Slashdot Mirror


Security Breach Exposes 40M Credit Cards

The Good Reverend writes "MasterCard International announced today that a security breach at CardSystems Solutions, a third party processor of payment card data, potentially exposed more than 40 million cards. Mastercard is aware of the specific card numbers affected, and is giving its member financial institutions the numbers that may have been compromised. Unlike many of the past high profile cases this one involves a hacker rather than lost packages. CNN Money, the New York Times, Reuters, MSNBC, ZDNet, C|Net, and the Washington Post are also covering the story."

14 of 304 comments (clear)

  1. Proves that the hackers... by bpuli · · Score: 5, Insightful

    will always exploit the weakest link in the chain. MasterCard itself might have the best security but what about all the systems downstream? Wonder how many more of these transactions processors have been compromised and don't even know it yet.

    --
    BP http://www.card-central.com
    1. Re:Proves that the hackers... by Ian+Jefferies · · Score: 5, Funny

      Just wait for the spam social engineering angle to kick in:

      "Just enter your credit card details into this site to see if your credit card number was one of those stolen"

      (Answer: not until 5 seconds ago)

      --
      A physicist is an atom's way of thinking about atoms
    2. Re:Proves that the hackers... by Anonymous Coward · · Score: 5, Informative

      Have to agree here. I work for a large mailing house company which processes client data and sends out bank statements and tax details and all sorts of other private information.

      Having a in depth security background, I can safely say that the security of this place is shocking. The guys handling this sensitive data are just kids straight out of uni. The banks etc themselves can go to great lengths to protect their clients data, but then they outsource to 3rd parties and hand over all their data to be processed.

      Posting anonymously for obvious reasons.

  2. What I would like to see by Timesprout · · Score: 4, Interesting

    since people here (Ireland) and the UK are basically being encouraged to rack up debt is some one to crack Mastercard/Visa and wipe out all the amounts owed on credit cards. Might encourage the financial institution to be a little less carefree with their lending policies.

    --
    Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
    What truth?
    There is no dupe
  3. Re: A bit over 1/4 were mastercard branded... by Black+Parrot · · Score: 4, Insightful


    > But that leaves a little under 3/4 who aren't mastercard branded. If it was a typical third-party payments system then it is likely that they handled other types of credit cards, just that those companies havent commented yet. So when is the other shoe going to fall?

    The news has been reporting for the last 14 hours (at least) that the four major credit cards are all affected.

    Also, this has been known since May 22, but everyone was keeping it quiet.

    If there's another shoe, it's going to be that the breach was even larger than reported, or that they got more information than we're being told.

    --
    Sheesh, evil *and* a jerk. -- Jade
  4. Re:being a site full of geeks by gweihir · · Score: 4, Insightful

    the processor must pay for a replacement card for every single victim

    An one more: Processors should have mandatory insurance against this event. Then the insurance company would check their security with a keen eye....

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  5. My Card? by valjean78 · · Score: 5, Funny

    Is there a form somewhere that I can enter my credit card information to check if my cc number has been comprimised? :p

    1. Re:My Card? by arose · · Score: 4, Funny

      I'm setting one up right now... :-P

      --
      Analogies don't equal equalities, they are merely somewhat analogous.
  6. This is simply the price of outsourcing. by 0xdeaddead · · Score: 5, Interesting
    See in the banking industry we run these "penetration scans" all the time, that are TOTALY WORTHLESS. I cannot emphasize this enough, that running the weakest setup possbile will pass their "tests" with flying colours. The people doing these tests (Some certified security specialists!) Think that firewalls are magical devices that know how to stop the pesky hackers. Bottom line is that people are involved, they are out of their element, and simply placeholders. Management in general needs to get out of this "placerholder" mentality when it comes to jobs, and just fire people that are not doing their jobs.

    Ok enough ranting, but trust me, in the late 90s banks were trying to outsource as many things as possible from customer service, to invoicing, bills, credit collections, applications and so on. As you can see when the "Credit card company" becomes nothing more than a brand, and a board of execs, everything is out of their control, not to mention every peice of the old credit empire is open for attack.....

    If anything the question is why did it take so long to find them?!

  7. Weakest link by hellfire · · Score: 4, Interesting

    It's not surprising someone other than MasterCard actually had a list of card numbers stolen. I have customers all the time tell me how they don't like what they feel are draconian measures to protect the credit card numbers people have in their own systems. What they fail to understand is that Visa and Mastercard require us to do this, and the protections we have are customer service.

    But they still complain, because their customers and they themselves don't ever notice. Hell at one point I was told by a demanding customer to remove the protections because he said "I'll risk it." I was tempted to show him how insecure he was by remotely accessing his system, getting his list of customer phone numbers, and telling all his customers that he was careless with credit card numbers and their numbers could have easily been stolen from his system.

    People are pretty careless about credit card security. It's usually in the name of convenience and visible customer service. Credit card security is invisible service. Being able to purchase something conveniently flies right in the face of having security which just might prevent you from selling something to someone, so some people don't care, as long as they are selling. Owners care once they find out that they'll be issued chargebacks, but individual salesreps will write down every credit card number on a piece of paper if it means making money for them personally.

    Visa and Mastercard have the right idea, and in the press release I like how they said that they gave cardsystems a "limited amount of time" to basically get their act together so this doesn't happen again. Education and enforcement of regulations... nice to see an organization, especially one that is a corporation, actually give a damn.

    --

    "All great wisdom is contained in .signature files"

  8. The only way by BCW2 · · Score: 4, Insightful

    To end this kind of thing is to make the companies handling records financialy responsible for any problems. Triple the amount in damages to each misused account. They won't do anything until it affect the P&L severely. It's the only thing big corporations understand.

    --
    Professional Politicians are not the solution, they ARE the problem.
  9. There are some numbers hackers can't steal. by game+kid · · Score: 5, Funny

    there are some numbers hackers can't steal

    for everything else there's MasterCard

    (Accepted all over, even if it's not yours.)

    --
    You can hold down the "B" button for continuous firing.
  10. imagine a similar disaster by e**(i+pi)-1 · · Score: 4, Insightful

    Now imagine a headline in 10 years: "120 Million biometric data stolen" It seems that the technical challenges to keep data secure has sunk in already. This credit card data breach could support these concerns.

  11. Re:US numbers only? by Curtman · · Score: 4, Informative

    I think we all have to worry anyway. This kind of shit happens all the time. They're going to find the people responsible for these, and the corporations that allow it to happen will get off with only a bit of bad publicity. That's the real tragedy. There ought to be a law that if you are going to retain someone's personal information then you are responsible for keeping it safe. Same as I'm responsible for keeping my PIN number safe.