Home > Data management / BI News > CardSystems admits stolen data violated policy
Data management / BI News:
EMAIL THIS

CardSystems admits stolen data violated policy

By Anne Saita, News Director
21 Jun 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

The depth of the data theft at CardSystems Solutions Inc. continues to grow after its CEO admitted the company had no business holding onto the 40 million credit card accounts it now admits were compromised recently by computer hackers.

John M. Perry told The New York Times the cardholder data was kept for "research purposes." MasterCard and Visa both require card processors such as the one CardSystems ran in Tucson, Ariz., to expunge that information once it is passed on to the banks. Instead, the Atlanta-based company retained records. "We should not have been doing that," Perry told the newspaper.

The theft came to light after credit card companies asked for a security audit of CardSystems' network following a spike in fraudulent charges on MasterCard and Visa cards processed in Tucson in April and May. A script to capture data, most likely installed via a virus, was discovered by digital forensics experts on May 22. The FBI was called in to investigate a day later.

MasterCard announced the database theft about a month later, on Friday. A CardSystems executive told The Associated Press the company was "absolutely blindsided" by the MasterCard press release in which the company warned that at least 68,000 account numbers had been exported by thieves. News accounts say 20 million accounts accessed in the massive database were Visa customers and almost 14 million owned MasterCard cards. The remaining 6 million were Discover or American Express cardholders. Company officials emphasized no Social Security numbers were on the cards to assist in identity theft. But fraud is another story.

Some say the 40 million accounts now at risk make CardSystems' attack the largest database hack to date. But it's just the latest in a litany of major companies to acknowledge security lapses that now have consumers, employees and clients scrambling to protect themselves against cybercrime. In fact, 14 companies have been forced to tell the public that private data had been exposed due to lapses in physical and logical security. Some, such as at Alpharetta, Ga.-based ChoicePoint Inc., involved social engineering by conmen; others, like Time Warner and Bank of America, included unencrypted backup tapes lost or stolen in transit.

"The steady stream of these disclosures shows the pressing need for regulation of the industry both in terms of limitation in the amount of personal information that companies collect and also liability when these kinds of disclosures occur," the Electronic Privacy Information Center's general counsel, David Sobel, told the AP when the attacks were first publicized. At least four bills related to consumer data privacy are floating around Congress at the moment.

Note: This story originally appeared on our sister site, SearchSecurity.com.



Tags: Enterprise content managementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise content management
Disjointed eDiscovery practices exposing companies to legal risk, rising costs
Enterprise search technology gives police the edge on criminals
Microsoft, IBM, others team up on enterprise content management standard
Enterprise content management brings order to chaotic unstructured content
DAMA keynote: Survival of the data management fittest
Content analytics takes the guesswork out of content lifecycle management
Off-site data storage: How far away is far enough?
Content intelligence: Content management meets business intelligence
Storage device: Before you purchase
Text analytics, search bolster business intelligence software stack, says TDWI

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
data classification  (SearchDataManagement.com)
synthetic backup  (SearchDataManagement.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Data Management: Business Intelligence, Data Integration, Data Compliance
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2005 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts