Thursday, February 26, 2009

Jewel Thieves


How To Steal a PIN

Chicago Sun Times
FROM STNG WIRE REPORTS

Two women police say were accomplices in a scam were arrested early Wednesday for allegedly stealing cash using a debit card PIN number in the self-checkout lines of a Near North Side Jewel grocery.

Belmont Area detectives issued a community alert Wednesday after a man met two women outside a River North bar last month and later discovered his bank debit card was missing and $8,600 was withdrawn from his account.

Neither of the women in custody, both 23, are believed to have been involved in the other incident.

The accomplices were spotted using an allegedly stolen credit card in the self-check out lanes and, using its PIN number, swiped it several times, each time asking $100 cash back for a small purchase like gum or soda.

In the alert, Belmont Area detectives said there have been numerous similar incidents downtown and on the Near North Side, where men have been approached by women "offering a ride or a good time."

The women convince the victims to withdraw cash from an ATM, and as he does so, they watch him enter his PIN. The women later take his credit/debit card without his knowledge and use it at self-checkout lanes at the Jewel groceries at 1224 S. Wabash Ave., 1210 N. Clark St. and Ohio and State.

In last month's incident, after the women got the man's card, they purchased a low-priced item at the South Wabash Jewel then depleted the man's bank account by $8,600 by withdrawing cash in $100 increments, the alert said. The women were seen by a witness driving away in a white Lincoln Continental.

Police advise men to be alert to suspicious people extending invitations to "go for a ride" or who offer a "good time." Additionally, police advise against carrying an excessive amount of cash and/or credit cards.

“It’s the perfect crime,’’ according to a police authority, who said the crimes are hard to prosecute for at least two reasons.

The victims often don’t want to come forward because they don’t want their names used, especially if they are married and the amounts are sometimes not comparatively very significant for the bank to aggressively seek action.



Reblog this post [with Zemanta]

United - No Cash..."Card Info"


In a Press Release from United Airlines, they announced No Cash...Visa!  So your Martini's, Dewars, Makers Mark and other in-flight purchases must be paid for with CASH only.

If the reasoning behind this is that they don't want their steward's to pocket cash, then they apparently are not aware of the potential danger this poses for their customers.   Hopefully people will be able to swipe their cards from their seat because it's highly unrecommended to hand over your card (and thus the Track 2 data on the magnetic stripe) to a waitress at a restaurant, let alone a waitress in the sky.  The opportunity, and thus temptation to "skim" the card information might be too great for some and the passenger can be taken a ride.

Credit/Debit
Credit/Debit
Credit/Debit

No Cash...Card


United Airlines introduces onboard credit/debit card acceptance beginning March 23

CHICAGO, Feb. 25 /PRNewswire-FirstCall/ -- United Airlines is making the search for exact change a thing of the past. With United's new EasyPurchase, customers will be able to use credit and debit cards for onboard purchases beginning March 23.

After a brief transition period through the spring break season, United will phase out cash and only accept credit and debit cards on flights within the United States (including Hawaii) and on flights to and from Canada, Mexico, Central America and the Caribbean.

United will continue to accept cash in addition to credit and debit cards on flights to and from Europe, Asia, the Middle East and South America.

On United Express flights, cash will continue to be the accepted form of payment.

"Our customers have responded very positively over the past year as we tested credit and debit card purchases on many flights including trans-continental routes," says Alex Marren, senior vice president - Onboard Service. "Whether customers want to enjoy an in-flight cocktail or a popular snackbox, our customers' purchases will soon be just a quick swipe away."

With EasyPurchase, customers will be able to use major credit cards, including Visa, MasterCard, American Express, Discover, and Diners Club, and debit cards bearing the Visa or MasterCard logos.

In addition, users of United Mileage Plus Visa cards from Chase will earn 10 miles for every dollar spent on in-flight purchases. Travelers who apply and are approved for a Chase Mileage Plus Visa card using the exclusive onboard application will earn 30,000 Mileage Plus bonus miles and receive $25 off their next United Airlines ticket, after their first purchase.

About United

United Airlines (Nasdaq: UAUA) operates more than 3,000* flights a day on United and United Express to more than 200 U.S. domestic and international destinations from its hubs in Los Angeles, San Francisco, Denver, Chicago and Washington, D.C. With key global air rights in the Asia-Pacific region, Europe and Latin America, United is one of the largest international carriers based in the United States. United also is a founding member of Star Alliance, which provides connections for our customers to 912 destinations in 159 countries worldwide. United's 49,500 employees reside in every U.S. state and in many countries around the world. News releases and other information about United can be found at the company's Web site at united.com.

*Based on United's flight schedule between Jan. 1, 2009, and Jan. 1, 2010.

SOURCE United Airlines



Reblog this post [with Zemanta]

Mystery Processor's Breach Timeline


DATALOSSdb.org has released a comprehensive time-line on the Mystery Breach at one of our nation's prominent card processors.  Since the PIN Payments Blog has been following this closely,  we thought we'd share.  Kudos to DATALOSSdb.org for putting this together in a clear and concise way...

2009-02-26 by d2d

Here's a timeline of what we've seen surrounding this vaguely disclosed breach. First, some terms:

CAMS: This is an acronym for a Visa implemented system, the "Compromised Account Management System". Alerts are distributed via this system to banks and other financial institutions to facilitate card reissuing and fraud detection. Mastercard also issues similar alerts.

Card Not Present: This term means exactly what you think it does. The card was not physically present during the transaction. This is typical in online shopping, telephone sales, etc.

UPDATE | February 11th, 2009: VISA blasts out a CAMS notice, which has been contributed to OSF anonymously:

"Date: February 11, 2009 Entity Type: Acquirer Processor - Fraud Reported: Yes, elevated fraud rates on this event Visa Fraud Control & Investigations has been notified of a confirmed network intrusion that may have put Visa account numbers at risk. The reported incident involves confirmed unauthorized access to a U.S. acquirer processors settlement system of stored transaction information that included Primary Account Numbers (PANs) and expiration dates. No magnetic stripe track data has been identified at risk in this alert. Fraud analysis has revealed elevated card-not-present fraud rates on this incident. Even though it is not known if any account information was actually removed during the intrusion, we must still consider the data to be at risk because of the elevated fraud. Based on the forensic investigative findings, the entity began storing PANs and expiration dates in February 2008. The forensic investigation is ongoing. Any new material information will be provided in a CAMS update to better assist you with fraud and risk mitigation."

