Sunday, February 15, 2009

Another Payment Card Processor Hacked

Anthony Freed, Financial Editor for Information Security Resources writes, in an excellent article, that there are reports that another Payment Card Processsor has been hacked.  The company has not yet been named, but "multiple tips from multiple sources" claim that another processor, other than Heartland is behind recent warnings to banks about potentially having to replace consumer cards.

Developing...
 
By Anthony M. Freed, Information-Security-Resources.com Financial Editor
Reports are surfacing that there has been another major information security breach at a credit card payment processor, though the company has not yet been identified.
The breach news comes less than one month after Heartland Payment Systems announced they had suffered what is likely to be the biggest PCI breach to date, possibly bigger than the TJMAX breach.
Heartland (HPY) is the sixth largest payment processor in the nation.
There had been indications in early Heartland reports that the FBI was pursuing suspects who may be part of a larger criminal conspiracy targeting multiple companies, but there are no reports yet as to whether this latest breach is part of that investigation, or whether the revelations at Heartland led to this breach being uncovered.
From DataLossDB.org on the breach at the unknown company:

Banks around the country are reportedly receiving warnings, and perhaps even new lists of cards to replace. This is apparently regarding another credit card processor, unrelated to Heartland Payment Systems, having a significant breach.

OSF has received multiple tips from multiple sources, and has spoken with the good people over at bankinfosecurity.com who have confirmed they too are hearing the exact same thing. From what we’ve heard, this second breach is significant in scale, but we have not as of yet been told who the processor is.

Also, speaking of BankInfoSecurity.com, they’ve released an article about three people being arrested for allegedly using credit cards from the Heartland Breach. And also, their list grows of institutions affected by the Heartland incident (they maintain a much more comprehensive list than we did). Hats off!
Our team has been predicting that 2009 will be the year that InfoSec moves to the forefront of the economic crisis. We believe the somewhat obscure issue will be as familiar to the American public as the notorious subprime and pay option ARMs have in the last year or two.

Much like the meltdown of the mortgage industry, the revelations of lax governance in the handling of sensitive and private data will likely shock the public and the business community alike, and those revelations are bound to come all too painfully slow, especially for shareholders.

The data loss debacle at Heartland highlights the fact that the failure to secure information is the next major shareholder derivative, director and officer liability, regulatory, consumer product safety, and class-action issue to impact our economy.

Nearly one month after going public, few details of the Heartland breach have been released, and many questions remain regarding a long chain of events that include both the breach and also an aggressive executive 10b5-1 stock selling plan adopted in early August of last year, the same month the breach is now reported to have ended, but still five months before the breach was announced publicly.


Heartland Payment Systems stock price has been flat-lined since losing half of it’s value shortly after the January 20, 2009 breach announcement. A report form komonews.com gravely illustrates that this is more than a security issue, it is a commercial viability issue:
Heartland says it has closed the security hole that allowed criminals to infiltrate their systems, but the matter is far from settled. The company will likely have to pay big penalties to banks to reimburse the cost of issuing new cards, and analysts say the intrusion could even threaten the company’s survival if the big card brands decide to cut off Heartland from connecting to their networks.

One big payment processor, CardSystemsSolutions, went under after a 2005 data breach in which 40 million credit card accounts were compromised and the big card brands stopped doing business with CardSystems. Representatives for Visa Inc. and MasterCard Inc. declined to comment.

The latest piece of news for the Heartland timeline comes from StorefrontBacktalk.com’s Evan Schuman:
“According to a MasterCard alert, this sniffer program stole card numbers and expiration dates from credit and debit cards processed by Heartland from May 14, 2008, through Aug. 19, 2008, as the information entered Heartland’s payment switch,”
Here is what we know of the Heartland timeline thus far, which is not much, but it does beg for a more thorough explanation by company officials for no other reason than several important things happened in a relatively short period of time, and that alone should be reason enough:
May 14, 2008: Breach reported to have began
May 20, 2008 Carr Makes first stock sale of the year, 2695 shares
August (first week), 2008: CEO Robert Carr’s 10b5-1 is proposed
August 8, 2008: Board approves 10b5-1 plan
August 8 - August 14, 2008: Carr makes six separate sales of stocks totalling 60,000 shares
August 19, 2008: Breach reported to have ended
August 28, 2008: Carr sells 80,000 shares
September 3, 2008: Carr sells 80,000 shares
September 17, 2008: Carr sells 80,000 shares
October 15, 2008: Carr sells 80,000 shares
October 28, 2008: Visa and MasterCard notify Heartland of problems; Carr sells 80,000 shares
November 6, 2008: Carr sells 80,000 shares
November 20, 2008: Carr sells 80,000 shares
December 11, 2008: Carr sells 80,000 shares
December 26, 2008: Carr sells 42,900 shares
January 7, 2009: Carr sells 80,000 shares
January ??, 2009: Carr suspends his 10b5-1 stock selling plan
January 20, 2009: Breach Announced
HeartLand representatives maintain that company officials were not alerted to the breach until being contacted by Visa (V) and MasterCard (US:MA) officials in late October.

