Wednesday, October 7, 2009

Malware Economy is Thriving

Last week I did a post entitled:  Game Over: Hackers Win! 



Dennis Fisher of Threatpost.com a security blog by Kapersky Labs says it ain't over til it's over! 



He also says the bad guys are doing great and the good guys aren't...(sounds over to me)

   

TORONTO -- The legitimate economy may be in rough shape right now, but the same cannot be said for the underground economy. Malware authors and botmasters are thriving, experts say, with some online criminals charging as much as $3,500 for their attack toolkits.



But don't be intimidated by the high price point. That's a premium product. More basic exploit kits can be had for as little as $100. But even at that price, the attackers are doing just fine, thank you.



"The bad guys are doing really great," said Roy Firestein of Digital Defence, speaking in a session on modern crimeware toolkits at the SecTor 2009 conference here. "How are the good guys doing? Not so good."



Continue Reading 









Reblog this post [with Zemanta]

More On the E-Mail Hijackings



Internet security experts are warning millions of email users not to get caught with their pants down and change their passwords immediately.



Following an apparently effective scam that harvested thousands of Hotmail login identifications and posted them online, Microsoft and other email providers are telling account holders to be safe and to change their login information as soon as possible.



Password information for Hotmail (Microsoft), G-Mail (Google), Yahoo, America OnLine (AOL), Earthlink and Comcast accounts were also posted in the online listing that was taken down shortly after it appeared but was certainly up long enough for those with criminal intent to copy the information.



Microsoft, Google and Yahoo said they are working with customers to recover any hijacked accounts.



Reblog this post [with Zemanta]

Google Doodle Bar Code

What's up with the Google Doodle today? It's the Bar Code Logo because today is the 57th anniversary of the Invention of the Bar Code...








In other news, Google is offering advice on "strong passwords". (The Password is: Oxymoron!) Here's a snippet from Information Week:

Passwords remain the primary means of online authentication, despite their shortcomings. (Editor's Note: Read that again!)


By Thomas Claburn InformationWeek

October 7, 2009 03:14 PM

It's National Cybersecurity Awareness Month and Google would like to remind you to choose strong passwords for your online services. Coincidentally, several thousand users of Windows Live Hotmail, along with some users of Gmail and Yahoo Mail, are in need of new passwords.

SANS Internet Storm Center handler Adrien de Beaupr is advising users of Hotmail, Gmail, and Yahoo Mail to change their passwords following the exposure of several thousand Hotmail credentials on a Web site over the weekend. According to Microsoft, the exposure was likely result of a phishing scam. And reports indicate that some Gmail and Yahoo Mail account information was also revealed.

Anyone who may have entered account information in a phishing site should pick a different password right away.

Continue Reading


Reblog this post [with Zemanta]

Zeus Online Banking Trojan Webinar Infected with...Zeus!



According to a story from Brian Krebs, a company produced a webinar on the online banking password stealing Trojan Zeus and was then targeted by the Zeus keepers:



"On Sept. 1, security industry start-up Silver Tail Systems held an in-depth online seminar for its bank and e-commerce clients that examined the stealth and sophistication of Zeus, a data-stealing Trojan horse program that organized thieves have used in a string of lucrative cyber heists this year.



A week later, Silver Tail learned that Zeus had infiltrated its own network defenses.



Silver Tail founder Laura Mather said she believes her company was targeted by criminals wielding Zeus specifically because of the recent webinar, which spotlighted the myriad ways in which Zeus can defeat online banking security measures. Still, she said the incident shows this family of malware can be a threat to any business - even security companies.



Continue Reading at Brian Krebs Security Fix



The Zeus-themed webinar that Silver Tail believes prompted this attack is long, but well worth a watch for anyone involved in defending networks. The ThreatExpert blog also recently published an excellent (yet far more technical) deep-dive on Zeus."

Reblog this post [with Zemanta]

Operation Phish Fry





According to KTLA: Operation Phish Fry (shouldn't it be Phry?) "netted" a bunch of Egyptian Phishermen. 

"Dozens of people are under arrest in Southern California, Nevada, North Carolina and Egypt in a major crackdown against identity theft.



The FBI has launched "Operation Phish Fry" to bust an identity theft ring that has victimized thousands of people.



Laura Eimiller, an FBI spokeswoman in Los Angeles, says about 100 arrests are expected - many of them in the Los Angeles area. Eimiller says the suspects are accused of running a "phishing" scheme that used computer intrusion and fraud to obtain personal information that allowed them to withdraw money from bank accounts.




"Phishing" scams often involve fake e-mails that direct victims to a bogus Web site where they are asked to update personal information, such as passwords and account numbers.

The LA Times Blog is reporting that 100 have already been arrested and 53 have already been indicted. 