February 11th, 2009: Fiserv blasted out this alert to their customers (banks, credit unions, processors, etc). We were tipped on this by multiple sources. The statement reads:

"The Risk Office Team has received information from Visa and MasterCard regarding the confirmed compromise of a U.S.-based acquirer processor. Please note that the compromised card alerts for this event are not related to the Heartland Data Systems’ breach. Given that confirmation of the Heartland breach and this new compromise occurred in such close proximity, it’s possible that the same card numbers could appear on compromised card lists associated for both events. You may wish to take this into consideration as you execute your organization’s monitoring and/or reissue plans for recently compromised cards."

February 12th, 2009: The Community Bankers Association of Illinois posts a notice that included the following:

"Today, VISA announced that an unnamed processor recently reported that it had discovered a data breach. The processor’s name has been withheld pending completion of the forensic investigation..."

Between 2-11 and 2-13: The Tuscaloosa Federal Credit Union releases a notice regarding the incident that reads:

"On the heels of the Heartland Payment Systems breach, another U.S. acquirer-processor has confirmed a network intrusion exposing primary card numbers and card expiration dates for card-not-present (CNP) transactions. Unlike the Heartland Payment breach, this breach does not expose magnetic stripe track data. The reported incident involves confirmed unauthorized access to a U.S. acquirer processor’s settlement system of stored transaction information that included Primary Account Numbers (PANs) and expiration dates. As the entity involved has not yet issued a press release, Visa and MasterCard are unable to release the name of the merchant processor. It is important to note that this event is not related to the Heartland Payment Systems breach."

February 13th, 2009: The Independent Community Bankers of America releases this on their website:

"ICBA learned of another security breach involving a merchant processor. The breach appears to be large, but not as large or severe as the recent breach at Heartland Payment Systems. The name of the breached processor is unknown at this time, but ICBA knows that: All accounts and all brands were equally exposed; however, only card numbers and expiration dates were captured. No track data was captured. Because there is no evidence of skimming counterfeit and all known fraudulent transactions have been key entered, Visa's ADCR program will not cover losses. However, compliance and “card not present” (depending on status of VbyV/SecureCode) chargeback rights should apply. MC issuers must file via compliance as they always do. Alerts for this new incident are being reported under Visa series US-2009-088 and MasterCard series MCA0150-US-09."

February 13th, 2009: The Pennsylvania Credit Union Association released this statement which we've retrieved from google cache, as the content of the old notice is now displaying a new notice about something else. The old notice read:

"Earlier this week, Visa and MasterCard began issuing accounts involved in a merchant processor breach. The reported incident involves confirmed unauthorized access to a U.S. acquirer processor̢۪s settlement system of stored transaction information that included Primary Account Numbers (PANs) and expiration dates. No magnetic stripe track data has been identified at risk in this alert. As the entity involved has not yet issued a press release, Visa and MasterCard are unable to release the name of the merchant processor. It is important to note that this event is not related to the Heartland Payment Systems breach. While it has been confirmed that malicious software was placed on the processor̢۪s platform, there is no forensic evidence that accounts were viewed or taken by the hackers. Since the final forensic report has not been provided there is no estimate available at this time of the number of accounts involved in this event. Law enforcement is activity engaged in an investigation into this situation. Visa began releasing affected accounts on Monday, February 9, 2009 under CAMS event series US- 2009-0088-IC. They expect to have all accounts released by Friday, February 13. MasterCard began releasing accounts on Wednesday, February 11, 2009 under MC Alert series MCA0150-US-09. They have not provided any information as to when they expect to have all their accounts released. The current window of exposure provided by both card associations is from February 2008 through January 2009. The only data elements at risk are account number and expiration date. No track data, PIN, CVV2/CVC2 data or cardholder-identifying information was captured. As in all events, it is the issuer̢۪s decision whether or not a block and/or reissue decision is warranted. However, we would like to emphasize that this event carries a lower level of risk than the Heartland compromise."

February 13th, 2009: We posted a blog entry regarding what we've been hearing from tipsters, who are usually dead on about these things, but we did so only after corroborating that the tips we'd heard we're also being heard by others.

February 17th, 2009: The Alabama Credit Union posts a notice on their website that reads:

"Alabama Credit Union has been notified by VISA that some members' VISA credit card information may have been discovered during a breach at a card processor's site. VISA has not named the card processor."

February 17th, 2009: The Bankers' Bank of Kansas posts a notification which reads:

" Two large data compromises affecting credit and debit cards were announced the weeks of 1/21/09 and 2/09/09. BBOK BankCard actively monitors all alerts from Visa®, MasterCard®, and our processor for compromised card data...."

February 19th, 2009: The Alabama Credit Union follows up on their initial reporting with an update indicating how fraud is being committed as a result of this new breach, and it contains the following:

We have been notified by VISA that a lengthy list of VISA ATM/Debit Card numbers was included as part of a data breach at an unknown vendor's location. VISA has declined to name the vendor or processor. The fraudulent transactions are primarily characterized as purchases of prepaid phone cards, prepaid gift cards, and money orders from Wal-Mart, and usually occur in $100 increments.

February 22nd, 2009: We posted a follow-up to our original story, with new information (some of the above timeline items) gathered from databreaches.net.

February 24th, 2009: News reports are released about St. Mary's Credit Union receiving notification regarding this breach. The article writes:

"A breach of a credit card processing system at St. Mary's Credit Union yesterday affected up to 4,300 customers and likely cost the business more than $20,000....The credit union does not know the name of the processing system, but Battista said the breach likely affected people across the country..."

End of Timeline

This is what we know. Of course, there is a lot of speculation as to who the unnamed is. Our mailboxes here are on fire with speculation, and you can read the comments on some of our previous posts on the topic to see examples of it. We have no solid information regarding who the affected organization is. We do know that we've had two other major breaches recently involving this type of data, namely: RBS Worldpay and Heartland Payment Systems. We also know that in a statement to the consumerist, Visa and Heartland is adamant that this new breach was not them.

Ultimately, I think the banks will demand to know, considering the costs are mostly their burden to bear. But in the meantime, we wait.


Reblog this post [with Zemanta]

500,000 Websites Hit by SQL Injection in '08


darkReading says that SQL Injection hit 500,000 Websites last year:

Report: More Than 500,000 Websites Hit By New Form Of SQL Injection In '08
New Web breach incident report finds the bad guys deploying more automated attacks, targeting customers rather than data on sites

Feb 25, 2009 | 02:52 PM
By Kelly Jackson Higgins
DarkReading

A new flavor of an old-school Web attack was responsible for compromising more than 500,000 Websites last year.

