Register for E-mail alerts. Comment on articles. Sign up today, it's easy.
Close
The Washington Times Online Edition

Breach reveals vulnerability of credit cards

ASSOCIATED PRESS

The criminal exploit that exposed 40 million credit card accounts to possible fraud is shedding light on an arcane but sensitive piece of the financial industry: the hundreds of companies that process transactions between merchants and card issuers.

While enormous in scope, the breach disclosed Friday at CardSystems Solutions Inc. was by no means the first such attack on a card processor.

Many analysts believe that banks and credit card companies, despite working hard to tighten their own security, have failed to force payment processors to maintain similar standards.

“They’re not being watched carefully enough,” said Avivah Litan, an analyst with Gartner Inc.

In recent years, card associations such as Visa and MasterCard have set up security requirements for processors to follow. No laws in particular govern this program, but the card associations can impose fines of several hundred thousand dollars for transgressions.

However, Miss Litan said aggressive audits of companies like CardSystems aren’t being done.

Credit card companies “just sort of wait for them to have a breach,” she said. “There’s just a lot of vagaries in how it’s enforced.”

In fact, she said, several similar breaches have occurred and the public wasn’t told.

Card processors and merchants must certify through third-party monitors that they meet the banks’ and credit card associations’ security standards. But complying can be a long and costly process.

Consequently, several experts said they doubt that CardSystems, which annually processes some $15 billion in transactions for more than 105,000 small- to mid-sized businesses, is alone among card processors in being vulnerable to hackers.

“It’s quite possible that it could exist elsewhere,” said Michael Petitti, a senior vice president at AmbironTrustWave, one of the companies that performs the industry’s security certifications. CardSystems was not in his company’s purview, he said.

The breach occurred after CardSystems inappropriately held onto card data for “research purposes” rather than deleting it. Forty million accounts were exposed, and records pertaining to at least 200,000 are known to have been stolen, primarily MasterCard and Visa cards.

CardSystems did not return repeated calls seeking comment yesterday, but MasterCard spokeswoman Sharon Gamsin said the records — names, banks and account numbers — should have been deleted because “you don’t want that information sitting around.”

“Merchants aren’t allowed to keep it, and these processors aren’t allowed to keep it,” she said.

Story Continues →

View Entire Story
Comments
blog comments powered by Disqus
You Might Also Like
  • **FILE** Director of National Intelligence James Clapper (Associated Press)

    Sanctions may be changing Iran’s nuke plans

    By Shaun Waterman - The Washington Times

  • David Wilmot, a power player in the District, is using a program to aid the economically disadvantaged to win contracts. (Barbara L. Salisbury/The Washington Times)

    Top D.C. lobbyist says he deserves special aid

    By Jeffrey Anderson - The Washington Times

  • Washington state Gov. Chris Gregoire is surrounded by legislators and others Monday as she signs into law a bill legalizing same-sex marriage. The law is to take effect June 7, but opponents are mounting a repeal effort. (Associated Press)

    Washington ballot best chance for foes of same-sex marriage

    By Valerie Richardson - The Washington Times

  • Happening Now

          Independent voices from the TWT Communities

          The Political Pro-Con

          Not your typical discussion, writer Conor Murphy writes about the cons, and pros, of politics

          A Heart Without Compromise; Advocating for Children

          Children around the globe are too often silent. From victims of abuse - physical, mental, and sexual to those whose lives embrace joy, their stories are many and need to be heard.