The federal indictment, which is due to be unsealed today, names 53 indicted suspects as well as 47 non-indicted co-conspirators from Egypt, said Laura Eimiller, the FBI spokeswoman.





Reblog this post [with Zemanta]

Aussies Fall Victim To Retail EFT-POS Skim-Scam





Skimmers are usually placed on ATM's but now it looks like they are moving to the point of sale terminals.  Kind of makes a case for purchasing online from a device you can trust, like your very own HomeATM SLIM! 



A GLOBAL crime gang has struck in Perth with a new card skimming fraud phenomenon that fleeces bank accounts from point-of-sale EFTPOS machines.


Fraudsters have stolen hundreds of thousands of dollars from thousands of Perth cardholders in an EFTPOS scam.



Police say they have received "substantial information" regarding machines being used to "skim" credit and debit cards of details - including PIN numbers - throughout the metropolitan area. WA Police today issued a state-wide alert after receiving dozens of complaints reporting missing money after transactions from EFTPOS machines at shops, including fast food outlets, since Monday.



They have revealed few details of the devices or investigation - citing "operational sensitivities" - but say the devices have compromised EFTPOS point-of-sale machines.  Until now, police have only been aware of automatic teller machines skimming scams, whereby criminals obtain bank account and PIN details after fitting secret card-reading devices to ATMs and hidden mobile phone cameras to record bank customers entering their secret PIN number.



Retailers have been asked to contact police if they suspect their EFTPOS machines have been tampered with. People are being advised to check their bank statements to ensure all withdrawals are legitimate and to contact police if they have concerns.



A Perth woman says she has lost $3,500 from her bank account...

Reblog this post [with Zemanta]

Fiserv to Deliver E-bills to Financial Institution Websites for Progress Energy Florida



Fiserv announced today that Progress Energy is extending the use of eBill Distribution to the electric utility's Florida region. The agreement with Progress Energy is an expansion of the existing relationship between Fiserv and the Fortune 500 energy company which serves customers in the Carolinas and Florida. Fiserv already provides eBill Distribution to Progress Energy customers in the Carolinas, as well as walk-in bill payment services in all three states. Now, Progress Energy customers in the Carolinas and Florida can receive their Progress Energy bill at any of the more than 3,000 financial institution websites in the Fiserv network.



Here's their Press Release:



Fiserv to Deliver E-bills to Financial Institution Websites for Progress Energy Florida

- Expansion of e-bill delivery channel allows company to meet more customers online for bill viewing and payment -



Brookfield, Wis., October 7, 2009 -PIN Payments News Blog- Fiserv, Inc. (NASDAQ: FISV), the leading global provider of financial services technology solutions, today announced that Progress Energy  is extending the use of eBill Distribution to the electric utility's Florida region. The agreement with Progress Energy is an expansion of the existing relationship between Fiserv and the Fortune 500 energy company which serves customers in the Carolinas and Florida. Fiserv already provides eBill Distribution to Progress Energy customers in the Carolinas, as well as walk-in bill payment services in all three states. Now, Progress Energy customers in the Carolinas and Florida can receive their Progress Energy bill at any of the more than 3,000 financial institution websites in the Fiserv network. According to financial industry analyst firm Javelin Strategy & Research, banks and credit unions represent the fastest-growing channel for viewing and paying bills online, making eBill Distribution a natural

complement to offering paperless options at Progress-Energy.com.



eBill Distribution from Fiserv enables companies like Progress Energy to offer paperless electronic bills, commonly known as e-bills. E-bills replicate the same information as the traditional paper bill, but are securely delivered to a financial institution or billing company Website instead of a physical mailbox. Customers who receive e-bills can schedule a specific date on which their bill will be paid and take advantage of features such as email reminders.



By eliminating the mailed statement, consumers can take a small, simple step toward the reduction of paper use, thereby preserving the environment. According to a 2009 Fiserv-sponsored study conducted by The Marketing Workshop and Harris Interactive, 58 percent of consumers cite the protection of the environment as a key reason to receive e-bills and turn off the corresponding paper bill.



According to the same study, 41 percent of current online banking users indicated plans to pay more bills online at their financial institution's Web site in the coming months. Progress Energy's commitment to paperless billing can allow the company to capitalize on this trend and provide customers additional billing options. As a testament to this commitment, Progress Energy Carolinas recently collaborated with Fiserv to educate consumers to turn off their paper bills and begin receiving e-bills through their financial institution. This campaign resulted in a 206 percent e-bill adoption rate increase, and encouraged Progress Energy to extend the bank channel e-bill delivery option to its Florida customers.



