Tuesday, February 3, 2009

Data Breaches Cost $202 Per Compromise - Study

Ponemon Study Shows Data Breach Costs Continue to Rise
Fourth Annual Study Shows Significant Increase in Cost of Lost Business Americans Continue to Stay Attentive to the Loss or Theft of Personal Information

Menlo Park, CA and Traverse City – Press Release

PGP Corporation, a global leader in enterprise data protection, and the Ponemon Institute, a privacy and information management research firm, today announced results of the fourth annual U.S. Cost of a Data Breach Study. According to the study which examined 43 organizations across 17 different industry sectors, data breach incidents cost U.S. companies $202 per compromised customer record in 2008, compared to $197 in 2007.

Editor's Note: That being the case, and assuming that the Heartland Breach compromised 100 million cardholders, I am shocked in amazement that their stock is hovering around the 8 or 9 dollars.

Within that number, the largest cost increase in 2008 concerns lost business created by abnormal churn, meaning turnover of customers. Since the study’s inception in 2005, this cost component has grown by more than $64 on a per victim basis, nearly a 40% increase.

The annual U.S. Cost of Data Breach Study tracks a wide range of cost factors, including expensive outlays for detection, escalation, notification and response along with legal, investigative and administrative expenses, customer defections, opportunity loss, reputation management, and costs associated with customer support such as information hotlines and credit monitoring subscriptions. Other key findings from the study include the following:

  • Average total per-incident costs in 2008 were $6.65 million, compared to an average per-incident cost of $6.3 million in 2007.
  • Healthcare and financial services companies experienced the highest churn rate – 6.5 percent and 5.5 percent respectively, on a total average of 3.6 percent, which reflect the sensitivity of the data collected and the customer expectation that information will be protected.
  • Third-party organizations accounted for more than 44 percent of all cases in the 2008 study and are also the most costly form of data breaches due to additional investigation and consulting fees.
  • More than 84 percent of 2008 cases involved organizations that had had more than one data breach in 2008 - meaning that companies are becoming more experienced in managing breaches over time.
  • More than 88% of all cases in this year’s study involved insider negligence.
  • More than half of respondents believe that training and awareness programs assist in preventing future breaches and 44 percent have expanded their use of encryption.
  • The most significant cost decrease was seen in activities relating to post-breach response, which indicates that organizations are becoming more cost effective in managing data breaches.

"After four years of conducting this study, one thing remains constant, U.S. businesses continue to pay dearly for having a data breach,” said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute. "As costs only continue to rise, companies must remain on guard or face losing valuable customers in this unpredictable economy."

The study, sponsored by PGP Corporation and independently conducted by the Ponemon Institute, examines the financial consequences of data breaches involving consumers’ personally identifiable information. The study uses objective methods for quantifying specific activities that result in direct, indirect and opportunity costs from the loss or theft of personal information, thus requiring notification to breach victims as required by law or policy.

“In this current economic climate, U.S. businesses can’t afford to give their customers any reason to go elsewhere," said Phillip Dunkelberger, president and CEO of PGP Corporation. “This study continues to show that the results of a data breach can seriously wound a company’s bottom line and reputation. This begs the question, when are organizations going to get proactive about protecting their critical data.”

The U.S. Cost of a Data Breach Study was derived from a detailed analysis of 43 data breach cases with a range of 4,200 to 113,000 records that were affected. The study found that there is a positive correlation between the number of records lost and the cost of an incident. Companies analyzed were from 17 different industries, including financial, retail, healthcare, services, education, technology, manufacturing, transportation, consumer, hotels and leisure, entertainment, marketing, pharmaceutical, communications, research, energy and defense. Copies of the study are available via this weblink: www.encryptionreports.com

About the Ponemon Institute
The Ponemon Institute© is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors and verifies the privacy and data protection practices of organizations in a variety of industries.

About PGP Corporation
PGP Corporation is a global leader in email and data encryption software for enterprise data protection. Based on a unified key management and policy infrastructure, the PGP® Encryption Platform offers the broadest set of integrated applications for enterprise data security. PGP® platform-enabled applications allow organizations to meet current needs and expand as security requirements evolve for email, laptops, desktops, instant messaging, smartphones, network storage, file transfers, automated processes, and backups.

PGP® solutions are used by more than 80,000 enterprises, businesses, and governments worldwide, including 95 percent of the Fortune® 100, 75 percent of the Fortune® Global 100, 87 percent of the German DAX Index, and 51 percent of the U.K. FTSE 100 Index. As a result, PGP Corporation has earned a global reputation for innovative, standards-based, and trusted solutions. PGP solutions help protect confidential information, secure customer data, achieve regulatory and audit compliance, and safeguard companies’ brands and reputations. Contact PGP Corporation at www.pgp.com

Media & Analyst Contacts for PGP Corporation:
North America:
Christina Grenier
PGP Corporation
+1 650 543 3697
cgrenier@pgp.com

Tom Rice
Merritt Group
+1 703 856 2218
rice@merrittgrp.com

Media Contact for Ponemon Institute:
Mike Spinney
Ponemon Institute
+ 978 597 0342
mspinney@ponemon.org

$143K in Card Fraud, Gets 2 Months Jail

Well this certainly sends a wonderful message to anyone out there (with questionable character, I might add) who may have lost their job during this tough economy.  Had he walked inside the same county pathologist house and stolen $143, he'd have gotten years in prison.  But he walks into his house of cards, steals $143,000, and he gets 2 months?  Something not sound right about that? 

San Mateo man gets jail time in $120,000 credit fraud case - Inside Bay Area

REDWOOD CITY — A San Mateo man accused of stealing nearly $120,000 from credit card companies by opening multiple bogus credit card accounts in the name of a county pathologist was sentenced Monday to two months in jail.

