Feeds

FTC settles with CardSystems over data breach

Forced to tighten security measures and undergo audit

SANS - Survey on application security programs

A payment processor that exposed 40m credit cards to the risk of fraud when a hacker took advantages of security failures has agreed to settle Federal Trade Commission (FTC) charges. Independent security audits will now be required every other year for 20 years.

CardSystems Solutions and its successor Solidus Networks (which does business as Pay By Touch) are also obliged to implement a comprehensive information security programme.

The case hit the headlines in June last year after it was revealed that security vulnerabilities in the systems of Tucson-based CardSystems had allowed a hacker to infiltrate its network and access cardholder data, putting cards of all brands at the risk of fraud.

According to the FTC, CardSystems provided merchants with products and services used in "authorisation processing" – obtaining approval for credit and debit card purchases from the banks that issued the cards. In processing these transactions, CardSystems collected personal information from the magnetic strip of the card, including the card number, expiry date, and other data. CardSystems then stored this information on its computer network.

The watchdog charges that CardSystems failed to provide reasonable and appropriate security for this sensitive consumer information.

According to the complaint, CardSystems not only created unnecessary risks to the information by storing it, but it did not then adequately assess the vulnerability of its computer network to commonly known or reasonably foreseeable attacks.

The company did not implement simple, low-cost, and readily available defences to such attacks, nor did it use strong passwords to prevent a hacker from gaining control over computers on its computer network and access to personal information stored on the network.

In addition, the FTC says, CardSystems did not use readily available security measures to limit access between computers on its network and between its computers and the internet, nor did it employ sufficient measures to detect unauthorised access to personal information or to conduct security investigations.

"CardSystems kept information it had no reason to keep and then stored it in a way that put consumers' financial information at risk," FTC chairman Deborah Platt Majoras said. "Any company that keeps sensitive consumer information must take steps to ensure that the data is held in a secure manner."

The security breach resulted in millions of dollars in fraudulent purchases and caused banks to cancel and re-issue thousands of credit cards. On top of this, consumers experienced inconvenience, worry, and time loss dealing with the affected cards, according to the FTC.

See The FTC complaint.

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.