"Progress Energy is at the forefront of meeting its customers at their point of preference when it comes to viewing and paying bills, and Fiserv is proud to be a partner," said Jardon Bouska, president, Biller Solutions, Fiserv. "Whether it is educating consumers about the benefits of e-bills and serving them through the bank channel or providing access to convenient retail and agent locations for walk-in based payments, we will continue to help Progress Energy leverage billing and payment touch points and ensure positive customer interactions."



Since 2000, Fiserv and Progress Energy together have delivered valuable billing and payment options for Progress Energy customers. In addition to powering Progress Energy's electronic billing and payment channels, Fiserv makes available to all Progress Energy customers the ability to pay bills in-person at more than 16,000 retail agent sites, such as convenience stores, grocery stores, drug stores, and retail shipping and postal stores.



Fiserv offers a robust portfolio for optimizing bill pay touch points to maximize profitability, including electronic and paper bill production and distribution, on-demand and recurring bill payment (via agent, web, IVR and walk-in channels) as well as e-lockbox and remittance processing.



About Fiserv

Fiserv, Inc. (NASDAQ: FISV) is the world leader in information management and e-commerce systems for the financial services industry, driving innovation that transforms banking for financial institutions and their customers. Ranked No. 1 on the FinTech 100 survey of top technology partners to the financial services industry, Fiserv celebrates its 25th year in 2009. More on Fiserv at www.fiserv.com, and examples of award-winning innovation are listed at www.newfiserv.com.



# # #

New Report Out on Bank Overdraft Fees





This report from the folks at Responsible Lending purports that Bank's have basically engaged in abusive practices in order to maximize overdraft fee revenue. 



It also explains why some banks have recently decided to cut back on the amounts they charge for overdraft fees.



Click the graphic on the right to read their harsh conclusion.



Viewer Warning:  If you are a banker, some of the recommendations contained in this report may be disturbing! 



To think that they actually have the tenacity to call it Overdraft Protection is amusing.  



Responsible Lending Report on Bank Overdraft Fees



Reblog this post [with Zemanta]

Online Banking Fraud in the UK Hits a New High









There is a disturbing trend going on.  The hackers steal our username and passwords and banks respond by telling us to "type" more information into a box on their online banking website.  I don't get it.  There's a website in the U.K. designed to help people fight the fight against online banking fraud called: www.BankSafeOnline.org  



Here's what they have to say. 



The three essential steps to protect your computer are:

  • Use anti-virus software and keep it up-to-date on a regular basis.

  • Install and learn how to use a personal firewall.

  • Download the latest security updates (or patches) for your web browser and operating system.

Oh really?  As I mentioned yesterday, a report by Trusteer says that Zeus, an online banking Trojan which steals your online banking credentials,  bypasses up-to-date anti-virus software 77% of the time.  So if you want to feel 23% protected, by all  means listen to their advice.  Firewalls are like locked windows.  Hackers just break the glass to get in.  The latest security updates are nothing more than an admission that browsers are not safe.  Why would you need weekly "security" updates if the browser was secure in the first place. 



There's only one way to authenticate an online banking customer.  Think ATM.  Think dispersal of cash in real time.  Why is that system trusted by banks?  Because the security behind the authentication works.  Why not 100% replicate that process for online banking log-in?  Exactly...why not?



Here's more on the 55% growth in online banking fraud during the first 6 months of the year.  Prediction.  When the report comes out on the growth of online banking for the second 6 months, it will be bigger than the first 6 months. Mark my words...or at least these three words:  Zeus, Clampi, urlZone.





Jeremy Kirk, IDG News Service

Wednesday, October 07, 2009 7:40 AM PDT



Online banking fraud in the U.K. has risen to the highest level in at least three years, according to industry figures released Wednesday.



Online banking fraud increased 55 percent to £39 million (US$62.4 million) in the first six months of the year compared to the same period a year ago, said Financial Fraud Action U.K. (FFA), formerly known as APACS. FFA collects data reported by U.K. financial institutions.



FFA attributed the rise to sophisticated malicious software programs that infect vulnerable consumer computers. FFA also counted 26,000 phishing sites, which are fraudulent Web sites designed to trick people into divulging their log-ins and passwords.



The rise in banking fraud comes as U.K. banks have taken more rigorous measures to combat online fraud. While U.S. banks often only require a log-in and password to get access to online banking, U.K. banks often have several more steps.



Editor's Note:  More steps are futile.  I've got a business associate that says banks understand the security risks, but I disagree and what follows is proof that they just don't get it!  Here's an exercise in futility by NatWest:



For example, NatWest -- owned by the Royal Bank of Scotland Group -- requires customers to "type" (enter) their birth date plus "type" (enter) a unique four digit code.  During the second step, a person is prompted to enter ("type") enter some digits of a separate four-digit PIN (Personal Identification Number), which is not the same as the person's ATM card.  Then, the Web site asks the user to ("type") enter "another password", but only specific parts of it, such as the second, fourth and seventh letter. NatWest asks for a different combination every time. If you fail to log in successfully, the account can't be accessed online.