In an email I received from Heartland’s representatives, they state that there is no relationship whatsoever between the breach and Carr’s stock sales:
At the time of this announcement, Mr. Carr was not under any trading restrictions pursuant to the company’s insider trading policy and was not in possession of any material non-public information concerning the company. Under this 10b5-1 plan, programmed sales of company stock were made on Mr. Carr’s behalf, and he had no discretion regarding the timing or other aspects of those sales.

Although he was not required to do so, Mr. Carr terminated his 10b5-1 when the company confirmed the security breach it disclosed in the company’s press release of January 20, 2009. As has been reported, Heartland first learned of a potential problem from the card associations on October 28th of last year, well after the announcement of this 10b5-1 plan. Heartland categorically denies that Mr. Carr was aware of a potential security breach at the time he adopted his trading plan.
I can see no reason not to take them at their word, but I also urge Heartland officials to release more information to clear up the issue, such as the documentation that Heartland’s Systems and IT departments keep to show compliance with requirements for sensitive data protection. Hard copy confirmation that no one at Heartland was aware of any major security problems prior to October 28, 2008 would put any questions to rest with more finality than a corporate press release or an email.

Something to look forward to is the conference call with Carr now scheduled to take place in the last week of February. The agenda state the call will discuss Q4-2008 earnings, but it seems almost certain they will address the breach then, and hopefully will provide more details regarding an eventful August 2008.

From the press release:
Chairman & Chief Executive Officer Robert Carr and President & Chief Financial Officer Robert Baldwin will host a conference call beginning at 8:30 AM Eastern Time, Tuesday, February 24, 2009, to discuss fourth quarter and fiscal year end 2008 results and conduct a question and answer session.


Heartland Payment Systems invites all interested parties to listen to its conference call broadcast through a webcast on the Company's website. To access the call, please visit the Investor Relations portion of the Company?s website at: www.heartlandpaymentsystems.com. The webcast will be archived on the Company?s website within two hours of the live call and will remain available through Friday, May 22, 2009.


You may also participate by calling (800) 559-6679 and providing the operator with Pin Number 81829786
The SEC does require disclosure by company leadership of known threats to share price, so we should expect that more will be revealed during the call - unless the investigation would prevent the release of such information, in that case we would probably at least get some statements to that effect.

Either way it seems that much will be revealed in the call.

As for the latest breach, let’s hope it is not a record breaker and that no fraud cases are the result. Be vigilant about checking your own credit card statements and report any suspicious activity immediately. Then just keep your fingers crossed that we can effectively put the information security genie back in the bottle before the next breach is not just a financial security matter, but a national security event as well.

Anthony is a researcher, analyst and freelance writer who worked as a consultant to senior members of product development, secondary, and capital markets from the largest financial institutions in the country during the height of the credit bubble. Anthony’s work is featured by leading Internet publishers including Reuters, The Chicago Sun-Times, Business Week’s Business Exchange, Seeking Alpha, and ML-Implode.
Reblog this post [with Zemanta]

Saturday, February 14, 2009

Week in Review



Friday, February 13, 2009

Canadians Spending More Online

Online business analyst eMarketer reported that Canadian retailers would sell an estimated $15.5 billion Canadian worth of goods and services in 2008, up some 12.4 percent from 2007's total of C$13.8 billion.

By 2012, Canadian ecommerce sales should reach C$22.8 billion, including travel sales, digital tickets, and digital products like software. In spite of this projected growth, Canadian's still trail their U.S. consumers in terms of purchasing online, according to a new study from eMarketer.

"Consumers in Canada are avid online product researchers, on par with their US counterparts. But they are much more likely to make a subsequent purchase in-store rather than on a Website," said eMarketer on its website.




