Up To 1.5 Million Visa, MasterCard Credit Card Numbers Stolen
An anonymous reader writes "Global Payments, the U.S.-based credit card processor company that experienced a security breach affecting Visa and MasterCard, confirmed that the breached portion of its processing system was confined to North America. The company also finally revealed how many credit card numbers were stolen: around 1,500,000."
And what recourse do card holders have? How do we know if our number was stolen, passed around, and now someone is just holding onto it indefinitely and might leap to use it after this whole thing blows over? A bit frightening.
Nothing is more dangerous than a programmer with a screwdriver.
on top of my theory that digital cash will prove to difficult to protect and ultimately fail; which is a shame, I like digital cash.
The Kruger Dunning explains most post on
I want to check if mine is on the list ;-)
New things are always on the horizon
That government guy from the cyberwar scare story last week had it right... We need a new security model. Just assume that your credit card numbers, your social security number, etc., are already compromised. Those things were never designed to be secure, and companies that we trust with this data simply can't keep them safe. We just have to accept that the bad guys are all up in our business and adjust our practices accordingly. We could do it.
"Here Lies Philip J. Fry, named for his uncle, to carry on his spirit"
Oh thank goodness it was limited to only North America! I'm so relieved.
You can't steal a number! It's not stealing if you still have your copy of the number! It's copyright infringement at the most.
Also, if put them one after the other, they stole a single number!
73
There you are, you can keep that number in exchange. I never liked 73 anyway.
You're welcome.
The bank had cancelled my card on Saturday morning stating that my number was reported to have been hacked. I had nothing taken but it was nice to know that they were on top of it just in case. The only hindrance to me was that I to run to the bank and get a temp card.
Foot placed squarely in mouth since 1983.
Because it was Visa/MasterCard and not Sony, /. won't make a big fuss over it.
My card expires in a few months anyway, guess I'll just step up getting a new one.
What do I know, I'm just an idiot, right?
their pa7r7ing
The thing is there are so many better ways to do things right now. For starters, you could force any retailer that wants to accept credit cards to upgrade to a chip and pin setup or lose their ability to accept credit cards. Chip and pin isn't perfect, but it's better than a magnetic stripe and a signature. For card not present transactions allow Visa card holders to create a one time credit card number (with a maximum limit) via the internet or over the phone. Want to buy something on line? Generate your own credit card number to the exact value of what you're buying. That CC # number expires at the end of the day - meaning that even if you gave it a ridiculous limit and then sent it to a shady site they'd have 24 hours to use it.
Of course implementing these fixes would cost more than just paying the scammers, so we'll never see it happen.
The numbers are still there, man, it's, like, totally just a bunch of bits and bytes and junk.
Or do we only apply that argument to music and movies and porn, hmm?
If you were blocking sigs, you wouldn't have to read this.
Nothing was stolen. They made a copy of a file or files that contained the credit card numbers. The company still has their copy of those numbers so they haven't actually lost anything.
So at most this is what? copyright infringement?
Of course they make sure to announce it on the same day as the Final Four championship. They want this story to get buried. Just like when Heartland processing made sure to announce their breach the same day as Pres. Obama's inauguration.
This is what happens when you have companies who have people who wear many hats and don't commit a person to watching over security. I see it all day long, they want someone who has PCI experience but they also want you to manage the network and everything else that plugs into the wall.
Companies who deal with credit card information needs to dedicate a security person to ensure that all PCI guidelines are being enforced and followed.
There are specific tools and software that PCI compliant companies have to have in place. I bet you the compliance guy was working on the other 10 emergencys that had nothing to do with PCI at the time the breach occured.
Guess who gets fired now.
Nah, that's not all that bad!
Krebs on Security stated the number was 10 million. GP and all initially admitted to 50,000.
I'm betting on Krebs. He's pretty reliable, or at least his sources are.
deleting the extra space after periods so i can stay relevant, yeah.
As mentioned at the other article related, because each time when there is a chargeback, the bank will take back the money from the merchant + somewhere between $15-$65 per transaction as a penalty. They have no incentives to make the system more secure.
Unless the law changes that makes the bank and VISA/MC liable for any fraudulent trasnactions, online or offline.
Twitter: @dainsanefh
At what point do we just assume that all CC #s have been stolen and if you haven't had your card # stolen yet, it's just a matter of time.
Debit != Credit. Learn the difference and learn to read before commenting next time
Heed your own advice before being rude. Global Payments processes debit, credit, and gift cards. Debit and credit cards were exposed by the breech. Fraudulent activity has been reported on both.
This has happened to me twice before, once with SONY and the other time was with the actual bank itself. Both times they have issued me a new card and my credit rating suffered a total of 80pts. That's a lot of hitpoints =/ But that's okay, because these banks don't care, they will just raise my APR to its legal limit, which is ridiculous considering that I have near-perfect (890) credit. Thanks banks and credit bureaus, you make me feel so good when I bend over and take it like a Swedish gimp.