Nonetheless, most bank security measures are defeatable if a person falls victim to a phishing scam and sends a fraudster their authentication credentials.  Editor's Note:  When consumers type, the information they type is fair-game to the hackers.  It doesn't matter if you instruct the consumer to type the 4th letter of every 5th word in War and Peace or every 7th letter of every 14th word in Genesis.  Typing is the problem. 

Reblog this post [with Zemanta]

SPVA Announces New President



Former Technology Executive to Lead Secure POS Vendor Alliance



New president Steven Hughes provides more than a decade of experience

to rapidly-growing global payment security organization



ATLANTA – October 7, 2009 – The Secure POS Vendor Alliance (SPVA), a non-profit business organization founded by Hypercom (NYSE: HYC), Ingenico S.A. (EURONEXT: ING) and VeriFone (NYSE: PAY) is pleased to announce that it has named Steven Hughes, formerly executive director for the Oracle Applications Users Group (OAUG), as its president. In his new role, Hughes will focus on strategic direction, membership development and act as liaison among the three founding board members. Hughes leads a newly-installed team of SPVA staff who will service SPVA’s growing membership base.



“Steven brings valuable skills and a track record of success in global membership expansion and retention,” said Christophe Dolique, SPVA Chairman and EVP, Global Marketing & Transaction Services at Ingenico. “At this stage of SPVA’s development, I could not think of a better individual to manage our efforts to focus the card payments industry on compliance.”

The SPVA launched in April 2009 to foster widespread compliance of existing security standards to protect cardholder information and defend merchants and acquirers against security breach. Its aim is to simplify compliance efforts, diminish the chaos and confusion often associated with standardization and reduce costs for all stakeholders. Hughes was selected by the SPVA board due to his success in growing the OAUG into one of the largest independent user groups in the world, among other accomplishments.



“I look forward to growing the SPVA into the premiere organization for facilitating a common understanding and acceptance of various security requirements and standards,” said Steven Hughes, SPVA president. “With the strong leadership team already in place, I am confident this objective can be attained.”



SPVA has experienced rapid growth since its launch at the ETA show in Las Vegas with prominent industry leaders joining, including Atos Worldline, Heartland Payment Systems, Moneris Solutions, Radiant Systems, Inc. and Witham Laboratories. Membership is open to all vendors that develop secure POS payment systems or have products or solutions that interact with secure POS payment devices such as retailers, acquirers and banks.



To learn more about the SPVA, visit www.spva.org.



###



About Secure POS Vendor Alliance (www.spva.org) The Secure POS Vendor Alliance (SPVA) is a non-profit organization that works with the multiple stakeholders of the payment value chain. Its aim is to develop an end-to-end security framework and to enhance security elements of payment solutions which protect cardholder information and defend merchants and acquirers against security breaches, while helping reducing fraud and lowering risk for all electronic payment stakeholders.



About Hypercom (www.hypercom.com) Global payment technology leader Hypercom Corporation delivers a full suite of high security, end-to-end electronic payment products and services. The Company's solutions address the high security electronic transaction needs of banks and other financial institutions, processors, large scale retailers, smaller merchants, quick service restaurants, and users in the transportation, petroleum, healthcare, prepaid, unattended and many other markets. Hypercom solutions enable businesses in more than 100 countries to securely expand their revenues and profits. Hypercom is a founding member of the Secure POS Vendor Alliance (SPVA) and is the second largest provider of electronic payment solutions and services in Western Europe and third largest provider globally.



About Ingenico (www.ingenico.com)



Ingenico is the world’s leading provider of payment solutions, with over 15 million terminals deployed in more than 125 countries. Its 2,500 employees worldwide support retailers, banks and service providers to optimize and secure their electronic payments solutions, develop their offer of services and increase their point of sales revenue. Ingenico generated pro-forma revenue of €780M in 2008.



About VeriFone Holdings, Inc. (www.verifone.com)



VeriFone Holdings, Inc. (“VeriFone”), a global leader in secure electronic payment technologies, provides expertise, solutions and services for today with a migration strategy for tomorrow. VeriFone delivers solutions that add value to the point of sale, resulting in improved merchant retention and the generation of new sources of revenue for its partners and customers. VeriFone solutions are specifically designed to meet the needs of vertical markets including financial, retail, petroleum, government and healthcare.

Tuesday, October 6, 2009

Online Banking Fraud Increases by 55% in the U.K.