An automated form of SQL injection using botnets emerged as the popular method of hacking Websites, according to a newly released report from the Web Hacking Incidents Database (WHID), an annual report by Breach Security and overseen by the Web Application Security Consortium (WASC). The report also found that attackers increasingly are targeting a Website's customers rather than the sensitive information in the site's database.

"It used to be that mostly e-commerce sites were targeted, but now it's potentially any site, especially those with a large customer base," says Ryan Barnett, director of application security research for Breach Security. "The attackers say, 'You're going to become a malware-launching point for us.'"

The so-called Mass SQL Injection Bot attacks basically automate the infection process; the Nihaorr1 and Asprox botnets both deployed this method last year, according to the report. "In the past, they had to do some manual reconnaissance with SQL injection to send the initial queries," Barnett says. The automated approach sent one request with a script that automated all of those recon steps -- using bots to perform the attacks.

"While the initial attack vector was SQL Injection, the overall attack more closely resembles a Cross-Site Scripting methodology as the end goal of the attack was to have malicious JavaScript execute within victims' browsers," the WHID reports says. "The JavaScript calls up remote malicious code that attempts to exploit various known browser flaws to install Trojans and Keyloggers in order to steal login credentials to other web applications."


Continue "darkReading"



Reblog this post [with Zemanta]

Heartland Being Thoroughly Investigated


The SEC had launched an informal inquiry into the company and there is also a related investigation by the Department of Justice. The U.S. Department of the Treasury's Office of the Comptroller of the Currency (OCC), which regulates national banks and their service providers, has launched an inquiry, as has the FTC

Editor's Note:  Investigations by the FTC and DOJ are not uncommon. The SEC investigation has nothing to do with the breach, but with starting to sell 80,000 shares per month and it coinciding with the timeframe of the breach. 

What's rare is the OCC investigation.  Gartner Distinguished Analyst, Avivah Litan, has a take on why they are involved.


The Treasury's OCC may be taking an interest in the breach because it could be part of a larger problem for the banking industry, said Avivah Litan, an analyst with Gartner Research. "I think that the criminal gang that targeted Heartland is targeting multiple payment processors and it's a serious threat to the integrity of the payment systems," she said.

Yes, there is a serious threat to the integrity of the payment systems. It all has to do with information security/data encryption. Data traveling over the network should be securely encrypted from the point of data entry (the POS) to the point where the data is processed (V/MC).  Beginning-to-End Encryption (B2EE)
will be costly and time consuming to implement, but look at the alternative.  (and yes...there is a HomeATM pun "encrypted" with 3DES/DUKPT in there)

In recent months at least three credit-card processing companies, including Heartland, have been the victims of sophisticated criminal attacks resulting in millions of compromised payment cards. One of the other card processors, RBS WorldPay, lost data on 1.5 million customers. A third hack, at an unnamed payment processor, was disclosed last week.

In related news, Heartland announced yesterday that the President and Chief Financial OfficerRobert Baldwin will be participating at the Goldman Sachs Technologyand Internet Conference, February 26, 2009, at 6:20 PM at the SanFrancisco Marriott in San Francisco, California.

After thelive presentation the web cast will be archived on the Company’swebsite. Those who are interested can listen to a live web cast of thepresentation on the Investor Relations section of Heartland’s websiteat: http://www.heartlandpaymentsystems.com.



Reblog this post [with Zemanta]

Wednesday, February 25, 2009

HomeATM Featured in American Banker



In an article published by American Banker, Will Hernandez, Associate Editor of ATM&Debit News writes about "some" of the recent developments occuring within the exciting world of HomeATM.  Normally, I'd provide a few quotes and a link to the full article, but in this case, you would need to be a subscriber to either American Banker or ATM&Debit News in order to read the article in it's entirely.


Test Planned for Debit Reader for Use at Home

American Banker | By Will Hernandez

In
creased attention to data breaches could provide a boost to a Montreal company that has developed a way for shoppers to use plug-in card readers with their home computers to make PIN debit purchases online.

HomeATM ePayment Solutions is preparing to test a reader that consumers can plug into a computer's USB port. When shoppers make a PIN debit purchase at participating merchants' Web sites, the checkout software prompts them to swipe the card and enter the PIN.

Kenneth Mages, HomeATM's chairman and chief executive, said in an interview last week that the SafeTPIN reader could make consumers more comfortable using their cards online and will enable merchants to process the payments at card-present interchange rates, rather than the more expensive card-not-present rates.

Several merchants, including a large U.S. airline, are considering participating in the upcoming test, Mr. Mages said, though he would not name them.

"It's a lot more acceptable now to plug something into the USB port," said John B. Frank, HomeATM's executive adviser. "Combined with all these breaches, it's time for people to make some new decisions." 

The transaction processor Heartland Payment Systems Inc. reported last month that hackers breached its network last year and captured the account numbers and expiration dates of a number of debit and credit cards.

Since 2001, 72% of all payment card breaches have involved software at the point of sale, according to the Chicago data security company Trustwave Holdings Inc.; 23% occurred through online shopping carts, and 1% involved a hardware breach.

Analysts said they persuading consumers to use the readers will be a challenge.

Adil Moussa, an analyst at the Boston research company Aite Group LLC, said consumers are reluctant to use such devices. "People want easier and simpler things to use. Asking people to have another device on their desk for their online shopping is not really a way to achieve that."

Avivah Litan, a vice president and research director at the market research company Gartner Inc., routinely warns people not to use debit cards and PINs online.

"The Holy Grail for criminals is PINs and ATM cards," Ms. Litan said. "I would highly recommend [to any consumer] not entering their PIN anywhere on the Internet unless it was hardware-based."

Mr. Mages said HomeATM's device encrypts payment data moving between consumers' computers, HomeATM's data center, merchants, and processors. "We also encrypt the Track 2 data, which isn't done at" retailers.

Fidelity National Information Services Inc.'s eFunds Inc. will process HomeATM transactions.

Mr. Mages said lower interchange rates will appeal to merchants and hopefully will encourage them to distribute the readers to their customers.

According to Mr. Frank, merchants can save more than 75 basis points on card-present transactions compared with card-not-present ones. "That's a $7.5 million interchange savings for a $1 billion retailer converting its customers to a card-present environment."

However, HomeATM could face some hurdles in delivering the readers to consumers. The company plans to sell them to merchants, which would distribute them to customers. They cost about $15 to produce. Mr. Mages said lower interchange rates will attract merchants; the next step is securing merchants to distribute the device.

Ms. Litan said this is a classic "chicken-and-egg problem."