Rel Kempf, 63, pleaded no contest in December to four felony charges of identity theft, grand theft and forgery. He had initially been charged with 10 felony counts of grand theft and three counts of forgery.

Kempf opened five credit card accounts in the pathologist's name over an eight-year period, according to prosecutors. He set up the fraudulent accounts while working at a business that was run by the pathologist's wife and managed to run up the charges to nearly $120,000 by paying the minimum amount of the cards' balances each month, prosecutors said.

Kempf used the stolen funds to pay for vacation trips, airplane flights and other personal affairs, prosecutors said. Meanwhile, Kempf pulled the identical identity theft scam on his roommate to steal $23,000, according to prosecutors.

Monday, February 2, 2009

Want to See Something Really Scary?

In a very scary article written by BYRON ACOHIDO and JON SWARTZ in USA Today last week, readers were provided the opportunity to gain some insight into just how unsafe it is to enter your debit or credit card numbers online.

These bullet points should be enough to (rightfully) scare the living bejeezeeze outta you and steer you away from the idea of ever typing in your credit or debit card numbers online again.


Remember: "Don't Type, Swipe"
You're 92 time more likely to be the victim of fraud if you type rather than utilize hardware, such as our personal card swiping device. (see Software Breach 92 Times More Likely Than Hardware Breach)

The good news is that there is a way to "mask" your data and "safely" make purchases online. You have to swipe your own card data before the bad guys do.  The day AFTER this story ran in USA Today, a game changing event occurred. On January 29th, I wrote that HomeATM was pleased to announce that they met PCI 2.0 requirements. When you combine that achievement along with the fact that HomeATM provides End-To-End Encryption (E2EE) protocols, you'll see that there truly is only one way to securely purchase goods online. And that's with HomeATM's online (PIN) debit platform.

Consider the following highlights, er lowlights...from the USA Today article...


  • The number of malicious programs circulating on the Internet tripled to more than 31,000 a day in mid-September...
  • Cybergangs now routinely activate hundreds of accounts by the minute, dedicating them to criminal pursuits.
  • The offense tends to outpace the defense," the FBI said, "The cyberthieves are extremely creative
"This Justin"


They tell the story of Justin Terrazas, 27, a beverage merchandiser from Seattle. Now pay close attention here, so you know what NOT to do. Justin clicked on a Web link that infected his MacBook Pro laptop with a data-stealing program. Not realizing the laptop was compromised, Terrazas later typed his Bank of America debit card number and PIN to pay his Verizon cell phone bill online. The data-stealer swiftly siphoned his information

(Editor's Note: As we've been stating on this blog for almost a year now, NEVER TYPE your Personal Account Number, let alone your PIN while you are online.)


A few days later, someone used Terrazas' debit card account to make a $501.41 online purchase from Modabrand.com, a designer clothing store. The merchandise was shipped to London, leaving Terrazas to unravel a big mess. "This is definitely something you don't need in your life," he said.
  • The boom in cyberthreats that occurred during the last three months of 2008 could accelerate, especially if the economy continues to falter, security specialists say.

  • Organized cybercrime groups have become increasingly efficient at assembling massive networks of infected computers, called botnets, and deploying them to amass large caches of stolen data

  • "There is a well-funded, well-educated horde continually probing for cracks and finding their way in" to consumers' financial information, said Roger Thornton, chief technology officer of security firm Fortify Software.

  • "They are breaching ... the highest levels of the global finance infrastructure and a majority of our home computers."

  • Some cybercriminals have begun to spread malicious programs by corrupting online banner ads. Security firm Finjan reports that new tools being sold on criminal forums can be used to infect online ads that use Adobe's popular Flash player.

  • Last fall, virulent programs called Trojans began to circulate more widely in e-mail and instant-message spam, got embedded in tens of thousands popular Web pages and spread in a widening barrage of online ads. Click on the wrong thing, and you would download an invisible Trojan crafted to steal sensitive data and allow the attacker to control your computer.

  • Unemployed IT personnel potentially can find easy income by purchasingand using crimeware," says Finjan CTO Yuval Ben-Itzhak. "We expect a rising number of people will try.

  • "In the next year or two, these challenges will increase in both breadth and depth of threats," says Larry Ponemon, chairman of Ponemon Institute.
You may remember the "CheckFree is Not HackFree" post, whereby I described how hackers redirected anyone going to their site to a dummy site in the Ukraine? According to the USA Today story, that's just the beginnings of what to expect in the future.
  • "The moral of this attack is that it's so easy to take over your website," Klein says. "I just need to get a hold of your user name and password once. And we all know how easy it is to get your credentials."
Do you really know how easy it is? If you truly did understand the scope of the problem I guarantee that you would never again type your debit/credit card number online. Instead, you would happily acquire HomeATM's PCI 2.X personal card swiping device so you could be protected by both dual-authentication (what you have/your card and what you know/your PIN) and our End-To-End Encryption. None of the threats listed above would have an effect on you, provided you completed your transaction by "swiping your own card" in our personal card reader with built-in PCI 2.0 certiified PIN pad.

Click here
to read the article in it's entirety, (but I think you get the jist) otherwise, click one or more of the 7 links below:
Reblog this post [with Zemanta]

Chip and PIN (+ Magstripe) = Fraud

Back in the middle of September, (see below) I blogged about a rash of PIN numbers that were stolen by Russian and Ukrainian skimmers via the rigging of ATM machines in Dubai. As a result, it caused Lloyds TBS to announce a switch-over to Chip and PIN last December. (also linked below)

Now word comes that the National Bank of Abu Dhabi has officially announced that all banks will be required to introduce Chip and PIN. You will find the link to the story, an excerpt, and some of my comments below:

Chip and PIN system to be introduced - The National Newspaper

In a move to thwart widespread credit card fraud, banks will start introducing a “chip-and-pin” system to replace the traditional magnetic security strip.

