HomeATM Extends Warm Holiday Wishes to Everyone!
Enjoy your Christmas!
Enjoy your Christmas!
| December Transactions | CHANGE |
|---|---|
| Credit & Signature Debit | +5.1% |
| PIN Debit | +11.7% |
| EBT | +26.2% |
| Total Transactions | +7.9% |
| Note: Growth reflects same store transactions only. | |
(December 23, 2009) MasterCard Inc. is changing a controversial policy, and pushing back a deadline, that it announced only six months ago regarding enforcement of the Payment Card Industry data-security standard. With the changes, which involve assessing computer systems for PCI compliance, MasterCard could be viewed as responding to valid complaints after first disclosing the planned changes, or it could be viewed has having done a flip-flop. Or both at the same time.Continue Reading at Digital Transactions News
In June, MasterCard adopted a new policy governing whether big merchants can do so-called self-assessments of their PCI compliance. The new policy applied to so-called Level 2 merchants, those submitting 1 million to 6 million total MasterCard and Maestro (PIN-debit) transactions annually, and Level 1 merchants, those submitting more than 6 million transactions. MasterCard previously had let Level 2 merchants to do annual self-assessments for PCI compliance unless they brought in a Qualified Security Assessor (QSA) certified by the PCI Security Standards Council for an on-site assessment. But come Dec. 31, 2010, MasterCard planned to require that all Level 1 and, for the first time, Level 2 merchants, use a QSA for the annual on-site PCI assessment.
That policy generated many complaints from Level 2 merchants, who security experts say would have to pay anywhere from $100,000 to $1 million for a QSA’s services. MasterCard’s policy also diverged from Visa Inc.’s, which lets Level 2 merchants do self-assessments. Many observers also wondered whether there were enough QSAs to go around to handle all the new work from Level 2s.
This month, however, MasterCard pushed back the deadline by six months, to June 30, 2011. And instead of requiring use of a QSA, MasterCard will let Level 2 merchants do the assessments themselves provided they have staff attend merchant-training courses offered by the PCI Council, and each year pass a PCI Council accreditation program. Level 2 merchants are free to use QSAs if they wish. Come June 30, 2011, Level 1 merchants can use an internal auditor provided the audit staff has PCI Council training and annual accreditation. MasterCard also said its definitions of merchant levels now match Visa’s, so, for example, if a merchant is a Level 2 merchant in Visa’s eyes, it’s also one in MasterCard’s eyes.
"Merchants’ lobbyists want consumers to believe they will benefit if Congress regulates the fee of about 2 cents on a dollar merchants pay for the benefits they get by accepting credit cards: they outsource their credit risk to the banks that issue the cards and are responsible if customers default; they get protection from fraud and theft; guaranteed payment, and efficient record keeping. Plus higher sales, as consumers aren’t constrained by the amount of cash they have in their wallet.
If merchants don’t pay their fair share, consumers get hurt. Like any other valuable service, electronic payments have a cost. Today, those costs are split between the two key beneficiaries - merchants and cardholders. If merchants get their way and persuade Congress to regulate their share, consumers will pay more. That happened in Australia, where the government regulated these fees. Consumers there now pay more for their cards through higher annual fees, fewer benefits, and sometimes, surcharges when they choose to use their cards. Merchants pocketed the savings, as there is no evidence that they have cut the prices they charge.
SHAWN MILES
Purchase, N.Y.
The writer is head of global public policy forMasterCard .
The Wall Street Journal ran a front page story that Citigroup, Inc. had been hacked. Citi responded that there was no breach, then PC World reported that it was an "old breach confused as a new breach." Then the WSJ story was attacked as being inaccurate..."Official statistics in the US suggesting $260m was lost last year in all forms of online crime are a complete joke." It’s a scandal. Why the authorities and the banks allow this cover-up to continue is a mystery.This, from Seeking Alpha:
The Federal Bureau of Investigation is probing a computer-security breach targeting Citigroup Inc. that resulted in a theft of tens of millions of dollars by computer hackers who appear linked to a Russian cyber gang, according to government officials.The fallout, however, is incredibly muddy and opaque.