"Consumers will not start using these devices until merchants accept them, and merchants will not accept them unless there are huge incentives," she said. "The trick is finding someone with a big market presence that's willing to introduce something new to the market."

Mr. Hernandez is the associate editor of ATM&Debit News.


Reblog this post [with Zemanta]

HomeATM Added To FinovateStartup09 Lineup

HomeATM has been added to the FinovateStartup09 Lineup to be held April 28th and we look forward to demonstrating how our technology can completely change the online payments landscape. 

In addition to providing an immensely more CNP2CP (Card Present To Card Present) Platform, HomeATM transactions are dually authenticated. (1.What you have/Card and 2.What you know/PIN)

Unlike any other payment method that we know of, HATM also provides a 3DES DUKPT End-to-End Encryption.  Our Pin Entry Device was recently tested by Witham Laboratories and met or exceeded PCI 2.0 PED requirements.  We are confident that our patented process offers the most secure online payment methodology in the industry.  We look forward to providing more insight to attendees of FinovateStartup09 in April.  See you there!



Finovate Startup Conference Lineup

The financial services startup community will be out in force April 28 at our second annual Finovate Startup conference.

The nine new companies below, along with the 39 participants announced two weeks ago, plus several we can't yet name, brings the total to 50 startups. That's eleven more than we had last year! We can now say that we'll have the largest group of financial services startups ever assembled in one place.

Don't miss your opportunity to talk to the companies that will help change the financial services landscape in the coming years. Join the many bank, credit union, and technology execs in San Francisco on Tuesday, April 28 for a thought-provoking and exciting day (see note 1).

The early-bird deadline ends Friday, so register now for just $795. Current Online Banking Report subscribers can save even more. Look on the back page of the most recent issue, or email info@netbanker.com for your customer discount code.

Here are the latest additions to the conference



  • WeSeed


For further information on FinovateStartup09 please visit NetBanker.com or Finovate.com








Reblog this post [with Zemanta]

Did Heartland Make False and Misleading Statements?

According to ShareholdersFoundation.com there is an investor investigation looking into possible securities violations related to public statements made by Heartland Payment Systems (HPY, see chart below...wow, under $5.50 now) between 8/5/08 and 2/23/09. Here's their statement:

Heartland Payment Systems, Inc Investor Investigation

If you purchased Heartland Payment Systems, Inc (NYSE:HPY) common stock between August 5, 2008 and February 23, 2009, you have certain options and you should contact the Shareholders Foundation, Inc. immediately!

You may contact us by using this form, or by sending an email to mail@shareholdersfoundation.com, or calling us at (858) 779-1554.

Company Name(s): Heartland Payment Systems
Affected Securities: NYSE: HPY  (Editor's Note: Soon to be SAD)


According to a press release there is an investigation on behalf of investors in Heartland Payment Systems, Inc. (NYSE:HPY) concerning possible securities violations related to public statements made by the Company between August 5, 2008 and February 23, 2009 was announced.

According to the press release the investigation by a law firm focuses on allegations that statements made by Heartland Payment Systems, Inc (“Heartland“) between August 5, 2008 and February 23, 2009 were false and misleading and failed to disclose or indicate, among other things, that Heartland’s safety and security measures designed to protect consumers' financial records and data from security breaches were inadequate and ineffective; Heartland faced liabilities associated with a breach of its payment processing network and increasing costs associated with implementing appropriate security measures; and as a result of a breach its payment processing network, Heartland was at risk of losing customers. Heartland Payment Systems, Inc. is primarily engaged in providing bank card payment processing services to merchants in the United States.


Banks Need Alternative Payments


In an article published yesterday in American Banker by Bruce Cundiff, he argues that the global economic slowdown could provide an opportunity for alternative payment companies and banks to strategically partner. Here's an excerpt:
Alternative Payments

The global economic slowdown, which is driving down consumer spending and credit card purchases, could prompt banks to adopt alternative payment systems.

Retailers have become increasingly interested in recent years in offering customers alternatives to credit and debit cards. These systems often exclude the traditional payment providers, and the main benefits of these transactions — revenue, customer relationship enhancement, or brand equity — flow to companies other than banks and card networks.

But many financial companies are wondering whether the economic downturn will fuel faster adoption of alternative payment methods and, perhaps more importantly, how that could impact their own payment revenue.

I argue that it is not a matter of whether alternative payments will gain steam as a result of economic difficulties. Rather, in the face of economic difficulties, financial institutions must embrace the alternative.

We must understand the value proposition, and the motivations, of various players in the retail payment ecosystem.

I'd provide a link to finish reading the article, but American Banker is a subscriber-based publication. To subscribe go to AmericanBanker.com

Reblog this post [with Zemanta]

Nigeria Chip and PIN Migration Begins with CBN Compliance


THE Central bank of Nigeria, CBN recently recorded compliance to its directive that all banks in Nigeria migrate from magstripe type of payment cards to chip and PIN based cards.

This is as Intercontinental bank Plc rolled out drums last week in celebration of its pioneering the first Chip and PIN verve card tagged Intercontinental Verve card. The event held at its Victoria Island Lagos headquarters at the weekend. 

The CBN in apparent bid to curtail the growing fraud prevalent in the banking sector, woke up recently, directing all banks operating in Nigeria to migrate from the magstripe based payment cards to chip based before the end of the second quarter of this year.

Obviously the magstripe cards were prone to compromise due to its method of usage and easy way of duplication. Because a magstripe card is used mostly by swiping across a terminal, fraudsters devised a means of inventing magnetic mechanism which retains the details of the card after being swiped on the machines and of course its cheap and easy way of production fueled more frauds that left unfortunate card users in misery.

So the introduction of this brand of payment card, which runs on Interswitch platform, makes the bank the first to comply with the CBN directive and according to the bank, gives its customers a leverage which others would always envy to experience.

Group Chief Executive of the bank, Dr Erastus Akingbola, while addressing the gathering at the launch of the card, described the development as another feat by Intercontinental Bank, saying this has separated the men from the boys in the banking business in Nigeria.

According to Akingbola, through today’s event Intercontinental has become the first Nigerian bank to issue the Verve Chip and PIN with loyalty card created in Nigeria for the world. With this development a new symbol of technological progress is making headlines in the Nigerian e-banking industry.

Akingbola said that besides upgrading all its channels to honour transactions initiated from these cards, in line with the CBN directive, his bank also deemed it necessary to move a step further by introducing the chip based card.He noted that staff from relevant departments of the bank were also trained on different aspects bordering on card operations, card issuance, business and product development dynamics set around the functionalities of these cards in order to ensure effective compliance and management.

He stated that the bank has ordered and taken delivery of the two brands of the chip cards and presently working on the modalities involved in migrating all its customers to the new enhanced and more secure EMV chip and PIN verve payment card on the Interswitch platform.

The Bank believes that by the new development, it is also adding another feather to its cap by making history as the first bank to issue a full EMV compliant local debit card in Nigeria.

Verve is a chip based card positioned as a premium, innovative brand set to meet the needs of the issuer, merchant and consumer by providing convenience, absolute security, reliability, recognition and reward.

According to Akingbola, “the cards many features have become a hot topic lately, and for good reason, because it surrounds transactions with iron-clad security.  The era of card cloning and loss of funds is coming to an end. In a nutshell, the information stored on the embedded microchip on this card is extremely difficult to hack and transactions are done with an even more secure personal identification number (PIN)”.

He said Intercontinental Bank PLC has always been a front runner in service delivery and customer satisfaction and will be taking the lead in the issuance of this new secured chip cards.





, ,

Prepaid Cards Summit 2009



Through Prepaid Card Summit 2009 and its associated publications Cards International and Electronic Payments International, VRL is pleased to announce this year's conference to be held in Rome, Italy in October 2009. Confirmed dates for your diary will be announced shortly.

Now in its fifth consecutive year, Prepaid Card Summit is an industry leading event and the only truly European card event of 2009. Join us in Rome to experience a stimulating conference, our agenda will be planned with the unique knowledge and understanding of the editorial teams of Cards International and Electronic Payments to cover the key issues and challenges involved in exploiting these relevant markets.

The event will cover European markets including Italian, German and Belgium along with Eastern Europe, all of whom are starting to experience growth with many new programmes launching every month. Italy boasts the most successful prepaid programme in Europe, Poste Italiane, making the location an appropriate choice for the event itself.

For more information

Our website is a regularly updated with information related to Prepaid Cards Summit 2009 including the latest agenda and speaker information.

Want to know more about VRL's previous highly successful prepaid conferences? Download our 2008 reference guide.


Monitise & Metavante Launch Text Message Banking



Service enables consumers to use text messaging for alerts and any-time balance information

PROVIDENCE, R.I., and MILWAUKEE, Feb. 25 /PRNewswire/ -- Monitise Americas, the mobile money people, and Metavante today announced the launch of text message banking services.

The service will allow consumers to use text messaging to obtain any-time balance information on their accounts.
It also enables consumers to set alerts, to notify them when their balance is low or when their payroll deposit has arrived, for example. Metavante Corporation is the first provider to deploy the new technology from Monitise Americas. Metavante (NYSE: MV) is a leading provider of banking and payments technology.

Monitise Americas is well-known for providing mobile money services using secure applications that consumers download to their cell phones. The company has added text message banking to deliver financial information to all mobile phone users, whether they have advanced, data-enabled handsets or more simple devices.

"Text alerts have become mainstream for many consumer services today. Many of us already receive news alerts on our mobile," said Lisa Stanton, chief executive officer of Monitise Americas. "Especially in this economy, consumers have told us that they want immediate access to their financial information. Mobile financial alerts will allow consumers to manage their money any time, anywhere, and I firmly believe that there is no better time to introduce this than now."

The integration of Metavante payments solutions -- including bill pay, prepaid and the NYCE Network -- with its mobile financial services creates a clear line of sight to mobile payments and commerce. This type of integration also creates the benefit of making mobile services available to virtually all account holders at a financial institution.

"Metavante is committed to keeping our clients competitive by moving consumers to mobile banking," said Frank D'Angelo, group president, Metavante Payment Solutions, and chairman of the board for Monitise Americas. "By enabling this text messaging functionality, we are making money management via a mobile phone available to virtually anyone, and making it easy for even reluctant consumers to engage with the idea of using their mobile phones to manage their finances."
About Monitise Americas

Monitise Americas is a joint venture between Metavante Corporation, a leading provider of banking and payments technologies to financial institutions and businesses worldwide and Monitise plc (MONI.L), the mobile money specialists. Monitise Americas provides mobile banking and payment services to North American financial institutions based on an "ecosystem" principle, which allows multiple mobile carriers and financial institutions to deliver services over a single platform. It has a sister ecosystem in the United Kingdom, MONILINK, developed by Monitise plc in partnership with VocaLink. Current partners of MONILINK include: first direct, Alliance & Leicester, Royal Bank of Scotland, NatWest, Vodafone, Orange, O2, T-Mobile and Hutchison 3G.

For more information on Monitise Americas and details of how to benefit from participating in its cross-America ecosystem, please visit www.monitise.com and www.monitiseamericas.com.

About Metavante

Metavante Technologies, Inc. (NYSE: MV) is the parent company of Metavante Corporation. Metavante Corporation delivers banking and payments technologies to over 8,000 financial services firms and businesses worldwide. Metavante products and services drive account processing for deposit, loan and trust systems, image-based and conventional check processing, electronic funds transfer, consumer healthcare payments, electronic presentment and payment, outsourcing, and payment network solutions including the NYCE Network, a leading ATM/PIN debit network. Metavante (www.metavante.com) is headquartered in Milwaukee.

Metavante and NYCE are registered trademarks of Metavante Corporation, which is the principal subsidiary of Metavante Technologies, Inc.


SOURCE Monitise Americas


Tuesday, February 24, 2009

UK Online Fraud Report - PIN Debit is the Answer?

CyberSource has released their UK Online Fraud Report. 

Interestingly, the report focuses on areas that HomeATM's patented PIN Debit platform would  solve. 

For example:

In the report (see graphic on the left and click to enlarge) they say that there is no concept of a real-time authorization when it comes to a payment by direct debit.  That the merchant will not know whether they will get their money until it actually arrives in their bank 3 days later.  

However, PIN Debit transactions are real-time, authorizations are immediate ad the funds are instantaneously set aside, guaranteeing payment.  In addition, chargebacks (except for extreme circumstances) are virtually eliminated and therefore the problem addressed in the chart on the left would be immediately/instantaneously solved. 

Another significant finding in the report is that that Internet Retailers continue to bear the the increasing burden of Fraud.  (see chart on right, click to enlarge)  What does PIN Debit do to reduce fraud and thus the financial burden associated with it?

PIN Debit not only provides dual-authentication (What you have/card and What you Know/PIN) but it also provides end-to-end encryption (E2EE).

So if merchants are the one's stuck with eating the cost of fraud, then maybe they should be the one's who take action and institute a safer payment alternative.