Editor's Note: Yes, but if the magnetic stripe is still on the back of the card it can be easily skimmed and cloned. Therefore the "increased security" is only applicable in "card present" situations. Otherwise the data contained on the magstripe can be lifted, and cloned for use overseas and online.

In my opinion, that is why I think it is a mistake for banks to be pushing "signature debit" over "PIN Debit" here in the states. Sure, they might be making a killing on overdraft fees today, but what's getting lost in translation is that they are leaving everyone else in the world open to fraud.

Back to the story:

"The introduction of such technology has proved to be extremely successful in other parts of the world in reducing card fraud, particularly in Europe,” the Central Bank said.

Editor's Note: That may or may not be true as the "flip-side" of the story is that overseas fraud was 14 times higher and last week, it was reported that more than 1 in 4 Brits have been a victim of credit or debit card fraud. Fraudsters, like water, seem to find the path of least resistance, which is another reason to be surprised at the banks pushing of the "least resistant" platform, known as signature debit.

They say that the argument against switching to a Chip and PIN system in the U.S. is the cost. But I say there's a more cost-effective approach. We don't need to spend the $15 plus billion to make the switchover when we could do it for nothing by pushing PIN based transactions over signature debit. At the same time we'd vastly increase the security of our transactions, and drastically reduce the instances of card cloning, especially in "card not present" situations by requiring the entry of a PIN, which is the preferred payment mechanism by both consumers and merchants anyway.

"While the cost of making the switch to Chip and PIN in America would be exorbitant, we could simply require the use of PIN's here in the States which would go a long way to combating fraud and cloned cards"
But I guess, in the long run (and I'm being extremely facetious here) it makes more sense for the banks to push "signature debit" in order to make their $35 overdraft profit on a "$4 Big Mac and Coke" purchase than to diligently prepare for the storm that is approaching. Banks have known for years that PIN Debit is more secure than signature debit. So I have to agree with Avivah Litan when she says:

"Signature-based transactions are definitely less secure, so it's really outrageous that banks are steering customers to use signatures rather than PINs simply because it generates more fee income," says Avivah Litan. One major retailer confided to her that fraud on signature-based debit purchases at his company's stores is 15 times higher than for transactions authorized by a PIN.


Signature is 15 times higher than PIN Debit? No wonder banks are pushing signature debit. It makes for complete non-sense. Common sense dictates the the push for PIN Debit , both in retail and on the web. Regarding the web, in it's current "card not present" state, there's not only more fraud, but cloned cards can be used almost at will. So you'd think even the banks would "get it." Especially based on the fact that they already seem to be PIN-heads. I'll try again:

"A PIN based transaction would be both "dually authenticated" and, with HomeATM, provide the added security of End-To-End Encryption. (E2EE)" Question: If PIN Debit fraud is 15 times LOWER in retail (a card present space) what are the numbers in a "card not present" environment, such as the web? I can only speculate. The fact that e-commerce transactions are all software based, (and fraud is 92 times more likely to be associated with software vs. hardware) provides me with evidence that the time for swiping your card and entering your PIN in a PCI 2.0 tamper proof PIN Pad , (thus making it "card present") has arrived.


But, seemingly, for now anyway, the bank's are focused on pushing/steering American consumers towards a fraud-centric payment mechanism that is 15+ times more likely to induce fraud, depending on the environment. Without doing research, I'm willing to bet that while the Interchange Fees contribute, it's the overdraft fees that are the main ingredient behind their recipe of pushing signature debit. I thought the Fall of Wall Street was supposed to teach us some truths about greed. Talk about "lie-ability."


Anyway, getting back to the story: Chip-and-pin cards rely on a personal number, usually four digits, rather than a signature, and are thought to be harder to defraud. All banks will be required to introduce the new technology, according to a statement from the Central Bank yesterday, although no timetable was given.“This is in line with global industry trends intended to reduce the risk of debit and credit card fraud.

Chip-and-pin technology has been used widely in Europe for many years, and was introduced in Britain in 2004. There is still some debate about its effectiveness, although according to a British government website, counterfeit and fraud were reduced by nearly £60 million the year after its introduction. Last week, a senior Dubai police officer told The National that its introduction could prevent increasingly sophisticated credit card fraud... (click here to continue reading)

Related Stories:

Russian Hack Creates "Rush On" Changing PIN's in Dubai

Sep 15, 2008 -Dubai — Some banks in the UAE have slashed the daily cash withdrawal limit of ATM users by almost half after hackers, who police said were from Russia and Ukraine, used counterfeit bank and credit cards to steal funds from customer ..

Chip and PIN Coming to Dubai
Dec 22, 2008 -Chip and PIN Coming to Dubai - Decision to switch based on recent hack and rise in card related fraud. Many banks across the UAE experienced a concerning rise in the
instances of card related fraud in the latter part of ...



Reblog this post [with Zemanta]

SmartCard Marketing Posts 1,700% Gain


SmartCard Marketing Systems Inc. Posts 1,700% Gain in Payment Processing Volume in December 2008 Compared to Same Period Last Year

SmartCard Marketing Systems Inc.(PINKSHEETS:SMKG) announced today another record high month in their Prepaid Card loading, PIN Debit (powered by HomeATM) and Bill Payment processing volume for December 2008.

The company saw an increase of 1,700% in Payment processing for December 2008 as compared to same period last year. This volume exceeds the previous record high by 211%, which was posted the month before in November of 2008. This growth trend started mid-2008 when SMKG completed development of its full complement of alternative financial services. The growth is anticipated to continue through 2009 and 2010 as the company grows its transaction volume and active customer base.

