the largest payment cards issued on its Nigeria Debit Card Scheme, developed and introduced Verve cards which is a chip and PIN (EMV) compliant card. The card was introduced to replace the 28 million magnetic strip cards on its network.
Already about six million Verve cards have been issued while 12 banks have ordered for Verve cards. The banks are Intercontinental Bank, Nigeria International Bank, Skye Bank, Bank PHB, Oceanic Bank, Ecobank, First City Monumental Bank (FCMB), First Bank, Stanbic IBTC, Unity Bank, Zenith Bank and United Bank for Africa (UBA).
Valucard however was the first to introduce EMV compliant cards. In 2004 following its partnership with Visa International, the company introduced Visa and VPay cards which are EMV compliant. The company in a statement last week however warned that the banking public should disregard any payment card claiming to be EMV compliant. Continue Reading
07/06/09 06:54 AM via The Buffalo News CREDIT Weak security opens door to hackers By Jordan Robertson | ASSOCIATED PRESS
Every time you swipe your credit card and wait for the transaction to be approved, sensitive data including your name and account number are ferried from store to bank through computer networks, each step a potential opening for hackers.
Editor's Note: The sensitive data of which they speak is the Track 2 data, and if the Track 2 data is encrypted, the above threat does not apply. Which is why HomeATM's devices have been engineered to "instantaneously encrypt" the Track 2 data providing the industry with our unique end-to-end encryption methodology. (Zones 1-4 click pic to enlarge) and eradicating the threat spoken of in this story...
And while you may take steps to protect yourself against identity theft, an Associated Press investigation has found the banks and other companies that handle your information are not being nearly as cautious as they could.
The government leaves it to card companies to design security rules that protect the nation’s 50 billion annual transactions. Yet an examination of those industry requirements explains why so many breaches occur: The rules are cursory at best and all but meaningless at worst, according to the analysis of data breaches dating to 2005.
It means every time you pay with plastic, companies are gambling with your personal data. If hackers intercept your numbers, you’ll spend weeks straightening your mangled credit, though you can’t be held liable for unauthorized charges. Even if your transaction isn’t hacked, you still lose: Merchants pass to all their customers the costs they incur from fraud.
More than 70 retailers and payment processors have disclosed breaches since 2006, involving tens of millions of credit and debit card numbers, according to the Privacy Rights Clearinghouse. Meanwhile, many others likely have been breached and didn’t detect it. Even the companies that had the payment industry’s top rating for computer security, a seal of approval known as PCI compliance, have fallen victim to huge heists.
Companies that are not compliant with the PCI standards—including one in 10 of the medium-sized and large retailers in the United States—face fines but are left free to process credit and debit card payments. Most retailers don’t have to endure security audits, but can evaluate themselves.
Credit card providers don’t appear to be in a rush to tighten the rules. They see fraud as a cost of doing business and say stricter security would throw sand into the gears of the payment system, which is built on speed, convenience and low cost.
That is of little consolation to consumers who bet on the industry’s payment security and lost.
It took four months for Pamela LaMotte, 46, of Colchester, Vt., to fix the damage after two of her credit card accounts were tapped by hack-
LaMotte, who was unemployed at the time, says she had to borrow money from her mother and boyfriend to pay $500 in overdraft and late fees—which were eventually refunded— while the banks investigated.
“Maybe somebody who doesn’t live paycheck to paycheck, it wouldn’t matter to them too much, but for me it screwed me up in a major way,” she said. LaMotte says she pays more by cash and check now.
It all happened at a supermarket chain that met the PCI standards. Someone installed malicious software on Hannaford’s servers that snatched customer data while it was being sent to the banks for approval.
Since then, hackers plundered two companies that process payments and had PCI certification. Heartland Payment Systems lost card numbers, expiration dates and other data for potentially hundreds of millions of shoppers. RBS World- Pay Inc. got taken for more than 1 million Social Security numbers—a golden ticket to hackers that enables all kinds of fraud.
In the past, each credit card company had its own security rules, a system that was chaotic for stores.
In 2006, the big card brands—Visa, MasterCard, American Express, Discover and JCB International— formed the Payment Card Industry Security Standards Council and created uniform security rules for merchants.
Avivah Litan, a Gartner Inc. analyst, says retailers and payment processors have spent more than $2 billion on security upgrades to comply with PCI. And the payment industry touts the fact that 93 percent of big retailers in the U. S., and 88 percent of medium-sized ones, are compliant with the PCI rules.
Computer security experts say the PCI guidelines are superficial, including requirements that stores run antivirus software and install computer firewalls. Those steps are designed to keep hackers out and customer data in. Yet tests that simulate hacker attacks are required just once a year, and businesses can run the tests themselves.
“It’s like going to a doctor and getting your blood pressure read, and if your blood pressure’s good you get a clean bill of health,” said Tom Kellermann, a former senior member of the World Bank’s Treasury security team and now vice president of security awareness for Core Security Technologies, which audited Google’s Internet payment processing system.
“PCI compliance can cost just a couple hundred bucks,” said Jeremiah Grossman, founder of WhiteHat Security Inc., a Web security firm. “If that’s the case, all the incentives are in the wrong direction. The merchants are inclined to go with the cheapest certification they need.”
For some inspectors, the certification course takes just one weekend and ends in an open-book exam.