...Massachusetts’s highest court (the Supreme Judicial Court or “Supreme Court” as referenced herein) delivered retailers a significant holiday gift in the form of an opinion slamming the door on some financial institutions seeking to recover reissuance costs arising out a retailer’s payment card data breach.
The Cumis Insurance Society, Inc. v. B.J. Wholesale Club, Inc. decision (“Supreme Court Decision”) analyzed and ruled upon most of the mainstream legal theories issuing banks have used to attempt to recover card reissuance costs, including breach of contract under a third party beneficiary theory, fraud, negligence, negligent misrepresentation and breach of unfair/deceptive practices laws (in this case M.G.L. Chapter . 93A, section 11). We have previously commented on multiple decisions involving retailer payment card breaches similar to the BJ Wholesale breach and PCI liability in general, including a 3rd Circuit federal appellate decision that allowed issuing banks to proceed forward with a third party beneficiary breach of contract theory.
This blog post dives into and analyzes the Supreme Court Decision, and looks at it in context against similar decisions. Overall, in terms of issuing banks recovering for payment card breaches, the game does not appear to be litigation in the courts, but rather in the backroom contracts and recovery processes contained in the card brand operating regulations that most retailers agree to comply with.
Continue Reading
Background. We recite the undisputed facts in the summary judgment record, reserving some facts for later discussion. Visa and MasterCard are membership organizations in which issuing and acquiring banks join in order to participate in point of sale transactions using the Visa and MasterCard brands. Issuing banks such as the plaintiff credit unions issue the physical plastic credit cards to cardholders, determine the amount of the authorized credit line available to each cardholder, and approve or decline each transaction when the cardholder presents the credit card to make a purchase.
When a cardholder presents a credit card to a merchant, the merchant transmits the information encoded on the back of the credit card to the acquiring bank. The acquiring bank, in turn, transmits the information to Visa or MasterCard, which submits the request to the appropriate issuer. The issuer then relays its decision to approve or decline the transaction back through the same channels to the merchant. After the transaction is approved, the acquiring bank acquires the merchant's Visa or MasterCard receipt, pays the merchant for the amount of the transaction, and seeks payment from the issuing bank; the issuing bank pays the acquiring bank and debits the cardholder's account. Approximately 16,000 issuers are members of the Visa organization and approximately 20,000 issuers are members of MasterCard. At least 20 million merchants participate in the Visa and MasterCard payment processing systems, but none are members and none contract directly with Visa or MasterCard.
Visa and MasterCard each issue extensive operating regulations that govern the payment processing system and their members' obligations. Every financial institution that becomes a member of the Visa and MasterCard organizations must sign a contract that includes a provision that it will comply with these regulations; acquirers are also contractually obligated to ensure that their merchants comply. Both Visa and MasterCard regulations prohibit merchants and acquirers from storing magnetic stripe data from the back of credit cards, in whole or in part, after a transaction is completed.
In February, 2004, Visa and MasterCard determined that computer thieves had gained access to the computer systems on which BJ's stored credit card transaction data at more than 150 stores, and that the breach had been ongoing since July, 2003. The breach provided the thieves access to the full magnetic stripe data from approximately 9.2 million cardholder accounts, allowing them access to cardholder names, account numbers, account expiration dates, and proprietary Visa and MasterCard security data. It was ultimately determined that the third-party transaction processing software used by BJ's was permanently storing the magnetic stripe data in transaction logs. The agreements between BJ's and Fifth Third contained a requirement that BJ's comply with Visa and MasterCard's regulations, including those prohibiting BJ's from storing any magnetic stripe data after a transaction was completed; the agreements among Fifth Third and Visa and MasterCard required Fifth Third to ensure that its merchants complied with the regulations. BJ's conceded that it was retaining the magnetic stripe data.