(SMKG:PINKSHEETS) President Bruce Baillio said, "Our bill pay, online PIN debit (powered by HomeATM) and card loading volumes are growing exponentially as we get caught up on product deliveries and customer installations. We are in the beginning stages of a major growth curve in both transactions and dollar volumes processed. Not only is the company catching up on backlogged orders, but we are signing new corporate customers every month. In spite of weakness in the overall economy, there is no sign of a slowdown in our business. "

gosmartcard.com


Gemalto, mChek Partner in South Asia


Gemalto, the world leader in digital security, today announced its partnership with India-based technology partner mChek, a leading provider of mobile security, banking and payment applications, to bolster the range and choice of secured mobile banking solutions available on Gemalto SIM cards to markets in South Asia.

Since September 2008, Gemalto and mChek have successfully deployed a broad range of mobile banking services with telecom operators in India and Sri Lanka on millions of SIM cards. This includes a mobile top-up service where its customers can recharge anywhere, anytime for themselves or others.

Tan Teck Lee, president of Gemalto Asia said, "mChek has demonstrated an exceptional platform that is flexible and scalable for a broad range of mobile banking and payment applications. By leveraging Gemalto's worldwide partnership program, we can partner with mChek to better serve our customers be they telecom operators or subscribers. Together we aim to bring new levels of security and convenience beyond India and Sri Lanka into markets such as Bangladesh, Indonesia and the Philippines."

The Gemalto Partner Network consists of leading companies that develop products that are complementary to Gemalto products and solutions. Gemalto partners such as mChek have the benefit of exchanging information and getting access to technology and business support as the company looks at expanding its secured mobile banking solutions. This move reaffirms Gemalto's commitment to the region and to bringing convenient, easy to use, secure-mobile solutions to subscribers.

Facilitating secured transactions on the mobile phone

The rapid adoption of mobile phones around the world, notably in emerging countries, provides an opportunity for the telecom and banking industries to leverage the uniqueness of the SIM card (i.e. a network-enabled personal security device) to provide a range of banking services. While some mobile operators have implemented Stored-Value Account (SVA) wallets, in most countries, banking regulations do not allow non-banks to accept deposits or limit the scope and value of operator managed SVA wallets.

The mChek platform addresses these two issues and provides a solution for telecom operators through Gemalto SIM cards. In a unified environment, mChek enables a broad range of services, including mobile banking, two-factor authentication, secure message delivery, cross-border and domestic money transfer and mobile payments using SVA wallets, direct debit and credit/debit card support.
About Gemalto

Gemalto (Euronext NL 0000400653 GTO) is the world leader in digital security with 2008 annual revenues of €1.68 billion, and 10,000 employees operating out of 75 offices, research and service centers in 40 countries. Gemalto is at the heart of our evolving digital society. The freedom to communicate, travel, shop, bank, entertain, and work—anytime, anywhere—has become an integral part of what people want and expect, in ways that are convenient, enjoyable and secure.  Gemalto delivers on the growing demands of billions of people worldwide for mobile connectivity, identity and data protection, credit card safety, health and transportation services, e-government and national security. We do this by supplying to governments, wireless operators, banks and enterprises a wide range of secure personal devices, such as subscriber identification modules (SIM) in mobile phones, smart banking cards, electronic passports, and USB tokens for online identity protection. To complete the solution we also provide software, systems and services to help our customers achieve their goals.

As the use of Gemalto's software and secure devices increases with the number of people interacting in the digital and wireless world, the company is poised to thrive over the coming years.

For more information please visit www.gemalto.com.

About mChek


mChek (www.mChek.com) is a leading provider of mobile security and payments solutions. Based in Bangalore, India, mChek's solutions are deployed on a large-scale at Bharti Airtel in India and Dialog Telekom in Sri Lanka.Bharti Airtel recently announced 1 million users on the mChek platform. mChek is approved by Visa International and is deployed by leading banks including Citibank, State Bank of India, ICICI Bank, HDFC bank, Corporation bank, NDB Bank and Seylan Bank.

Source:  Montner & Associates Tech PR Agency

Reblog this post [with Zemanta]

Bill Me Later and I "Might Pay"


Here's a surprise.  Bill Me Later,  an online payment processor purchased by eBay saw credit losses reach their highest level,  8.75% during the fourth quarter of 2008. The credit loss for the period was the highest rate recorded by the newly acquired company.  Imagine that.

Some analysts had doubted whether eBay would benefit from the acquisition. 

However, Bob Swan, chief financial officer at San Jose, eBay, stated that the rate was in line with expectations and “much less than at other credit issuers.”

Editor's Note:  Say again?  They  expected credit losses to rise, thus they expected it to lose money?  I guess that was the underlying reason they bought them for nearly $1 billion.
  As I said in a post back when they were acquired, the only winner here is the  Bill Me Later shareholders who were happy to be paid immediately.

Personally, I expect the 8.75% rate to surpass 10% for Q1 2009 for Bill Me Later, which "might" cause them to re-brand as "MightPay."   I wonder if that's in line with what Bob Swan's expectations are.  It makes you wonder how much they would have paid if they "expected" it to "save the day." 



Reblog this post [with Zemanta]

Saturday, January 31, 2009

ProPay Denies Breach...

The FBI continues to investigate an international fraud scheme that has affected hundreds of small business accounts...
ACH, Banking Account Fraud Scheme

ProPay, Inc. has recently become aware of what appears to be a very large and widespread international fraud scheme involving unauthorized electronic checks (ACH). The scheme has affected millions of people including, unfortunately, a small number of individuals who may be or have been ProPay account holders. To be clear, after internal and external analysis and investigation, ProPay is extremely confident that the stolen bank information came from other sources and not from ProPay.

