Google Search

Showing posts with label MasterCard. Show all posts
Showing posts with label MasterCard. Show all posts

Friday, April 6, 2012

MasterCard and Visa payment processor compromised, up to 10 million cards stolen

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Card Terminal photo courtesy of ShutterstockBrian Krebs is reporting that MasterCard and Visa are warning member-banks of a payment processor breach that may impact more than 10,000,000 credit cards.

It is important to note that MasterCard and Visa's own networks were not involved in the attack, it appears to be related to payment processor Global Payments.

Reuters is reporting that Global Payments stock was suspended for trading after falling more than 9% on the Nasdaq stock exchange.

Krebs reported that one of the financial institutions he spoke with had to cancel 56,455 credit cards, of which fraud was detected on 876, or 1.5%.

There is much speculation about the source of the breach as many are reporting that the majority of the fraud is occurring in the greater New York City area, yet cards are being cancelled around the country.

What is a payment processor? Payment processors provide merchants (stores) with access to payment brokering networks like MasterCard, Visa, American Express and Discover. The terminal that processes your card sends the details of the transaction to the payment processor to facilitate the purchase.

It is being reported that the attackers got "full Track 1 and Track 2 data". This is very bad as it would allow for the attackers to fully produce cards including the CVV/CCV code you often need to enter for online transactions.

Strangely, law enforcement contacts told Krebs they believe the breach is related to a Dominican gang in New York and primarily targeted corporate credit and debit cards.

Card statement image courtesy of ShutterstockFortunately consumers don't need to worry too much. Card issuing banks (Bank of America, Chase, etc.) are cancelling cards that are involved in the theft and card holders will not be held responsible for any fraudulent activity.

I wouldn't cancel my card or ask for a new one, but it would certainly be prudent to keep a close eye on your statements to be sure nothing suspicious shows up.

As we find out more details on how this heist came about, we will post information here. From the sound of it the card information sounds like it may not have been encrypted or they wouldn't need to cancel so many cards.

Follow @chetwisniewski

Credit card processing terminal image and card statement image courtesy of Shutterstock.


View the original article here

Saturday, July 2, 2011

MasterCard Taken Down by Hackers Again in Support of WikiLeaks

Hackers have attacked MasterCard's website in protest of the company's blockade of WikiLeaks.

"MasterCard.com DOWN!!!, thats what you get when you mess with @wikileaks @Anon_Central and the enter community of lulz loving individuals :D," tweeted @ibomhacktivist, who seems to be connected with the hacker collective Anonymous.

[More from Mashable: LulzSec Shuts Down, Ends Hacking Campaign]

Though MasterCard's site is currently online, there are reports that it was completely offline at one point due to the DDoS (distributed denial of service) attack.

In December 2010, hackers took down Mastercard's website, along with Postfinance and PayPal, for the exact same reason: a WikiLeaks blockade.

[More from Mashable: Dropbox Bug Made Accounts Accessible Without Passwords]

Shortly after the attack on MasterCard, WikiLeaks acknowledged on its official Twitter account that several banks still won't do business with the organization. "The unlawful banking blockade against WikiLeaks in 6th month: The culprits: VISA, MasterCard, PayPal, Bank of America, Western Union," said the tweet.

LulzSec, the hacker group that wreaked havoc on corporate and government websites in the past two months, recently disbanded. However, the Anonymous hacktivist collective vowed to continue their hacking activities, and we can already see proof that they weren't kidding.

[via Finextra]

This story originally published on Mashable here.


View the original article here