Last Week was "Online Banking is Weak Week" on the PIN Payments News Blog.



But that doesn't mean it's yesterday's news. Everyday, there is news regarding the perils and weaknesses of the old-fashioned, inept and obviously obsolete practice of "typing" user name and password log-in details into a graphical user interface on an online banking



The following excerpt is from today's Sky News:
website.



Online banking fraud has jumped by more than a half over the past year amid fears that Britain is becoming a soft touch for internet crooks.


Conmen are finding new ways to steal banking passwords



The cost of the crime rose to a record £39m for the first half of this year - a 55% increase on the same period in 2008, according to industry body Financial Fraud Action UK.



Experts blamed the hike on fraudsters using increasingly sophisticated methods to get their hands on customers' cash, rather than weaknesses in the banks' own online systems.



Methods include targeting online bankers through malware scams, where customers' computers are infected with a Trojan virus,
which logs their keystrokes, including passwords and personal data.   There were also more than 26,000 phishing incidents during the same period - a 26% increase on the first six months of last year.




  • Phishing sees victims conned into handing over their banking details often through an official-looking letter or website.

  • Shadow home affairs minister James Brokenshire said: "These figures underline the growing threat from online crime.

    • "Unless more concerted action is taken, consumer confidence in the internet will be damaged with significant implications for business

    • "We need a strong coordinated approach to prevent more people falling victim to computer crime."  Editor's Note:  How about providing a log-in procedure that 100% replicates the same way banks trust consumers to access cash in real time at an ATM? 

    Continue Reading



    Advice about preventing online banking fraud: www.banksafeonline.org.uk

    P.S. Don't bother.  They probably tell you to use updated anti-virus software so that you won't be infected.  But, the new online banking Trojans bypass even up-to-date anti-virus programs 77% of the time.



    "There is an online banking Trojan out there
    that is bypassing up-to-date anti-virus programs as much as 77% of the time, according to security company Trusteer."PDF





    From the report: Page 6, first paragraph:  The effectiveness of an up to
    date anti virus against Zeus is thus not 100%, not 90%, not even 50% -
    it’s just 23%.



    I'm not making this stuff up folks.  It's the Typing and it's the Browser.  They don't mix.  It's got to be done "inside the box."  That said,
      "For advice on eliminating the threats to online banking fraud, stay tuned to the PIN Payments News Blog!"



    Again...I really don't think I'm being too simplistic when I point out the reality of the situation:    As long as online banking customers continue to "type" their log-in details into a box, the only swiping going on will be on the part of the Hackers. So the question begs to be asked.  If your online banking details are going to be swiped anyway, shouldn't online banking customers be the one's doing the swiping? 



    How's that for a "strong" coordinated approach to prevent more people from falling victim to computer crime?






    Reblog this post [with Zemanta]

    Todos Secures Another Bank





    Further E-vidence that Banks are Looking to Secure Online Banking Authentication with Hardware



    GOTHENBURG, SWEDEN -- PIN Payments Blog -- 10/06/09 --



    Hwatai Commercial Bank deploys the Todos eCode system to increase trust and security for customers and gain great flexibility and opportunities for future development.



    GOTHENBURG, SWEDEN AND TAIPEI, TAIWAN-OCTOBER 6, 2009-Hwatai Commercial Bank has selected Todos to supply authentication servers and devices for its online banking customers.



    Hwatai Bank has a history and reputation dating back 66 years and it has 30 branches across Taiwan.



    This decision demonstrates Todos's global reach. The company beat several other leading providers to win this contract and supplies eight of the top 30 Taiwanese banks. Todos is also the only company to offer a Government-certified smart card reader with Chinese character output in Taiwan.



    Hwatai initially plans to deploy the Todos C200. This light-weight smart card reader is easy for bank customers to use and provides extra protection against fraud compared with static passwords or one-time password tokens. It comes with Todos's unique technologies Dynamic Signatures and Secure Domain Separation, increasing both security and user-friendliness to unrivalled levels.



    A key factor in the bank's decision was the flexibility and future-proof design of the Todos eCode system. The Todos Versatile Authentication Server is really very versatile. It allows banks to issue multiple devices to individual customers. For example the same user can have a compact travel device and a more secure smart card reader for the office. Banks can also give different types of users different devices. For example business customers might need more enhanced devices than consumers. Lastly, it makes it easy for the bank to upgrade users to more enhanced devices if required in the future.



    Many of Todos's authentication devices feature user-friendly 'login' and 'pay' buttons with secure domain separation between different uses. This means that Hwatai can deploy the devices to login to eBanking systems today and, in future, offer its customers eCommerce functionality. This is a significant opportunity for the bank since their sister company, PX Mart, is the largest chain of supermarkets in Taiwan.