ProPay has an ongoing effort to monitor our systems and we remain confident in our system security. ProPay's systems fully encrypt client sensitive information in storage as well as in transit. In addition, sensitive client information is masked when it is viewed internally or externally. ProPay is committed to protecting sensitive information and we will continue to adhere to industry best practice security standards. ProPay meets or exceeds the security requirements and data protection as defined by the major card brands (PCI DSS)—Visa, MasterCard, etc.

The fraud scheme mentioned above involves an electronic draft against a checking account ranging in amount from $24.95 – $39.99. The charge appears on the affected individual's checking account statement under one of a variety of names which may include MBilling, MB Moon Park, MB Hot Planet, and PHE Subscription. The business supporting these names represents itself to victims as a third-party billing service, generally billing on behalf of a purported adult website.

With regard to this particular ACH scheme we know the following:

1. This is an international scheme and millions of people (the vast majority of whom have no affiliation to ProPay) have been affected.
2. We know that numerous payment providers, processors, banks, mortgage companies and others have felt the effects of this scheme and have been named in various reports, blogs, etc.

We encourage the following actions to protect your sensitive information from fraudulent activity.

1. Frequently check your bank accounts and credit card statements (even if you don't balance your account) and immediately report suspicious activity.
2. Keep your computer secure by using up-to-date firewall and virus protection software and by restricting access appropriately.
3. Sign up for automatic updates for any Windows Operating System (OS). If you have an OS earlier than XP, we strongly recommend that you upgrade to at least XP and install all Service Packs.
4. Reject any email that asks you to follow a link to a website and input sensitive or personal information.
5. Only do business with secure websites – look for the lock icon in the bottom-right of your internet browser or look for the prefix "https://..." where the "s" indicates a secure site.
6. Strengthen your password – include numbers, symbols and upper and lower case letters. Using a unique password for each service also helps protect your accounts.
7. For more information please see www.onguardonline.gov.

ProPay has been in contact with law enforcement and will continue to monitor the developments surrounding this particular fraud scheme and will gladly assist, to the extent possible, any ProPay account holders that may have been affected. If you have questions please contact ProPay at (866) 964-0853.

Reblog this post [with Zemanta]

Dismissal of AmEx Lawsuit Reversed

2nd Circuit Reverses Dismissal of American Express Class Action Lawsuit - MSNBC Wire Services - msnbc.com
ST. PAUL, Minn., Jan. 30, 2009 (GLOBE NEWSWIRE) -- The United States Second Circuit Court of Appeals today reversed the dismissal of a massive antitrust class action brought by merchants against the American Express Company ("Am Ex"). The case alleges that American Express in 1999 began a massive effort to take a share of the standard commodity credit card business away from Visa and MasterCard. However, Am Ex wished to partner with banks in issuing these credit cards. The merchants alleged that Am Ex understood that a high merchant fee would be attractive to the banks; therefore Am Ex illegally forced merchants to pay excessive rates equal to Am Ex's more attractive business and personal charge cards by tying the acceptance of the credit and charge cards together. As a condition of accepting Am Ex's credit and charge cards, Am Ex required merchants to sign away their ability to pursue claims as a class (known as a "class action waiver").

The U.S. District Court in the Southern District of New York granted Am Ex's motion to dismiss the case and send it to arbitration. The small merchants appealed the decision to the Second Circuit Court of Appeals, which found that "the class action waiver . . . cannot be enforced in this case because to do so would grant Amex de facto immunity from antitrust liability by removing the plaintiffs' only reasonably feasible means of recovery."

The policy of putting anti-class action rules in consumer and merchant agreements has been growing enormously in recent years. This case was the first case decided by a U.S. Appellate Court in which it was held that the high costs of the case itself voids such rules because the case could only proceed if all the plaintiffs were allowed to share the costs in a class action. The decision will no doubt be used by plaintiffs in dozens of other cases where defendants have attempted to ban class actions by inserting such a clause in a standard agreement.
Story continues below ↓advertisement | your ad here

The plaintiffs in the case were represented by Friedman Law Group of Manhattan, NY, Reinhardt Wendorf and Blanchfield of St. Paul, MN and Patton Boggs of Washington, DC.

CONTACT: Friedman Law Group
Gary Friedman
212 680-5150 or 917 568-5024

Reinhardt Wendorf and Blanchfield
Mark Reinhardt
843 883-9333

Source: GlobeNewswire, Inc. 2009

Reblog this post [with Zemanta]

Friday, January 30, 2009

Gemalto Chippin' In with Venezuelan Bank Card Leaders

Gemalto teams with Venezuelan bank card market leaders to accelerate EMV migration

Digital security provider Gemalto is teaming up with Corporación Cardtech, Venezuela’s largest supplier of magnetic stripe bank cards, and Newtech Solutions, a consulting and technical support organization that specializes in EMV to help banks in Venezuela move to the new, smart credit card that will better protect their customers from fraud and identity theft.  Under the new agreement, banks in Venezuela working with the two companies will have access to expertise, consulting services, smart cards and technology from Gemalto. The partners estimate that eight million cards will be issued in the first year, starting in June 2009. Close to 16 million debit and credit cards are currently in use in Venezuela.

"Venezuelan banks are faced with constantly increasing card fraud, mostly due to illegal copying of magnetic stripe information to create “cloned” credit cards. The problem, that affects all of Latin America, has led to a liability shift which penalizes card issuers and merchants that do not issue or accept EMV cards. This liability change for non-EMV cards becomes effective in Venezuela starting July 2009."

EMV cards, also known as Chip and PIN, include a microprocessor and software with security features that work together with the payment transaction authorization network to prevent card fraud and identity theft. Unlike with magnetic stripe only cards, smart card based transactions cannot be easily cloned, which is a primary source of fraud throughout Latin America.