With Dual-Auth and E2EE, there is no safer payment mechanism than PIN Debit.

In today's tough economic environment, combined with low margins, can 13% of Internet Retailers continue losing 5% of their revenue?  Assuming 5% margins, can 37% of Internet Retailers afford to lose 20% of their revenue? 

Those numbers do NOT take into account the savings that could be enjoyed by switching over to the more secure, lower cost PIN Debit.  A billion dollar in annual sales Internet Retailer could save up to 100 basis points on each transaction.  Assuming they are paying an average of 2%, that would cut their processing fees in half.  Put another way, $20 million in processing would be reduced to $10,000,000.  What would that do do their bottom line?  Well, it would ADD 1%.  Since 37%  are LOSING 1%, that's a 2% swing.  Going back to the 5% margin example, that's a 40% increase in revenue.  Those are NOT insignificant numbers.

In addition, the report also shows that 50% of UK Consumers are AFRAID to shop online.  (Chart on left, click to enlarge)

Well, I say that if you give them a more secure transaction, let's say, one with dual-authentication, one that provides E2EE you have an exponentially better opportunity to alleviate those fears.  And once you decrease the fears, you increase the possibilities. 

Add those numbers to the equation (converting 50% of the population to online shopping by alleviating their fears) by offering a secure payment mechanism and you've got one heck of an enduring strategy to contend with the problem.  

The recession should help online retailers as it bites into bricks and mortar (high street) sales. Experienced online shoppers know that they can do research, comparison shop, and get the best deal. 

Now all the Internet Retailers need to do is to cut fraud, mitigate risk, and provide a faster route to receive their payments. 

Real-time, dual-auth, E2EE PIN Debit transactions are not only a perfect fit.  Don't believe me?  Do research and comparison shop.  Then come to your own conclusions as to what payment mechanism gives you more bang for your shoppers buck.  To get you started I've provided links at the end of this post.  (Related Articles)

To review.  PIN debit provides real-time authorization, sorry mate, "authorisation"...immediately sets aside the funds (guaranteeing payment) reduces the fraud that Internet Retailers are stuck holding the bag on, reduces processing costs by up to 100 basis points, and increases the consumers faith that it's a safe, secure, dually-authenticated, end to end encrypted transaction, thus alleviating their fears.




Where am I wrong here?  I'm not trying to be a wanker.  I'm just curious as to what it might be that I am missing.  Anyone disagee?  Anyone have other thoughts?  Love to hear them...post your comments below...

JBF - PIN Payments Blog



Reblog this post [with Zemanta]

Heartland Exposes "It's Own" Card?

Is Heartland going to take the position that they are a plaintiff rather than a defendant against claims from cardholders/issuers and V/MC themselves? Will they shoot back or is PCI DSS certification going to shoot down any argument that V/MC may have?

Heartland Payment Systems, Bob Carr shows one of his cards. In their newly released 4th Quarter Earnings Report (which by the way was pre-breach) he says that one of the biggest challenges they face in regards to the breach is "defending" claims that the "cardholders" "card issuers" V/MC, regulators (and others) have asserted (or may assert).

For the first time (that I've seen) he implies that they intend to not only vigorously defend any such claims, but that they have "meritorious defenses" to those claims. So it appears that they are preparing to claim that they are the plaintiffs and the defendants are going to be the brands (V/MC) Undoubtedly, they will use their PCI DSS certification as a launching pad to deter blame from them to others. PCI DSS may be the bullet that Heartland fires back with if V/MC tries to shoot them down.

This is going to be an interesting legal development and the PIN Payments Blog will keep a close eye on further developments...



Heartland Payment Systems Reports Fourth Quarter Earnings of $0.21 Per Diluted Share - MarketWatch

Heartland is committed to aggressively pursuing its efforts for the development and industry-wide implementation of end-to-end encryption technology- which if successfully developed and implemented will be designed to protect data at rest as well as data in motion - as an improved and safer standard of payments security.

"Clearly our biggest challenge in 2009 will arise from the system breach we suffered. There are two main components to the challenge we face: addressing claims that cardholders, card issuers, the Brands, regulators, and others have asserted, or may assert, against us arising out of the breach and managing the potential impact of the breach on the day-to-day operations of our business.

With regard to the first challenge, we intend to vigorously defend any such claims and we believe we have meritorious defenses to those claims that have been asserted to date.

At this time we do not have information that would enable us to reasonably estimate the amount of losses we might incur in connection with such claims. As to the second challenge, our sales and service teams have responded tremendously, and early indications of client response are positive: in the weeks since our announcement of the breach, we have installed more margin, and have a bit less merchant attrition, than in the same period in 2008. While it is too early to tell, and we will certainly face challenges from macro economic conditions confronting our customers, at this point we believe that our expanded product breadth, reputation for superior customer service, candor, and no arbitrary rate increases, should allow us to grow our card processing merchants, payroll clients and check management clients in 2009. I am very proud of our Heartland employees, who are aggressively reaching out to strengthen our relationships and maintain the trust and confidence of the merchant community."


Reblog this post [with Zemanta]

Report: ATM Transactions Will Rise

ATM Future Trends | New report says ATM consolidation will continue, ATM transaction volumes will rise | ATM Marketplace
New report says ATM consolidation will continue, ATM transaction volumes will rise

BOSTON — Tremont Capital Group, an ATM-industry consultancy that works closely with the ATM Industry Association, (ATMIA) has released its 2009 ATM Industry Fact Sheet, which summarizes the history and current state of the ATM industry.

Among its findings, Tremont Capital Group estimates that 401,500 ATMs are currently deployed within the United States, approximately 202,500 (50 percent) of which are now operated by independent sales organizations. Tremont Capital Group predicts that rapid consolidation in the ISO sector will continue in the near-term, until consolidators acquire the nation's remaining viable small- to mid-sized ATM portfolios.

"As the United States marks the 40th anniversary of its first ATMs, the number of ATMs deployed in the nation has surpassed the 400,000 milestone and cash remains the dominant payment mechanism for consumers," said Sam M. Ditzion, chief executive of Tremont Capital Group.

(Editor's Note:  Actually, Cash is no Longer King... See yesterday's post:
"Debit is King, Replaces Cash on Throne"   Then again, I suppose you need your debit card to withdraw cash at an ATM.  So, does pulling out $200 with your debit card, and then spending  that same $200 in cash result in a stalemate...?) 

