Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, April 2, 2012

Up to 1.5M credit card numbers stolen from Global Payments

On Friday, we heard the news that payments processor Global Payments was hit with a massive security breach involving MasterCard and Visa cardholders. At the time it was unclear the reach of the security issue, which was being investigated by the U.S. Secret Service. Tonight, Global Payments reports that those cards affected in the breach processing system were confined to North America and up to 1.5 million card numbers may have been exported. Visa had originally pegged that number at around 50,000 cards stolen.



The company said it believes the incident has been contained and it is working with third parties to investigate the incident and minimize impact on customers, although it did not describe those efforts.

"We are making rapid progress toward bringing this issue to a close," CEO Paul Garcia said in the statement.

MasterCard and Visa have already sent out notices to their customers who may have been affected, informing them of the possible risk.

As a result of the breach, Visa removed Global Payments from its list of approved service providers. Visa told The Wall Street Journal (subscription required) that the move was in response to "Global Payments' reported unauthorized access." Visa said it has invited Global Payments to re-apply for validation by submitting evidence that its security is in compliance with Visa's standards.

Global Payments is scheduled to hold a conference call at 5 a.m. PT Monday to provide further information on the incident.
0 comments

Monday, March 19, 2012

India: 112 government sites hacked

There was embarrassing news for the Indian government this week as one of its ministers was forced to admit that over 100 of its web sites had been hacked in just three months at the beginning of the year, including that of a state-owned telecoms company.

Minister for communications and IT, Sachin Pilot, revealed in a written reply in parliament that a total of 112 sites had been compromised from December 2011 to February 2012, Indian news service IANS reported.

Many of the sites hacked appeared to be those of government agencies in various regions of the sprawling country including Madhya Pradesh, Rajasthan and Kerala, the report continued.



The website of state-owned telecom operator Bharat Sanchar Nigam Limited (BSNL) was attacked for the fourth time on December 4, by a Pakistani hacker group called “H4tr!ck.” In fact, at least 22 websites under the Rajasthan state government were destroyed by hackers, mostly from Pakistan, in February. They deleted or stole data from the various sites of important departments including technical education, college education and finance, according to sources cited by India Times.

State government websites have very poor security practices. For example, most government websites in Rajasthan run on single server. This means if a hacker exploits a single vulnerability in any of the websites, he or she can compromise the other websites as well by taking control of the whole server. To make matters worse, when data is deleted, backups are simply uploaded back to website. Given that the sites are attacked again and again, it would appear that nothing is being done to actually fix the security issues.

This can’t go on forever: India is going to have to tap some of the bright minds in IT and get its act together. After all, India is the world’s second most populous country: it’s simply a question of putting the right people in the right positions.
0 comments