Massive credit-card security breach

N&P: Discuss governments, nations, politics and recent related news here.

Moderators: Alyrium Denryle, Edi, K. A. Pital

Post Reply
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Massive credit-card security breach

Post by Darth Wong »

CBC wrote:Hackers attack credit card processor in massive security breach
Last Updated: Wednesday, January 21, 2009 | 9:41 AM ET
CBC News

A U.S.-based company that processes credit card transactions for more than 250,000 businesses has uncovered a massive security breach, officials said Tuesday.

New Jersey-based Heartland Payment Systems said malicious software in its processing system was uncovered last week.

Canadian merchants were not believed to be affected, although consumers who may have travelled to the U.S. and used a Visa or MasterCard credit card are advised to check their credit card statements for any irregularities.

"We found evidence of an intrusion last week and immediately notified federal law enforcement officials as well as the card brands," Robert H.B. Baldwin Jr., Heartland's president and chief financial officer, said in a release.

"We understand that this incident may be the result of a widespread global cyber fraud operation, and we are co-operating closely with the United States Secret Service and Department of Justice."

The company said the breach did not affect merchant data, social security numbers, unencrypted personal identification numbers, addresses or telephone numbers.

CBC News' Marivel Taruc, who spoke with Baldwin, said authorities suspect Heartland may not be the only company to have been hacked in this operation. Authorities suspect the extent of the breach could be among the largest ever committed.

"The other concern here [is] cyber experts are saying this could be the biggest breach of credit card fraud online ever … because Heartland processes 100 million transactions every month," Taruc said.

The largest online data breach — in which more than 94 million credit and debit cards were exposed — was committed in January 2007 against the TJX Cos.

A probe by the privacy commissioner's office found the Massachusetts-based parent company of Winners and HomeSense collected too much information, kept the data for too long and relied on weak WEP encryption technology to protect its wireless local networks.

The privacy commissioner also found the hackers did not use sophisticated equipment to break into the computer system.
Wonderful. They process a hundred million transactions every month and they rely on WEP for security on their wireless networks.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
Admiral Valdemar
Outside Context Problem
Posts: 31572
Joined: 2002-07-04 07:17pm
Location: UK

Re: Massive credit-card security breach

Post by Admiral Valdemar »

Oh wow. Why didn't they cut out the middle-man and just hand out information CD-ROMs to passers by?
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Re: Massive credit-card security breach

Post by Darth Wong »

Why aren't financial institutions ever sued for negligence? Or am I just not hearing about these lawsuits? It seems to me that the whole goddamned industry has been ridiculously careless for a long time now, and not just about network security.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
General Zod
Never Shuts Up
Posts: 29211
Joined: 2003-11-18 03:08pm
Location: The Clearance Rack
Contact:

Re: Massive credit-card security breach

Post by General Zod »

Darth Wong wrote:Why aren't financial institutions ever sued for negligence? Or am I just not hearing about these lawsuits? It seems to me that the whole goddamned industry has been ridiculously careless for a long time now, and not just about network security.
It probably doesn't help that the financial institutions have armies of lawyers at their disposal and you practically have to be a billionaire to even really consider suing them successfully.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
User avatar
Glocksman
Emperor's Hand
Posts: 7233
Joined: 2002-09-03 06:43pm
Location: Mr. Five by Five

Re: Massive credit-card security breach

Post by Glocksman »

Wonderful. They process a hundred million transactions every month and they rely on WEP for security on their wireless networks.
That's my employer's (TJX) breach, not Heartland's.
The article doesn't say how the malicious software got in Heartland's setup.
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier

Oderint dum metuant
User avatar
Solauren
Emperor's Hand
Posts: 10422
Joined: 2003-05-11 09:41pm

Re: Massive credit-card security breach

Post by Solauren »

Quite frankly, malicious software getting into any kind of finacial system reaks of pour security.

Maybe they shouldn't be sued, but someone should lose their job(s) over this.
I've been asked why I still follow a few of the people I know on Facebook with 'interesting political habits and view points'.

It's so when they comment on or approve of something, I know what pages to block/what not to vote for.
Post Reply