Attacks/Breaches
1/20/2009
05:08 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Heartland Payment Systems Hit By Data Security Breach

The systems penetrated by a malicious keylogger could result in a data breach that rivals the parent company of TJ Maxx in 2007.

Heartland Payment Systems, a leading payment processing company, reported on Tuesday that its systems had been compromised by malware in 2008.

The data breach could turn out to rival the massive breach reported by TJX in 2007, which affected as many as 94 million credit card accounts. Heartland handles 100 million transactions per month for more than 250,000 businesses. But the company isn't yet ready to disclose the number of credit card accounts affected.

"We found evidence of an intrusion last week and immediately notified federal law enforcement officials as well as the card brands," said Robert H.B. Baldwin Jr., Heartland's president and CFO, in a statement. "We understand that this incident may be the result of a widespread global cyberfraud operation, and we are cooperating closely with the United States Secret Service and Department of Justice."

Heartland was alerted to the breach by reports of suspicious transactions from Visa and MasterCard.

In a phone interview, Baldwin said that the bulk of the exposed data consisted of credit card numbers and expiration dates, and that a subset of the exposed data also included credit card names.

Baldwin said his company couldn't yet reveal an accurate number of exposed accounts. "There are some numbers flying around now that aren't based on any discussion that Heartland has had with anyone," he said. "They are speculation. ...We just discovered this last week. We have been working around the clock to get data out to the public because it's consequential and we think it's important to be transparent on this."

In its statement about the breach, Heartland said that no merchant data, cardholder Social Security numbers, unencrypted personal identification numbers (PIN), addresses, or telephone numbers were exposed.

Baldwin said his company wasn't yet ready to disclose the dates when its network was exposed. "We can say, however, that this is fully contained," he said. "That is both our view and the view of the forensic auditors we brought in to work on this issue."

Baldwin said that the breach was the result of keylogging malware, which covertly captures anything typed on an infected computer, such as user names and passwords.

"There were two elements to it, one of which was a keylogger that got through our firewall," he said. "Then subsequently it was able to propagate a sniffer onto some of the machines in our network. And those are what was actually grabbing the transactions as they floated over our network."

A sniffer is similar in concept to a keylogger, but rather than merely capturing keystrokes, a sniffer captures entire data packets on a network.

Asked whether the data was read remotely from a locally stored file or transmitted to an external site, Baldwin said, "We don't know in what way there was egress or to what extent," he said. "And that's one of the frustrating things about this. We know that a lot of transactions go across our network; we don't know the percentage of transactions that the sniffer was able to grab. And we don't know the percentage of those that the bad guys were able to access."

He added that while investigators considered the possibility that an insider might have been involved, there was no information that suggested any insider involvement.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.