    "We're very happy to add Hwatai Commercial Bank to our roster of bank customers in Taiwan," says Kelly Lin, Sales Director Asia at Todos AB. "Now that they are deploying the Todos eCode system they can offer people greater trust and security and pave the way for exciting future opportunities."



    ###



    Todos AB helps banks and other businesses create trusted, secure relationships with their customers online. Founded in 1987, Todos designs, develops, delivers and supports security solutions for eBanking and eCommerce strong authentication. We have delivered over 20m products to 100+ financial institutions in more than 30 countries. When trust matters, trust Todos.



    For further information please contact:

    John Ahlberg, Communications Director



    Todos AB
    john.ahlberg@todos.se
    www.todos.se
    +46 31 775 88 00

    CRE Secure Rescues e-Commerce Merchants from PCI Compliance Burdens

    Hosted Payment Page delivers secure shopping cart transactions without sacrificing branding and customer experience

    Atlanta, GA (PRWEB) October 6, 2009 -- As the remaining Payment Card Industry Data Security Standard (PCI DSS) deadlines approach, e-commerce merchants must quickly determine how to bring their checkout process into alignment with the new required standards for protecting sensitive cardholder data. To ease the burden, CRE Secure Payments, LLC has unveiled a Hosted Payment Page technology aimed at reducing the scope and cost of PCI Compliance for e-commerce merchants by moving the storage, processing and transmittal of payment information from the merchant's environment to a PCI-Compliant data center without interrupting checkout flow.



    Hosted Payment Page with Patent-Pending HTML CLONE™ Technology

    CRE Secure's Hosted Payment Page is a PCI compliant service that presents itself in the normal checkout process to provide a smooth and familiar experience to customers for payment collection. Unlike traditional services that redirect customers off-site for payment, CRE Secure's patent-pending HTML CLONE technology calls on the merchant's shopping cart or website CSS to provide an exact replica of the merchant environment to ensure a seamless checkout experience for the user - including access to all links and live navigation of the merchant site.



    "A seamless checkout process was an absolute requirement for us," said Greg McGraw, President and CEO of CRE Secure Payments. "Other outsourced payment processing services, like PayPal's Payment Standard, disrupt the checkout flow and force the merchant to surrender branding control - often resulting in confused customers, increased cart abandonment, and fewer items per ticket".



    The Fast Track to PCI Compliance



    The Hosted Payment Page provides a methodology by which e-commerce merchants can leverage CRE Secure's PCI-Compliant process to manage the storage, transmittal, and processing of cardholder data - thereby removing these elements from the scope of the merchant's PCI compliance requirements - dramatically reducing the time and cost required to achieve compliance.



    The time, energy, and cost required to meet compliance requirements can be overwhelming for the e-commerce merchant. With a Hosted Payment Page, integration can be done via a readily available Hosted Payment Page toolkit from partner IP Commerce and takes as little as one day to implement. "We are thrilled that CRE Secure has chosen our Managed Commerce Services Platform as the cloud-based backbone for the Hosted Payment Page. This is exactly the type of secure commerce innovation we built our platform to enable," says Chip Kahn, CEO of IP Commerce.



    CRE Secure's Hosted Payment Page offers a much needed lifeline to the thousands of e-commerce merchants struggling to achieve PCI Compliance prior to approaching deadlines. "By taking cardholder data out of scope, we can greatly reduce the amount of effort required to achieve PCI Compliance - allowing e-commerce merchants to worry less about managing compliance and more about providing a great customer experience," adds McGraw.



    Pricing and Availability



    CRE Secure works with most open source shopping cart software including OSCommerce, CRE Loaded, ZenCart, Magento, VirtueMart, and Ubercart, and provides direct connectivity to leading payment processors including Chase Paymentech.

    Visit us at the following link to learn more or to begin a Commerce Hosted Payment Page integration.



    About CRE Secure

    CRE Secure is the latest innovative solution from CRE Commerce, a leading open source eCommerce software project since 2001. Today, the company is using its experience as an online merchant and its nearly 200,000 users of its award winning open source shopping cart to launch a new secure payment service, CRE Secure Payments. CRE Commerce's PCI compliant shopping cart software is based on the osCommerce architecture operating under the GPL and includes a "loaded' solution set of powerful features, plug-ins and affiliate partnerships all designed to help online merchants get web stores up and running in secure environments and generating revenue faster. CRE Commerce, and its subsidiary CRE Secure Payments, is a venture backed e-commerce company, based in Atlanta, GA. To learn more or to get started visit CRE Secure or call 1-800-609-2141.