"Tremont Capital Group anticipates three key trends in the industry in 2009. First, average ATM transaction volumes will stabilize and possibly increase as consumer credit standards continue to tighten and the deleveraging process deepens. Second, financial institutions will slightly consolidate their ATM networks, while continuing to implement check-imaging upgrades on an accelerated basis. Third, the ISO sector of the ATM industry will experience continued merger and acquisition activity."

Tremont Capital Group's report is available for free from the company's Web site.





Operation Tuna Puts 4 in the Can


TheStar.com | Crime | Four charged in credit card fraud ring
Canada: Police have charged four people in connection with an organized credit card fraud ring that victimized over 200 clients of a high-end women's spa in Yorkville.

The accused allegedly used a tampered PIN pad device at the spa to access users' credit card information during the spring and summer of 2008.

They then manufactured new credit cards and used them to furnish and renovate condominiums in Yorkville, buy hundreds of thousands of dollars in clothing, and open a new "legitimate" business, Jung Spa, at 257 Danforth Avenue.

The accused allegedly stole the credit card information from 216 clients of the spa. Police are advising people to check their credit card statements to make sure they weren't victims of the fraud scheme.

Police from the 11 Division Major Crime Unit and the 14 Division Fraud Office began their investigation, dubbed "Project Tuna", in June 2008. 
(Editor's Note:  I don't mean to tell the police how to name their investigations, but wouldn't "Project Tuna" be more a more aptly named investigation for a phishing scheme?)  

On Thursday, Feb. 19 they executed six search warrants, primarily in the Yorkville area, and seized furniture, electronics, purses and more – to the "tuna" more than $285,000 to date.  Goran Sadic, 44, Filip Djukic, 39, Julia Sung, 25, and Milena Sadic, 41, all of Toronto, face hundreds of fraud-related charges.  Throw 'em in the can!


Chase Gets Patent for Fraud Analysis

Chase patents card fraud analysis system

Chase Card Services has received a patent for First Watch Intelligence, an analytical application for detecting credit card fraud and ID theft.

First Watch Intelligence creates an automated system for evaluating more than 40 fraud factors, which is used by Chase employees to monitor consumer accounts for indications of potential fraudulent abuse.

Chase executives says the current economic crisis is likely to lead to a rise in attempted credit card fraud over the coming year.

Bill Mann, executive director, patent and business development, Chase Card Services, says: "As the number of fraud cases increases in this time of economic uncertainty, the timing is ripe for this innovative patent, which is already being used to protect our customers."




Card and Payments in Asia Report from VRL


VRL has announced the release of their new report, Cards & Payments in Asia.  To request an executive summary of the report, you may click here.

Payment cards have played a major role in the Asia-Pacific region, and it is predicted that several key markets will continue to see significant consumer base and spending growth. According to the Asian Development Bank, more than 300 million households in the Asia-Pacific region lack access to basic financial services. Despite the low base, credit card spending at the point of sale has grown rapidly and debit cards have increasingly shown high growth levels.

However, Asia remains a very cash-dominant society. Many areas remain isolated and rural, which will impede on overall growth potential. Additionally, issuers remain very cautious about growth in the Asia-Pacific region given the current global economic downturn. In the past, the most significant hurdle for industry growth has been the lack of effective risk management, and while in many countries this is being addressed through the formation of credit bureaus and the development of comprehensive data reporting systems, it is still a significant challenge.

Nevertheless, it is worth pointing out that the region did go through its own version of the credit crunch several years ago with the loan default crises in Korea, Hong Kong and Taiwan and for the most part the lessons of inadequate risk management have been learned.

Widely speaking, some markets in the region will continue to grow rapidly as their economies mature and a larger consumer base is developed. The more developed countries such as Australia and Japan will expand but less so. However, each market brings with it its own unique set of circumstances, such as Taiwan and its recent NPL trouble and recovery. Another example would be the Australian market and its interchange battles with regulatory bodies.

The first section of the report will examine both macro and micro economic factors that will be largely responsible for influencing the growth and profit of financial cards industry in the Asia-Pacific region. These are:

  • Market demographics – this chapter looks at the wider economic influences that will have an effect on potential growth within the Asia-Pacific region. This includes consumer spending, consumer confidence and population statistics, and also looks at any potential cultural trends that may play a role in the adoption of payment cards and consumer credit.

  • Acquiring industry structure – this chapter focuses on merchant service fees and interchange rates that drive revenues as well as the merchant coverage that allows for consumers to use cards to make payments. It looks at potential regional challenges for the acquiring industry as well as possible solutions and areas for growth, and then examines both the acquiring environment of several countries in the region.

  • Regulatory environment – this chapter examines the causes behind the default crises seen across several Asia-Pacific markets in 2004-2005, and how regulatory bodies have reacted. It also looks at fresh challenges seen in markets such as China that are seeing an increased foreign presence in the market, and the process of Basel II implementation process throughout the region will highlight the varying approaches that regulators have adopted in order to meet these new risk management requirements.

  • Product mix – the main focus of this chapter is the various card products (debit, credit and prepaid) that are available in the Asia-Pacific region, the opportunities they present for volume and transaction value growth as well as the various challenges that specific markets will present. Prepaid opportunities are examined in close detail across several countries.

  • Technology developments – this chapter looks at influence of technology on the growth and profitability levels of the Asia-Pacific payment cards industry. The growth and underlying potential of mobile banking, prepaid applications and contactless technology within several key markets has only recently come to the fore, and these are examined in greater detail.

  • Level of competitive intensity – this chapter looks at markets across the region individually, examining which of the factors covered in the previous chapters will play a significant role in the growth and development of the cards market.

These influences will combine to drive growth and profitability levels in the market.


$56.6 Billion Lost to ID Theft


Identity theft costs a record $56.6 billion

Written by Identity Theft Daily Staff
Tuesday, 24 February 2009


Identity theft, the biggest source of U.S. consumer fraud, costs a record $56.6 billion in cash, goods, and services. Two thirds of victims have no out-of-pocket expense (because banks and credit card companies seldom ask victims to cover any charges), for about 3 million victims, the average cost of repairing their credit was nearly $1,200 and for all victims the average time to set the record straight was 40 hours.

Fortunately, ID theft is declining after cases reported to the Federal Trade Commission (FTC) nearly tripled from 2001 through 2004, the number of identity fraud victims in the United States was 8.1 million in 2007, a 3.6 percent decrease from the 8.4 million in 2006 and a 9.0 percent decrease from 2005 according to Javelin Strategy & Research. Awareness by consumers and creditors coupled with technological safeguards has helped curb cases of identity theft.