Editor's Note:  While it's true that they can't be cloned and easily used" at a retail location, they  certainly can  be  "easily" cloned and used online.  This is because the magstripe is still present on the back of the smart cards and that is what is "lifted" when cloning a card.

That, in large part, is why UK Fraud is 14 times higher overseas, (see related stories below) and why 1 in 4 Brits have experienced credit or debit card fraud.  (and why Gemalto wants EMV in the US.)  Online Transactions (web based) are currently (and HATM can change that) Card Not Present transactions.

So in order to
protect both online shoppers and online retailers, online (PIN) debit should be utilized.  HomeATM is the only provider of such a solution  which has been deemed both PCI 2.0 compliant, and offers "End to End Encryption" on all of it's PIN Based Transactions. 





In addition, HATM is EMV ready and it's personal swiping device transforms Card Not Present transactions into Card Present transactions, adding a layer of security with two factor authentication. (what you have and what you know, the card and the PIN respectively)

HATM's end-to-end encryption protects the consumers PIN throughout the whole transaction, as it is NEVER in the clear.     

For more information on how HomeATM's PIN Based Transactions can benefit your organization, visit
www.homeatm.net





Reblog this post [with Zemanta]

Did Heartland CEO Make Insider Trades?

In an article written by Anthony M. Freed, which I read yesterday, and was picked up this morning by Seeking Alpha,  he questions the timing of CEO Robert Carr's stock trades and whether or not they had anything to do with insider knowledge of the breach.  Makes for interesting reading and thought I'd share his conjectures with you. 

Did Heartland CEO Make Insider Trades? : Information Security Resources
By Anthony M. Freed, Information-Security-Resources.com Financial Editor


Heartland Payment Systems (HPY) and Federal investigators have released more details about the technical nature of the massive financial data breach made public last week, but have refused to pinpoint the exact date that Heartland first became aware there may have been a problem with their network security.

The date they settle on may well be the difference between market serendipity and an SEC investigation for insider trading, as an examination of stock sales made by Heartland CEO Robert O. Carr in the second half of 2008 raises some serious questions about just who knew what and when in the latest version of the worst-ever information security breach which has now spawned a class action lawsuit.



Heartland CEO Questionable Stock Trades - Click to Enlarge

Federal investigators and the Secret Service have apparently traced the Heartland data breach to sources outside of North America, with some reports indicating Eastern Europe as being the most likely origin of the unauthorized access.


The principles and methods used by the perpetrator(s) have been uncovered, with evidence that is somewhat contradictory in nature, some of which is suspected of being nothing more than red haring planted by the hacker(s) to throw investigators off their trail.

Excerpts from Evan Schuman:(StoreFront BackTalk)
The sniffer malware that surreptitiously siphoned tons of payment card data from card processor Heartland Payment Systems hid in an unallocated portion of a server’s disk. The malware, which was ultimately detected courtesy of a trail of temp files, was hidden so well that it eluded two different teams of forensic investigators brought in to find it after fraud alerts went off at both Visa (V) and MasterCard (US:MA) according to Heartland CFO Robert Baldwin.

“A significant portion of the sophistication of the attack was in the cloaking,” Baldwin said.

Another consultant-who also wanted his name left out-said the ability to write directly to specific disk sectors is frightening. “Somehow, these guys went directly to the base level of the machine (to an area) that was not part of the file table for the disk,” he said. “Somehow, they got around the operating system. That’s a scary mother in and of itself.”

Other industry brains were less impressed. One nationally recognized and certified information security expert who I corresponded with Wednesday evening regarding the breach indicated that the hackers exploited a system weakness that should have been well known to Heartland, for which protocols issued several years ago.

From my email conversation:
“This was an ‘I told you so’ moment for me. I know exactly which part of the process got hit. It was the un-encrypted Point-to-Point connection which occurs between the Host Security Module (HSM) and the Application Security Module (ASM).

“But that means that they had to have had a hole in their firewall to insert the sniffer into unallocated disk space. “

“Now Heartland is crying poor me, and the making it sound like they are heroes by claiming that they are going to ‘develop’ end to end encryption. They should have been using the ISO Banking Security Standards which were promulgated in 2004/2005. They should be expected to uphold the standard.”

It looks as if the techies have already dissected the mechanics of this modern day cyber-cat-burglar, but ten days later we still have no clear idea of how long the sensitive data was exposed or when Carr and other Heartland executives first had an indication that something was not as it should be.

More from Evan Schuman:
Heartland CFO Robert) Baldwin also added more details to the sketchy timeframes that have been revealed thus far about the attacks, specifying that Heartland was contacted by Visa and MasterCard “in very late October,” possibly October 28.

Given that authorities are conducting an investigation, it is understandable that many details will not be released until after an arrest is made, but given the nature of the details that have and have not been revealed, one has to wonder who all is actually under investigation here.

Usually in an on-going criminal investigation, details are withheld from the press and public for many different reasons, but generally it is the mechanistic details of the crime, and often all the press has to report on is the headline and a timestamp.

Oddly enough it is the those details of the crime that have been trickling out that one would not expect - including the suspects possible location - but yet the generalities are being obscured, like what was stolen when did they steal it?

The answer to the latter of the two questions is of particular issue.

If Heartland personnel, and particularly Bob Carr, had absolutely no indication that something was awry with their processing system security until they were alerted by Visa and MasterCard at the end of October, then there is no problem.

Under this scenario, according to the chart above, Carr just happened to be in the middle of a major sell off of Heartland stock unlike any he has ever undertaken before when he found out “late in the fall” about the existence of problems.

It could simply be the case that Carr just happen to decide to sell 80,000 shares of Heartland stock for roughly $1.6 Million a pop on nine separate occasions about every other week in the four month period leading up to the announcement of the breach. These uncharacteristically large and more than frequent liquidations just happen to have occurred while the company was in the middle of an expensive acquisition and expansion of services push, all of course while the credit markets were in total dysfunction.