Reblog this post [with Zemanta]

Visa Showcases Mobile Payment/Money Transfer




Visa showcases mobile payments, money transfer, payment services at 2009 Mobile World Congress

London and San Francisco, Feb. 13, 2009 -- Visa Europe and Visa Inc. (NYSE: V - News), the world's largest retail electronic payments network1, will be showcasing the latest innovations in payments at the 2009 GSMA Mobile World Congress. In addition, Visa executives will discuss how Visa is helping to drive the convergence of financial services and mobile technology.

Visa will use real life examples to demonstrate how its innovations in mobile payment technologies can enhance consumers’ daily lives, providing speed, convenience, security and choice.

Visa mobile product demonstrations will include:

  • Visa Mobile on Android: In December, Visa launched the first commercial service in the U.S. that provides mobile offers, transaction alerts and a locator service. Visa Mobile is available on mobile devices powered by Android, including the T-Mobile G1™ phone.
  • Mobile Visa payWave: Secure mobile point of sale payments using Visa payWave embedded in a mobile device. Visa will demonstrate both NFC-based and SIM-based contactless payments.
  • Mobile Money Transfer: A demonstration of handset-to-handset and online-to-handset money transfer.
  • Mobile Transaction Alerts: Near real-time notification of card purchase activity delivered to the mobile device.
  • Mobile Offers: Targeted offers and coupons delivered directly to the mobile device and redeemed at near-by merchants.
  • Mobile Merchant: Convenient cashless transactions on the move. Mobile merchants, such as a pizza delivery service, can accept Visa payments with the help of enhanced mobile handsets that double as a mobile acceptance device.
  • Smart Poster: Co-branded mobile posters, signposting nearby coffee shops with the offer of exclusive mobile ‘buy one, get one free’ offers.

The Congress is the key global conference and exhibition for the mobile industry and is sponsored by the GSM Association (GSMA). It attracts more than 1,200 exhibitors, and more than 50,000 visitors including key Visa clients and vendors from around the world.

Visa executive speakers at the Mobile World Congress 2009 include:

  • Kelly Alpert, Head of Money Transfer Initiative, Visa Inc.
  • Mary Carol Harris, Head of Mobile, Visa Europe
  • Guido Mangiagalli, VP, Visa payWave and Mobile, Visa Europe
  • Pam Zuercher, Senior Business Leader, Product Innovation, Visa Inc.

Source: Company press release.







Reblog this post [with Zemanta]

PCI Compliance May Benefit Heartland - cardline

CardForum | PCI COMPLIANCE MAY BENEFIT BREACH-SUIT DEFENDANTS


PCI COMPLIANCE MAY BENEFIT BREACH-SUIT DEFENDANTS


Reported compliance with the Payment Card Industry Data Security Standard could help Heartland Payment Systems Inc. defend itself against class-action lawsuits filed in the aftermath of its reported card-data breach, according to Ronald Mann, a professor of law and co-chair of the Charles E. Gerber Transactional Studies Program at Columbia Law School.

Since Heartland announced the breach Jan. 20 (CardLine, 1/20), consumers have filed at least three lawsuits alleging the Princeton, N.J.-based merchant processor violated the Fair Credit Reporting Act and a variety of state data-breach notification and consumer-protection laws (CardLine, 1/29).

Plaintiffs could have difficulty proving the breach harmed them, given that, besides some cardholder names, the only breached information appears to have been card data, Mann says. Clearing fraudulent transactions from a card account can be a hassle for consumers, but issuers tend to cancel cards or reimburse cardholders for fraudulent transactions, he says. "In previous litigation in this area, class-action suits against the hacked merchant have suffered from the problem that the likelihood of identity theft or of substantial harm depends a great deal on the particular circumstances of the victims and of their card issuers," Mann says.


Web Retailers Post Solid Quarterly Sales

 
  Welcome to the new IRNewsLink Financials
Welcome to the new monthly IRNewsLink Financials newsletter. Understanding the financial performance of retailers and the technology and services providers who serve them has never been more important than in today’s economy. With this new monthly edition of IRNewsLink, readers can follow key financial and operations metrics. Included in this report are charts and articles that summarize the monthly activity of retailers’ web sales, the financial performance of key vendors, new equity deals, recent mergers and acquisitions, and Internet Retailer’s new stock index.

