Technology Review

Computing

Malware Swipes Millions of Credit Cards

A security breach shows failings in security rules.

  • Thursday, January 22, 2009
  • By John Borland

Tens of millions of credit cards could be at risk of fraudulent use thanks to a serious computer-security breach at financial-transactions company Heartland Payment Systems. Earlier this week, Heartland revealed that a piece of malicious software, apparently installed inside the company's transaction-processing system last year, had compromised credit-card data as it crossed the network.

The breach was announced on Tuesday--the day of the U.S. presidential inauguration--and, according to some experts, it shows that attackers are successfully defeating the financial industry's tough computer-security rules. "The potential is certainly there for this to be one of the biggest, if not the biggest breach we've seen," says Rich Mogull, founder of computer-security consulting company Securosis. "Something huge had to have gone wrong here."

It's not clear precisely what kind of malicious software was used, or how many credit-card accounts were compromised. But company president Robert Baldwin has said that Heartland handles as many as 100 million transactions per month.

From a consumer perspective, the level of danger stemming from the Heartland breach is uncertain but significant. Heartland has declined to say which merchants were involved in the fraudulent transactions, or how long the malicious software was operating. But the company serves more than 250,000 locations, with a particular focus on small businesses such as restaurants and hotels.

Advertisement

Heartland has created a website to answer customers' questions regarding the break-in. Some credit-card companies are already notifying subscribers, and others may simply issue new cards. But consumers have been warned to keep a close eye on their statements. Most credit-card companies will cover the cost of unauthorized activity completely, as long as the fraud is reported within several months.

Heartland executives say that their first danger sign came in the form of warnings from MasterCard and Visa regarding suspicious transaction activity related to the company's business. Heartland hired forensic computer specialists to investigate, and last week discovered the malware on its system, according to statements issued by the company.

Heartland says that the compromised data did not include personal information such as addresses, PIN numbers, Social Security numbers, or phone numbers, reducing the threat of full-blown identity theft. However, security experts say that the data stolen could be used to create cloned versions of the original credit cards, with nothing more complicated than blank magnetic-strip cards and a sub-$200 card writer. In most cases, these false cards would have to be used at a physical location since online purchases and other "card not present" transactions typically require a customer's address or other identifying information to be supplied.

Print

Related Articles

Hijacking Mobile-Phone Data

Researchers claim to be able to hijack cell-phone data connections.

A Plan to Catch the Conficker Worm

A new tool allows entire networks to be scanned efficiently for infection.

A Portal to Your Passwords

A Web browser loophole could make it easier for crooks to scam the unwary.

To comment, please sign in or register

Forgot my password

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Sponsored Content

Technologies from National Instruments

Adding Data Logging
Log measured data to a file and open it in Microsoft Excel

> Click here for more National Instruments Videos <
Whitepaper

Temperature Measurements with Thermocouples: How-To Guide

This document is part of the “How-To Guide for Most Common Measurements” centralized resource portal. This tutorial provides a detailed guide for measurement and device considerations to take temperature measurements using thermocouples. Get an introduction to thermocouples, which are inexpensive sensing devices widely used with PC-based data acquisition systems. Also review some specific thermocouple examples and learn how thermocouples work and ways to integrate them into a data acquisition measurement system.

View full PDF > Listen to story >
Find us on Youtube

Videos

A Robot Recruit that Can Do It All

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Calxeda

BIND Biosciences

Siemens

American Superconductor

More

Advertisement

Facebook

Advertisement