If on the other hand, company communiqué and records reveal that Heartland knew of possible anomalies in the processing security at the end of August instead of at the end of October, then we have a whole other scenario to apply the data to.

Under this hypothetical situation, Heartland may have discovered problems prior to end of August and may have known it was something serious simply because no one could figure it out. According to the official company statements, this was a difficult intrusion to detect, one that was missed more than once.

Again from Evan Schuman:
The initial internal conclusion was that “it looked most likely that it would be in a certain segment of our processing platform,” said Baldwin, adding that Heartland does not want to identify what that segment was. The company hired a forensic investigation team to come in and focus solely on that one area, an effort that ultimately proved fruitless. “We found issues in a large segment of our processing environment. The one that looked like the most promising turned out to be clean,” he said.

That second team “was nearing conclusion” and was about to make the same assessment the first team did: clean bill of health. But one of the last things that external, qualified risk assessor did was to try and match various temp files with their associated application. When some orphans-.tmp files that couldn’t be matched to any application or the OS-were turned over to Heartland’s internal IT group, they also couldn’t explain them, saying that it was “not in a format we use,” Baldwin said. More investigation ultimately concluded that those temp files were the byproduct of malware, and more searching eventually located the files in the unallocated portions of server disk drives.

So, continuing with the hypothetical scenario, Heartland would have had inside personnel looking for the problem when they get a call of Visa and MasterCard with the friendly heads-up. Heartland could have just not acknowledged the problem until their business partners forced them to.

The end of August is of interest because this is when Carr began to sell of large blocks of stock about every other week, and this was a significantly different trading pattern than Carr had engaged in previously.

If documentation turns up that indicates Heartland knew of serious problems with their network security prior to August 28th, these huge and rapid sell-offs by Carr may look more than suspect to the SEC.

I can not see the strategic value of withholding an accurate timeline of what exactly the company and Carr knew, and when exactly they knew it. But, if it turns out that everything is kosher here and all is as Heartland has indicated so far - which is very little - then I guess I just don’t understand Carr’s trading strategy over the last half of 2008 and how it related to his goals as a CEO for the growth an performance of his company.

They seem to be at odds, but that is no crime, just ask anyone who shorts their own company from time to time. It just needs to be cleared up. Not to worry though, as this is nothing that a solid and well documented timeline won’t be able to take care of (hint hint).

Meanwhile, Heartland’s stock (HPY) bounced back a little Wednesday, but is still trading at nearly half of it’s value prior to the breach announcement.

The data loss debacle at Heartland highlights the fact that the failure to secure information is a growing national security threat, and will be the next major shareholder derivative, director and officer liability, regulatory, consumer product safety, and class-action issue to impact our economy.

The Author gives permission to link, post, distribute, or reference this article for any lawful purpose, provided attribution is made to the author and Information-Security-Resources.com

Reblog this post [with Zemanta]

Hundreds Hit in Debit Scam

London Free Press - News- Debit scam victims now in the 'hundreds'

Police now confirm there are “hundreds” of victims in a debit card scam in Stratford.

Although police said every financial institution was hit, they’ve confirmed there were more than 350 victims at just two banks. “We’re just starting to extrapolate the data, but it’s obviously in the hundreds,” said Det. Inspector Sam Theocharis.   Asked how much money the culprits have scammed, Theocharis said: “Who knows? We can’t say for sure just yet, but it’s well over $100,000. Right now, I can say there’s no bank that hasn’t been affected.”

Police are working with the Interact Canada, the Canadian Bankers Association, and security branches of the various banks to try and gauge the breadth of the scam, which was discovered last weekend as Stratford residents began seeing money disappear from accounts and debit cards were disabled.

Police have traced some of the “empty envelope” deposits to the Greater Toronto Area, Montreal and Kirkland, Que. The scammers use the debit card information of victims to withdraw cash or make phony deposits before making withdrawls. Theocharis said there's little doubt the scam involved more than one person and more than a single ATM, bank or business. But he said the investigation is still in the early stages of pulling information together from various banks.

Some of the victims are from the surrounding area and frequent Stratford on a regular basis. Police have a variety of investigative tools available to them, such as video surveillance to identify suspects, which is part of the information now being gathered.

“We’re still trying to pinpoint where it happened and then we’ll try to find some common denominators and, hopefully, identify some suspects,” said Theocharis.  Police urge Stratford residents to check their accounts and report suspicious activity. The Canadian Bankers Association (CBA) said earlier this week no one will be out of pocket, because the banks will refund their accounts.

The illegal withdrawals range from $200 to $2,000. In some instances, the culprits tried to withdraw money, but failed because of bank anti-fraud technology. 

The CBA says debit card fraud is a problem, but not as widespread as some may think. Less than one per cent of the 21 million debit cards in circulation in 2007 were hit by fraud, with the total amount lost estimated at $107 million.

For information about how to protect yourself from debit-card fraud, the CBA urges consumers to visit its website at www.cba.ca/fraud.

Reblog this post [with Zemanta]

What the Heartland Breach Means to Banks

 
Heartland Breach: What it Means to Banking Institutions. An Interview with James Van Dyke, Founder/President, Javelin Strategy & Research

Bank Info Security- The Heartland Payment Systems data breach – it’s the first major security incident of 2009. But how big is it really?  What are the key takeaways for banking institutions left explaining this breach to their customers?

In an exclusive interview, James Van Dyke, Founder and President of Javelin Strategy & Research, discusses the implications of the Heartland case, offering insight on:
– Conclusions we can draw from the Heartland breach;
– How banking institutions should communicate with their customers;
– Vulnerabilities we should watch to avoid the next big breach.