The most frequent source of information for ID thieves is you according to the Javelin survey, among victims who knew how their numbers were pilfered, 30 percent of frauds began with a lost or stolen wallet, checkbook, or credit card. So don't carry PIN codes for your plastic or your Social Security card. One in seven cases of ID theft traced to a source turns up a family member or other trusted associate the victim. Keep your checkbook, credit cards, and any important papers (such as mortgage, insurance, and investment records) under lock and key. Javelin found, frauds first noticed by victims were uncovered a month sooner than those financial institutions identified. Regularly checking credit card and bank statements, it's good to scan your credit history for inquiries on existing accounts and applications for new loans. You can get one free credit history annually from each of the three major bureaus (Experian, Equifax, and TransUnion) at www.annualcreditreport.com. By rotating your requests, you can receive a report every four months.

Households earning less than $50,000 are three times more likely to be victimized by fraud according to Javelin Strategy & Research. According to Frost & Sullivan, the amount of credit card fraud is projected to reach $15.5 billion, up from $7.5 billion in 2007. Deloitte says that 51 percent of external attacks on financial institutions were phishing followed by spyware at 48 percent. Recent laws in eight states let you freeze access to your credit file to keep anyone, legit or not from reviewing your standing or opening loans in your name. Freezes that used to be applied by credit bureaus only after ID thieves struck are available free by law to any citizen in Colorado and New Jersey. Consumers in California, Connecticut, Louisiana, Maine, Nevada, and North Carolina can stop credit tampering cold for a small fee, generally up to $10. And for another $5 or $10 the same eight states allow a credit thaw when you need a new loan. Freezes are also available by law to ID-theft victims in Illinois, Texas, Vermont, and Washington.

continue reading at Identity Theft Daily




, ,

Visa Confirms Another Payment Processor Breach

Another Month...Another Data Breach. 

Visa confirmed today that
rampant rumors of yet another major payment processor breach are, in fact, true.  That marks the third straight month with a "massive" data breach.

The article states that the "victim" (interesting choice of words) appears to be a provider that processes online transactions. 

I say it's high time for the more secure E2EE online debit to make a marquee appearance on the web.  After all, this is getting crazy...and it's just the beginning.  Malicious code today, SSL or DNS attack tomorrow.

In a new report that came out yesterday from BAI and Hitachi Consulting, (see Debit is King, Cash Overthrone") it was revealed that Debit now makes up 37% of all payments.  Cash is second at 29%.  PIN is preferred 45% to 35%.  So, think about it.   Debit is #1, Cash is #2, and PIN Debit is the same as a real-time cash payment...and it provides end to end encryption.  And it's known as online debit.  So when is a major player, oh, let's say V or MC going to realize that it's time to back online debit for online shopping?  These breaches may force their hand sooner vs. later.

In all three breaches, RBS
Worldpay, Heartland  Payments and the latest mystery processor, PIN's were NOT compromised.  In fact, you never read about PIN's being compromised.  (Yes, there was one isolated incident last July with Citibank ATM's, but they were using a Windows based application and left their data in the clear.  That is not the way PINs are usually handled and they've corrected  the situation.

We said back in December that 2009 will be the "Year of the Hack."  We also  said a key buzzword for 2009 will be end to end encryption.  Until yesterday's confirmation, there had only been "rumors" of a third payment processor hack.
Information Security Resources first ran a story about it on February 14tha and the PIN Payments Blog shared their story on the 15th. See "Another Payment Processor Hacked - February 15th - PIN Payments Blog.)

Well according to yesterday's SC Magazine, Visa has confirmed the rumors as fact.    3 in 3.  Until there's across the board E2EE encryption, which HomeATM has done since January 2007...yes two full years ago expect to see these breaches crop up.

So who's going to be hit the hardest?  It looks like e-commerce merchants, because the data stolen, (Personal Account Numbers and Expiration Dates), cannot be used to clone cards but can be used for Card Not Present transactions.  The biggest risk from these kind of breaches are chargebacks.  I would humbly remind everyone that PIN Debit virtually eliminates chargebacks. 

Here's SC magazine's story:

Another payment processor has fallen victim to hackers, Visa confirmed on Monday.

Visa and MasterCard are notifying banks about accounts impacted by a "major compromise," unrelated to the massive Heartland Payment Systems incident announced last month, according to a number of credit unions and banking associations.

The hackers apparently breached the processor in the same way they infiltrated Heartland -- by placing malicious software on the network, according to an alert from the Pennsylvania Credit Union Association.

Visa hosted a conference call on Feb. 12 to notify member banks about the breach, which affected transactions made from February to August 2008, the association said. The incident involves account numbers and expiration dates, but no track data was compromised;  therefore the attackers would be unable to make counterfeit cards.

The size of the breach appears significant
but fewer cards were affected than in the Heartland case, the Community Bankers Association of Illinois said in its own announcement. (Editor's Note:  Well, I would hope  so...) That breach potentially exposed as many as 100 million accounts.

The victim in this case appears to be a provider that processes online transactions, said David Shettler, vice president and CTO of Open Security Foundation, a nonprofit that researches data breaches.  Editor's Note:  See ProPay Denies Breach - January 30th - PIN Payments Blog.

He told SCMagazineUS.com on Monday that the group has been receiving tips about the breach since Feb. 12, but few details have been confirmed.

"What concerns me is that Visa and MasterCard, they clearly know who it is," Shettler said. "That just won't say anything because the processor hasn't come clean. The of sort feel it gives people is that Visa and MasterCard are covering for some unnamed organization."

Visa and MasterCard began notifying card issuers about affected accounts on Feb. 9 and 13, respectively. It is unclear whether this processor was compliant with payment industry guidelines, the association said. Heartland was deemed Payment Card Industry Data Security Standard-certified (PCI DSS) when it announced its breach.

This marks the third data-loss incident to impact payment processors in the past three months. In December, RBS WorldPay disclosed a breach that affected some 1.5 million card users. Shettler said cybercriminals are zoning in on these entities because they deal with the most amount of information.

"You can crack into merchants, but that's a limited scope," he said. "If I were the payment card industry, namely Visa and MasterCard, I'd be concerned."  Visa said it was working with business and financial institutions to improve security measures.  (Editor's Note:  We'll that's interesting.  For the record, we'd be happy to work with Visa or MasterCard..

"It's essential that every business that handles payment card information adhere to the highest data protection standards to protect the security and privacy of their customers' financial information," Visa said in a statement. Well that certainly sounds like a ringing endorsement for a web-based PIN debit application to me!)

A representative from MasterCard could not be reached for comment.





Reblog this post [with Zemanta]

Disqus for ePayment News