Community
What data breach? Are you talking about the one that happened at Heartland in 2009? Or, maybe the Fidelity one from 2011? Again, no?
Oh, you're referring to the latest one that led to the arrests in New York of several people who fraudulently withdrew $45M from several ATMs.
By now, it should be obvious what's different about the latest breach. If not, read on.
High-profile breaches in the past, like the ones that hit Heartland Payment Systems and Fidelity National Information Services, involved theft of payment card information. The current one has gone further and has actually resulted in the loss of money. It's accordingly known as "$45M ATM heist" than data breach.
Like other past breaches into payment information, this one also began as breaking and entering into the databases of several payment processors - including ElectraCard Services and EnStage - who hold sensitive card information of banking customers. The first B&E into ElectraCard Services happened in December 2012 and the second one involving EnStage, in February 2013. At the time, there was little publicity about these breaches, at least nothing that caught my eye. The real media frenzy began only when the scamsters who used the stolen information to withdraw money from ATMs were apprehended in NYC about 10 ten days ago. In other words, this is one of the rare cases of a high-profile data breach that is directly linked to financial losses.
Like an onion peel, details of the present incident are unraveling day by day. I hope we'll eventually get answers to the following questions:
I also hope this incident makes it amply clear to regulators that large scale frauds happen as a result of breaches into payment processors' systems, and not when individual cardholders are shopping online and putting through one-off transactions. Keeping this in mind, they should revisit their present approach of trying to prevent fraud by insisting on cumbersome two-factor authentication for all sizes of online and mobile payment transactions. Such a procedure adds friction and causes heavy shopping cart abandonment (more on that here) while proving futile when sensitive data comes under an attack where it's found in bulk. Instead, regulators should shift their focus to ensuring that payment card information is encrypted and stored absolutely safely. In this context, the CEO of Heartland Payment Systems set the tone by accepting that, when it comes to security levels to be maintained by payment processors, PCI certification is necessary but not sufficient.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
Alex Kreger Founder & CEO at UXDA
27 November
Kyrylo Reitor Chief Marketing Officer at International Fintech Business
Amr Adawi Co-Founder and Co-CEO at MetaWealth
25 November
Kathiravan Rajendran Associate Director of Marketing Operations at Macro Global
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.