Read Full Article (registration required)

Reblog this post [with Zemanta]

Thursday, January 29, 2009

HomeATM Meets PCI 2.0 Requirements

Witham Labs Provides A=OK, Certification Next Step
Above photo courtesy of HomeATM CEO, Ken Mages


I am pleased to report that since October 2008, HomeATM's personal card swiping device has undergone the scrutiny and rigors of PCI 2.0 testing at  Witham Labs, and that as of today, 1/29, our SafeTPIN device has either met or exceeded  the PCI 2.0 requirements "for a PIN Entry Device for online PINs".

Congratulations are in order for our CTO, Ben Lo, who works out of our Hong Kong location.  Congrats to Ben and his team for their integral role in achieving this milestone! 


When you combine this news with the fact that HomeATM already provides "end to end encryption" which is only a topic of discussion for other processors, it escalates HomeATM to the top of the security ranks in the payments industry.

* E2EE = Continuous protection of the confidentiality and integrity of transmitted information by encrypting it at the origin and decrypting at its destination. For example, a virtual private network (VPN) uses end-to-end encryption.  Another example, HomeATM uses end-to-end encryption.

Back to our PCI 2.0 story.  Here's a sampling from the Witham Labs report:  Click on the graphics to enlarge and read.


Executive Summary

HomeATM of 1010 Sherbrooke West, Monreal, Quebec, Canada H3A 2R7, has designed and manufactured a PIN Entry Device named “SafeTPIN”. This PED has magnetic stripe reader.

Witham Laboratories was asked to study the SafeTPIN and comment on its compliance with the PCI requirements for PEDs, v2.0. Under NDA, working units were provided for destructive analysis, along with wiring schematics and layouts, test data, loader application and firmware source code. We tested and evaluated the submitted samples of the device.



This report presents our findings for compliance to the PCI-PED requirements (v2.0), with detailed analysis of each requirement, overview of architecture and methods and cost estimates of possible attacks.

Witham Laboratories was able to verify the compliance of the SafeTPIN with all applicable PCI requirements v2.0 for PIN entry devices.

This report details the results of the evaluation, and is suitable for submission to PCI.

“The PED uses tamper detection and response mechanisms which cause the PED to become immediately inoperable and results in the automatic and immediate erasure of any secret information which may be stored in the PED. These mechanisms protect against physical penetration of the device by means of (but not limited to) drills, lasers, chemical solvents, opening covers, splitting the casing (seams) and using ventilation openings and there is not  any demonstrable way to disable or defeat the mechanisms"







Reblog this post [with Zemanta]

Is Google Checking Out Austraila?

Is Google Going Down...Under?  The Herald Sun says it very well may be, mate. 


How do you want to pay? Google? | Herald Sun
GOOGLE Australia is considering a plan to take on payments giants such as Visa, Mastercard and B-Pay in the booming online payments market. The move comes as the search giant secured a financial services license from local regulators.

The Australian Securities and Investments Commission recently issued Google Australia with an authority to provide deposit and payments services to local merchants and shoppers.  While the licence does not permit Google to provide cash-based payments services to Australian clients, it will enable the group to facilitate digital or online transactions.

Web-based commerce is a hotly contested and lucrative market for payments providers and has spawned a raft of new players including E-Bay subsidiary PayPal.

The ASIC licence potentially opens a fresh revenue stream for Google which will be able to collect processing and transaction fees for bringing shoppers and merchants together via its websites.

Google Australia spokesman Rob Schilken confirmed that the company was working on options to roll out an internet payments platform in Australia.
  "It's a matter of doing the due diligence and the homework so that if we're in a position to launch we can do it," he said.


But no decision has been taken."  Through PayPal, EBay has stolen a march on Google in the Australian online payments arena.

Market research published earlier this month by Neilson Online found that 7.3 million Australians shop over the internet.



Reblog this post [with Zemanta]

Malware = $1 Trillion Problem


Malware Increased  by 400% in '08

DAVOS, Switzerland (Reuters) - Businesses risk losing over $1 trillion from loss or theft of data and other cybercrime, according to a study released on Thursday by security technology firm McAfee Inc.

The California-based company launched the survey after detecting a rapid acceleration of malicious software, or "malware," last year, CEO David DeWalt told Reuters. Malware increased by 400 percent in 2008, he said.

"This was a very insidious type of malware that was designed either to steal your data, steal your identity, steal your money, and in many cases the scale as well as the sophistication was very alarming," DeWalt said in an interview at the meeting of the World Economic Forum in Davos, Switzerland.

Editor's Note: In the wake of the Massive Heart(land) Attack some industry leaders are calling for end-to-end encryption. (E2EE)  HomeATM already incorporates E2EE and is awaiting PCI  2.0 certification for their personal swiping device with PIN Pad.

The survey of 800 companies in 8 countries showed that 80 percent of malware aimed to make a financial gain, in contrast to traditional viruses and worms which just had nuisance value.

In the survey, 42 percent of companies said that laid-off employees were the single biggest threat to their data security.

The increase in the availability and power of removable storage, such as mobile phones, laptops, and USB sticks, has made data loss or theft easier. And global supply chains mean that sensitive data is often stored abroad.

DeWalt said the survey showed that the average company has $12 million of data stored outside its home country -- often in countries with little intellectual property law.

Data lost accidentally or through theft can be expensive to replace or damaging to a company's reputation or brand.

In April last year, discount retailer TJX said it would pay up to $24 million as part of a settlement with MasterCard over a security breach that put credit card data for tens of millions of shoppers at risk.

The British government has been repeatedly embarrassed by losses of data, such as when the tax authority, HM Revenue and Customs, lost data on 25 million people exposing them to the risk of identity theft and fraud.

(Reporting by Jonathan Lynn; editing by Simon Jessop)

Reblog this post [with Zemanta]

Disqus for ePayment News