Visa and MasterCard notified all their member issuing banks that had issued any of the possibly compromised accounts. In response to this notification, the plaintiff credit unions closed all their potentially compromised accounts, without regard to whether fraudulent charges had been made on a particular account; advised cardholders to destroy their old plastic credit cards; and issued new account numbers and new plastic credit cards to all affected cardholders. Cumis paid the plaintiff credit unions millions of dollars for fraudulent transactions made using the compromised accounts; the plaintiff credit unions and Cumis then commenced this action.
Offering Chase Checking Account Customers a way to enjoy Disney Perks and Rewards
"This research, on the whole, confirms long standing trends; increasing reliance on debit cards and phone or internet banking and a noticeable decline in use of cheques. That said, while there are clear nationwide trends there are also parts of the country which stand out in comparison to the national statistics, for example the proportion of adults in the North East using internet or phone banking, which at 46 per cent is 7 per cent below the national average.
“Payment Regions brings together these regional variations and offers a fascinating insight into how our payment habits compare with those of our neighbours. It also demonstrates how as a nation our payment habits have evolved to take advantage of new technology and to meet the needs of our ever more demanding lifestyles."
Hackers are always probing for ways to crack new technology, even elements so personal you would never imagine they could be hacked -- like, well, your face. Extreme hacks that hit close to home and we can see in the mirror remind us of just how much technology has infiltrated the everyday, and how fragile it ultimately can be at the hands of the bad guys.
This year saw some creative and unusual hacks that gamed biometric facial identities, weaponized iPod Touches, dug up actual missile defense data on a second-hand hard drive, replaced application updates with malware in midstream, and even found a way to silence a teenager's frenzy of text messaging. And don't get us started on a phony Bill Gates "LinkedIN" e-vite that landed in multiple corporate emailboxes unscathed.
These are among the hacks we have selected as nine of the coolest hacks covered here at Dark Reading in 2009 -- sometimes off-the-wall and in-your-face (pun intended) vulnerabilities that were exposed and exploited by creative and imaginative researchers who are all about staying one step ahead of the bad guys, and maybe having a little fun along the way.
So kick back, relax (if you can), and take a look back at the more offbeat yet profound hacks of the year.
When buzz began bubbling up around Square about a month ago, the industry took notice. Many charged that was due mainly in part because the driving force behind Square was the co-founder of Twitter, Jack Dorsey. Many industry insiders, like MagTek CEO Mimi Hart, raised security concerns around where the consumer's data was encrypted.
PYMNTS.com asked "Paying with Plastic" author and industry expert David S. Evans to speak with Dorsey about why Square is "what's next" in payments.
A New Report From Aite Group |
Online banking executives are optimistic about their budgets for 2010, with half of those surveyed anticipating significant budget increases. |
Boston, MA, – A new report from Aite Group, LLC assesses financial institutions' development priorities for the online channel in 2010. The report, which is based on Aite Group interviews with senior online channel executives from 20 of the 100 largest U.S. banks, reveals that executives are optimistic about their budgets for 2010. Among the banks surveyed, half anticipate budget increases more than 15% higher than 2009 budgets. |
The year ahead looks to be a good one for investment into and strategic focus on banks' online channels. Driving this renewed focus is a stronger commitment from senior management, according to interviewees. Banks will pursue different online strategies. Some will pinpoint online sales and marketing, while others will focus on online service or improving the customer experience. One theme cuts across all the strategies: channel integration. Many online channel executives stressed the need to improve their bank's ability to integrate sales, service and the customer experience across channels. "Despite the attention that the online channel has received and its promise to revolutionize traditional banking, many banks have never truly embraced it as a primary channel for customer interactions and transactions," says Ron Shevlin, senior analyst with Aite Group and author of this report. "The tide is finally turning. The combination of two forces - banks waking up to the reality of consumer behavior, and the ascent of a younger group of managers with a more accepting view of technology - is finally helping to bring about this change." |