Web sales continue to increase
Internet retailers continue to grow sales both on a quarterly and an annual basis. The combined quarterly sales of 17 web retailers that broke out sales in January and early February grew by 14.1% to $8.25 billion in 2008 from $7.23 billion in the comparable quarter in 2007. The combined annual sales of 14 retailers grew by 24.6% to $23.04 billion in 2008 from $18.49 billion in 2007.

Retailers
 
 
 
 
Company name
Period
Recent sales (millions)
Year ago sales (millions)
Change
Q2
$230.10
$274.20
-16.1%
Q4
$6,700
$5,670
18.2%
FY
$19,170
$14,840
29.2%
Q4
$32.00
$26.70
19.9%
FY
$119.00
$102.00
16.7%
Q4
$16.00
$10.00
60.0%
FY
$50.00
$32.50
53.8%
Q4
$93.94
$91,30
2.9%
FY
$366.60
$339.30
8.0%
Q4
$67.80
$65.90
2.9%
FY
$165.00
$144.00
14.6%
Q3
$24.70
$25.40
-2.8%
Q1
$23.00
$14.80
55.4%
Q4
$359.60
$302.40
18.9%
FY
$1,360
$1,200
13.3%
FY
$18.50
$21.10
-12.3%
Q4
$255.90
$294.50
-13.1%
FY
$834.40
$765.90
8.9%
Q3
$28.60
$24.40
17.2%
Q4
$107.70
$97.50
10.5%
FY
$213.50
$186.70
14.4%
Q4
$10.10
$19.00
-46.8%
FY
$47.60
$79.70
-40.3%
Q4
$28.90
$64.00
-54.8%
FY
$134.70
$223.40
-39.7%
Q4
$79.00
$65.60
20.4%
FY
$245.20
$185.10
32.5%
Q4
$45.40
$69.80
-35.0%
FY
$180.80
$250.20
-27.7%
Q2
$138.90
$105.00
32.3%
Q4
$34.40
$24.50
45.7%
FY
$126.50
$87.80
40.0%
*Sales are in U.S. Dollars
Quarterly vendor sales grow slightly
The combined quarterly sales of 11 companies in January and early February grew by just 0.6% to $21.12 billion in 2008 from $20.99 billion in 2007. The combined annual sales of 10 vendors grew by 11% to $84.40 billion in 2008 from $76.03 billion in 2007.

Service & technology providers
Company name
Period
Recent sales (millions)
Year ago sales (millions)
Change
Q4
$45.40
$39.30
15.5%
FY
$164.60
$137.10
20.1%
Q4
$62.30
$45.40
37.2%
FY
$229.00
$117.00
95.7%
Q4
$95.90
$96.90
-1.0%
FY
$394.20
$349.30
12.9%
Q4
$2,040
$2,180
-6.4%
FY
$8,540
$7,670
11.3%
Q4
$5,700
$4,830
18.0%
FY
$21,800
$16,600
31.3%
Q4
$391.40
$335.10
16.8%
FY
$966.90
$750.00
28.9%
Q4
$106.20
$98.50
7.8%
FY
$390.30
$373.60
4.5%
Q1
$20.60
$17.70
16.4%
Q4
$19.60
$16.77
16.9%
FY
$74.65
$52.22
43.0%
Q4
$41.40
$31.70
30.6%
FY
$152.50
$108.50
40.6%
Q4
$83.00
$43.10
92.6%
FY
$296.00
$143.00
107.0%
FY
$300.00
$261.20
14.9%
Q4
$36.10
$30.70
17.6%
FY
$140.40
$112.10
25.2%
Q4
$12,700
$13,390
-5.2%
FY
$51,490
$49,690
3.6%
Q4
$247.00
$221.70
11.5%
FY
$961.73
$847.50
13.5%
 
Forward to a Friend

EComm Guide EComm Guide
 
       
 
Rising Above - Not Just Surviving -
The Economic Storm
The Internet Retailer 2009 Conference & Exhibition, America's Fastest Growing Show *, will be held June 15-18, 2009 at the Boston
Convention & Exhibition Center. IRCE 2009 is devoted to the strategies and tools that e-retailers can use to thrive in a recession. It draws e-retailers from all channels with the most comprehensive conference agenda and the largest display of e-retailing technology. Hear 179 E-Retail Pros in 94 conference sessions, visit 350 exhibiting companies and network with 5,000 E-Retailers.

 
     
Reblog this post [with Zemanta]

Disqus for ePayment News