Hackers Breach Payment Systems of Major Parking Garage Operator
wiredmikey writes Parking garage operator SP+ said on Friday that an unauthorized attacker gained access to its payment processing systems and was able to access customer names and payment card information. The company, which operates roughly 4,200 parking facilities in hundreds of cities across North America, said the attack affected 17 SP+ parking facilities. According to the company, an unauthorized person had used a remote access tool to connect to the payment processing systems to install malware which searched for payment card data that was being routed through the computers that accept payments made at the parking facilities. Parking facilities in Chicago, Cleveland, Philadelphia, Seattle, and Evanston were affected by the breach, though a majority of the locations affected were located in Chicago.
So any word on the hats they were wearing while doing what bogeymen do so well? No CCTV footage? Bit of a fail, innit.
Since they really don't have any liability, there's no incentive to secure their systems.
http://www.dailytech.com/EXCLU...
I'm beginning to think that many corporations establish online systems without ever doing a serious 3rd party security audit and then penetration testing, plus using whatever real time monitoring tools they can to detect and stop intrusions.
This reminds me of the US leaving the Southern US border open and saying "No terrorists would get in across our Southern border."
So when are you switching to chip+pin so it's at least less meaningful to steal data?
So, someone is stealing from organized crime syndicates? Is this is a dumb or smart move.
Crackers people, cheese.
(Ducks)
~.~
I'm a peripheral visionary.
MR OLUMIDE JOHNSON
we give you access to a trillion dollars worth of tech and yet the best you dumb Nigerian fucks can do with it is create a website that copy and pastes news articles or scamming with 419s and then post it on a geek site ? no wonder your country is fucked, a dog thinks deeper about their actions than you jerks do.
enjoy your mud huts, looks like you will be living in them a bit longer
Why is a payment processing system accessible via the internet? Is it connected to an online payment website? Or am I missing something? I usually don't store my payment information online.
Why the reluctance to mention the Operating System?
And stopped accepting cash. Everyone wins!
As someone that does PCI pen testing I can tell you the problem lies with upper management of these compnies. Management thinks there is no up keep on a network. These corps that have gotten cracked don't do proper upgrades and patching. The weird thing is the bigger the company the worst off their network is. Online adult toy stores have better security than you bank. No shit!
Seems the bigger corporations see that it is cheaper to give you a year's worth of credit checks and a "I'm sorry I fucked you" email than to do proper patching and upgrades.
Yes one of the top five banks still run Solaris8 on the backend. Yes that is an 8 eight!
(That's "coins" as in stamped discs of sheet metal ; "wallet" as in pouch of fabric and leather for storing payment tokens in without wearing out the fabric of one's pockets.)
Birds are not dinosaur descendants;birds are dinosaurs, for all useful meanings of "birds", "are" and "dinosaurs"