Security experts say there are several steps the payment industry could take to make sure customer information doesn’t leak out of networks.
Banks could scramble the data that travels over payment networks, so it would be meaningless to anyone not authorized to see it.
Another possibility: Some security professionals think the banks and credit card companies should start their own PCI inspection arms to make sure the audits are done properly. Banks say they have stepped up oversight of the inspections, doing their own checks of questionable PCI assessment jobs. But taking control of the whole process is far-fetched: nobody wants the liability.
LONDON, July PRNewswire/ -- NTT Europe Online is providing a bespoke hosting platform for a new mobile banking service, MoBank, which launches on 6th July 2009. MoBank - the brainchild of ex First Direct and Egg bankers, Steve Townend and Dominic Keen - is a brand new service that works with your existing bank account to let you buy and pay for items using your mobile phone.
At launch, consumers will be able to buy all sorts of things using MoBank, such as cinema tickets, clothes, music, books, flowers, gifts and tickets; and check the balance on their card from their phone. Soon, it will include extra convenient banking features such as money transfers, bill payments and budget trackers.
MoBank will initially be available on the iPhone, with plans to roll it out to Java, Google and Blackberry phones later in the year.
With a proven history of working with security-critical online financial services, NTT Europe Online's managed hosting platform is built to deliver maximum performance to MoBank users. With multi-tiered firewall protection, anti-virus and intrusion-prevention technology, the platform is fully compliant with the Payment Card Industry Data Security Standard (PCI DSS) to protect users' sensitive personal data. NTT Europe Online's managed hosting services also meet the ISO27001 Information Security Standard, allowing MoBank to guarantee the reliability and availability of the service.
Dominic Keen of MoBank said: "The Internet has revolutionised how we shop and manage our money. The next step is to take this to mobile phones. MoBank has been designed to make people's lives easier and save them time by providing banking services on the move.
"A secure hosting platform is extremely important. We worked closely with NTT Europe Online to provide this, ensuring it was scalable and capable of delivering high performance levels. The technical backing we receive from NTT Europe Online is critical in helping us achieve our goals."
Damien Skendrovic of NTT Europe Online comments: "We're delighted to be working with MoBank and their application shows us just how exciting and useful mobile technology can be. A service such as this has to have the right technological foundations to make it succeed. In MoBanks' case, its hosting platform needs to meet the levels of security required by any financial service as well as the specific demands of mobile data applications. We're convinced that MoBank will be a huge success."
MoBank is already attracting interest: in 2008, it won a Red Herring 100 award for the best startups in the world; and it won the Oxford University Saïd Business School Venture Competition in 2008.
About NTT Europe Online
NTT Europe Online provides managed hosting, security and application management services to businesses globally. These services provide the reliability, availability, security and scalability needed to underpin business success online.
NTT Europe Online is certified to ISO27001 for Information Security Management and, as part of NTT Communications, has the global reach and scale to support businesses of all sizes. NTT Communications is the global data and IP services arm of the Fortune Global 500 telecom leader, Nippon Telegraph & Telephone Corporation (NTT). For further information visit http://www.ntteuropeonline.com
About MoBank:
MoBank - http://www.mobank.co.uk - is a new mobile banking service started by ex-First Direct and Egg bankers, Steve Townend and Dominic Keen. MoBank works with your existing bank account to let you buy and pay for stuff using your mobile phone. In 2008, it won a Red Herring 100 award for the best startups in the world; and it won the Oxford University Saïd Business School Venture Fund Competition 2008.
NationalCreditReport.com Recommends Credit Monitoring in the Event of a Breach and Reporting Online and Offline Fraud Activity
Data breach at Cornell puts 45,000 at risk of identity theft. Be sure to safeguard all credit.
Delray Beach, FL - June 25, 2009 - NationalCreditReport.com™ (the"Company"), a leading provider of free credit reports and credit monitoringservices, recommends that all consumers, especially those whoseidentities have been compromised in a data breach, utilize a creditmonitoring service to help protect themselves from identity theft.Also, the Company highly recommends reporting any offline and online fraud activity.
Earlier this week, Cornell University announced that more than 45,000people associated with the university had their names and SocialSecurity numbers exposed after a laptop was stolen. Cornell has said itwill provide credit monitoring and other identity theft protectionservices to those involved.
Credit monitoring is an automated service that reduces the threat ofidentity theft by updating consumers of changes and inquiries made totheir credit files.
NationalCreditReport.com's Safeguard Credit™monitoring alerts the subscriber within 24 hours of any major changesmade to their credit file, and does not affect the subscriber's creditor credit score.
"The computer theft at Cornell demonstrates the vulnerability ofconsumers' information and the need for protective services such ascredit monitoring, especially in the event of a breach," said AllisonTomek, NationalCreditReport.com's Vice President of Investor Relationsand Corporate Communications. "Our Safeguard Credit service sends emailalerts when potentially fraudulent items, or any significant changes,are made to a credit report, like the opening of a fraudulent creditcard. Our identity security services, which encompass creditmonitoring, help give consumers peace of mind."
About NationalCreditReport.com: Since 2004,NationalCreditReport.com has specialized in providing identity theftprotection services, which encompass credit monitoring and creditreporting, to help protect consumers from identity theft. The Companyencourages consumers to utilize its credit monitoring service, especially in the event of a data breach and encourages the reporting of any fraud activity online and offline.