    About Commerce Lab

    Commerce Lab from IP Commerce enabled CRE Secure to build a scalable and secure payment processing product by integrating to the Managed Commerce Services Platform. For more information, visit Commerce Lab

    Based in Denver, Colo., IP Commerce provides the first cloud-computing platform for commerce. The Managed Commerce Services Platform enables payment providers and new industry entrants to become solution providers enabling new work flows and processes on-demand.



    The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

    ###



    Source: Company Press Release

    BofA Pledges to Keep Credit Card Fees in Check Until...



    Bank of America Vows to Maintain Credit-Card Rates Ahead of Law



    By Peter Eichenbaum and Alison Vekshin



    Oct. 6 (Bloomberg) -- Bank of America Corp., the biggest U.S. bank, vowed to keep consumer credit-card fees and interest rates unchanged until federal regulations take effect next year.



    The bank offered the pledge in a letter to House Financial Services Committee Chairman Barney Frank, who called a hearing Oct. 8 on legislation that would move up the effective date for the Credit Card Accountability Responsibility and Disclosure Act. Frank, a Massachusetts Democrat, proposed that provisions, including a requirement that lenders apply payments to higher- rate balances first, take effect Dec. 1 rather than in February.



    Continue Reading at Bloomberg

    Reblog this post [with Zemanta]

    Hess Convenient Stores to Accept PayPass





    Purchase, N.Y., Oct. 6, 2009 -- MasterCard Worldwide announced today that leading independent gasoline-convenience store retailer Hess will accept MasterCard PayPass at more than 870 company-operated Hess and Hess Express locations along the eastern United States. In addition to traditional magnetic-stripe payment cards, Hess will accept MasterCard PayPass at check-out counters at these locations by early 2010 to provide customers with quicker transactions and greater payment convenience.



    "Our customers are always looking for greater speed, security and convenience at Hess locations, and increasingly they prefer electronic forms of payment over cash," said Rick Lawlor, vice president, Retail Sales and Marketing, Hess Corporation. "Accepting MasterCard PayPass means we can meet our customers' needs and continue to enhance the customer experience, which is the Hess Way."



    With MasterCard PayPass, Hess customers simply tap their PayPass-enabled MasterCard card or device on a PayPass-accepting reader at check-out. Cardholders benefit from additional security because the card never leaves the customer's hand. MasterCard PayPass also does not require customers to sign receipts for purchases under $25, further speeding up the transaction. This amount will increase to $50 as of October 16th.



    The use of contactless payment cards continues to see exponential growth. As of second quarter 2009, MasterCard had issued nearly 61 million MasterCard PayPass cards or devices, which can be used at over 153,000 merchant locations globally.



    "Hess branded locations are the perfect environment for MasterCard PayPass because the value of faster transactions at the point of sale translates directly to busy customers who don't want to spend time waiting in line," said Cathleen Conforti, senior vice president, Global PayPass, MasterCard Worldwide. "As more customers turn to electronic payments over cash, by accepting MasterCard PayPass, Hess is taking another step to meet customer needs, and deliver great customer service and throughput at the register."



    Growing usage and acceptance of contactless payments reflects growing consumer preference for electronic payments over cash for everyday purchases. According to MasterCard research, about 94 percent of PayPass-using respondents to a 2008 MasterCard PayPass Benchmark Study were satisfied with their experience, and 77 percent of consumers that have a PayPass-enabled card use it as their primary form of payment.



    About Hess Corporation



    Hess Corporation (NYSE:HES), with headquarters in New York, is a global integrated energy company engaged in the exploration, development, production, purchase, transportation and sale of crude oil and natural gas as well as the production and sale of refined petroleum, natural gas and electricity products. Hess is one of the leading independent gasoline-convenience store retailers on the East Coast with retail outlets in 16 states from Massachusetts to Florida. For more information, please visit www.hessexpress.com .



    About MasterCard® PayPass(TM)



    MasterCard PayPass is ideal for traditional cash-heavy environments where speed is essential, and has led the way in bringing contactless technology to consumer categories such as quick serve restaurants, drug stores, gas stations, vending machines, convenience stores, sports arenas, movie theaters, transit systems, taxis, parking garages and more. As of Q2 2009, there are nearly 61 million MasterCard PayPass cards and devices in use at over 153,000 merchants worldwide, including participating BP, Best Buy, 7-Eleven, CVS, McDonald's, Petco and many others. PayPass also is accepted at numerous professional football and baseball stadiums. For more information about MasterCard PayPass and a full list of participating merchants, visit www.mastercard.com/paypass .



