Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Visa, Amex cut ties with processing firm hit by security breach

After October, CardSystems won't be allowed to process their transactions

July 20, 2005 12:00 PM ET

Computerworld - Visa U.S.A. Inc. and American Express Co. are terminating their contracts with a credit card transaction processing company that was hit by hacker attacks, potentially exposing 40 million card numbers to online intruders.

In separate announcements, Visa and American Express said they are ending their relationships with CardSystems Solutions Inc. in Atlanta because the company didn't meet its contractual requirements in providing processing services for merchants that accept the credit cards. The companies will no longer allow CardSystems to process their transactions after October.

Rosetta Jones, a spokeswoman for San Francisco-based Visa, said in a statement that the action against CardSystems comes "after an internal and forensics review of its processing practices demonstrated that -- in violation of Visa's rules -- it did not have the appropriate controls in place to protect cardholder information."

"Despite some remediation actions taken by the processor since the initial reporting of the data compromise, Visa cannot overlook the significant harm the data compromise and CardSystems' failure to maintain the required security protections has had on Visa member financial institutions and merchants, as well as the significant concerns it has raised for cardholders," Jones said. "CardSystems has not corrected, and cannot at this point correct, the failure to provide proper data security for Visa accounts."

CardSystems apparently kept credit cardholder data on file after the transactions were processed, in violation of its agreement with Visa, she said. Because the data was still on file, it could be accessed by intruders. "Visa's security requirements were adopted precisely for the purpose of protecting cardholder information and guarding against the type of data compromise recently experienced by CardSystems," Jones said.

Judy Tenzer, a spokeswoman for New York-based American Express, would not comment on the direct cause for the termination of the processing arrangements with CardSystems.

A spokesman for CardSystems didn't respond to numerous messages left by a reporter today.

Last month, MasterCard International Inc. announced that 13.9 million of its credit card numbers were among the 40 million that may have been accessed by intruders who apparently infiltrated CardSystems' network (see Security breach may have exposed 40M credit cards). A MasterCard spokeswoman said the credit card company's fraud-detection system first became aware of the infiltration in May and the company promptly launched an investigation into the breach.

In a statement yesterday, Purchase, N.Y.-based MasterCard said it will continue to allow CardSystems to provide transaction processing services because the company has worked to improve its security and procedures since the earlier incidents.

"MasterCard has required CardSystems Solutions to develop a detailed plan to bring its systems into compliance with MasterCard security requirements by August 31, 2005," the statement said. "MasterCard is holding weekly meetings with them to monitor progress, and as of today, we are not aware of any deficiencies in its systems that are incapable of being remediated. They have already ceased storing sensitive data in accordance with MasterCard rules.

"However, if CardSystems cannot demonstrate that they are in compliance by that date, their ability to provide services to MasterCard members will be at risk," the statement said.

Transaction processing companies such as CardSystems process transactions for merchants that accept credit cards from retail purchasers. The credit card companies certify the processing companies to provide the services. Merchants that have used CardSystems as their provider will be able to choose another processing company to provide the services once the agreements with Visa and American Express are ended, said Tenzer of American Express.



Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...  

Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...

The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...  

Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...

Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...  

Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...

Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...  

Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...