    About MasterCard Worldwide



    MasterCard Worldwide advances global commerce by providing a critical economic link among financial institutions, businesses, cardholders and merchants worldwide. As a franchisor, processor and advisor, MasterCard develops and markets payment solutions, processes approximately 21 billion transactions each year, and provides industry-leading analysis and consulting services to financial-institution customers and merchants. Powered by the MasterCard Worldwide Network and through its family of brands, including MasterCard®, Maestro® and Cirrus®, MasterCard serves consumers and businesses in more than 210 countries and territories. For more information go to www.mastercard.com .



    Source: Company press release.
    Reblog this post [with Zemanta]

    Avivah Litan Podcast on Breaches in the Retail Industry

























    Data breaches in the Retail Industry



    In this podcast, Gartner analyst Avivah Litan talks about the Heartland data breach in relation to current data security trends in the retail industry. Also, a discussion with Ernst & Young's Sagi Leizerov on data privacy in the retail industry reveals common trouble spots for retailers, including managing vendors and tracking customer purchases.



    Sponsored by McAfee, Inc.









    Play now:

        





    Download for later:



    Data breaches in the Retail Industry

    • Internet Explorer: Right Click > Save Target As

    • Firefox: Right Click > Save Link As




    Browse Related Resources:

    Database Security  |  Payment Card Industry  |  Privacy Rights  |  Security Best Practices  |  Security Threats

    View all Resources by McAfee, Inc.











    Reblog this post [with Zemanta]

    MoneyGram International Temporarily Eliminates Money Transfer Fees from Australia and New Zealand to Samoa and Tonga



    Program helps families maximize funds sent following the recent devastation Zero fee* money transfer runs from Oct. 3 to Oct. 31




    SYDNEY---MoneyGram International (NYSE:MGI), a leading global money transfer company, announced today that it would temporarily waive its money transfer service fee from Australia and New Zealand to Samoa and Tonga, as part of a coordinated effort with its money transfer agents in response to the tsunami and earthquake that hit Samoa and Tonga on Tuesday.



    “MoneyGram is eager to help these communities continue their recovery and respond to the urgent needs in Samoa and Tonga following the devastating earthquake and tsunami,” said Janice Ong, regional manager of Australia and Oceania. “In addition, MoneyGram understands how vital it is for families and friends to support one another especially in times of great need. To provide the greatest immediate benefit to affected families, MoneyGram is temporarily eliminating fees for transactions sent to Samoa and Tonga from our Australia and New Zealand agents.”



    The no fee money transfer is available until Oct. 31 at all Australia and New Zealand MoneyGram agent locations.



    “We hope this effort by MoneyGram and our agents will assist our customers in maximizing the funds sent to loved ones,” Ong said. “Westpac Bank of Samoa and Westpac Bank of Tonga have remained open since the tsunami and earthquake to ensure funds are available for the people who need help the most.”



    Funds can be collected at any MoneyGram location in Samoa or Tonga including all Westpac Bank locations, Money Exchange Limited in Samoa and Alfred Cowley Company in Tonga.



    * A currency exchange rate may apply.



    About MoneyGram International

    MoneyGram International offers more control and more choices for people separated from friends and family by distance or those with limited bank relationships to meet their financial needs. A leading global provider of money transfer services, MoneyGram International helps consumers to safely send money around the world with funds arriving at available agent locations in as little as 10 minutes. Its global network is comprised of 180,000 agent locations in more than 190 countries and territories. MoneyGram’s convenient and reliable network includes retailers, international post offices and financial institutions. To learn more about money transfer at an agent location, please visit www.moneygram.com.
    Reblog this post [with Zemanta]

    Global Payments to Present at William Blair & Company's Emerging Stock Conference

    ATLANTA, Oct. 5 /PRNewswire-FirstCall/ -- Global Payments Inc. (NYSE: GPN), represented by Executive Vice President and Chief Financial Officer, David Mangum, will present at "William Blair & Company's 2009 Emerging Growth Stock Conference" on October 6, 2009. Mr. Mangum is expected to present at 11:45 a.m. ET. The conference will be held in New York, NY and can be accessed via Web cast at www.globalpaymentsinc.com.



    Global Payments Inc. (NYSE: GPN) is a leading provider of electronic transaction processing services for consumers, merchants, Independent Sales Organizations (ISOs), financial institutions, government agencies, gaming establishments, and multi-national corporations located throughout the United States, Canada, Latin America, Europe, and the Asia-Pacific region. Global Payments offers a comprehensive line of processing solutions for credit and debit cards, business-to-business purchasing cards, gift cards, electronic check conversion and check guarantee, verification and recovery including electronic check services, as well as terminal management. The company also provides consumer money transfer services from the U.S. and Europe to destinations in Latin America, Morocco, and the Philippines. Visit www.globalpaymentsinc.com for more information about the company and its services.



    Contact: Jane M. Elliott
    770-829-8234
    investor.relations@globalpay.com

    Disqus for ePayment News