Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Global Payments Breach: Fresh Questions On Timing

Did the Global Payments data breach that exposed at least 1.5 million credit and debit card numbers date back to 2011? As new evidence is reported, Global Payments declines comment on timeframe.

How long did the Global Payments breach that exposed at least 1.5 million credit and debit numbers last?

The answer to that question continues to change. Initially, Visa and MasterCard warned card-issuing banks, in separate alerts released in March, that there had been a series of breaches at an unnamed payment card processor, beginning in mid-January 2012 and lasting for about a month. Thieves obtained credit card account numbers and expiration dates, which could be used to create counterfeit cards.

But earlier this week, Visa and MasterCard warned banks that the breaches, which were first detected in early March, dated back to at least early June 2011, Brian Krebs reported. He said law enforcement sources suspected "Dominican street gangs in and around New York City" of being involved in the attacks.

Despite varying reports regarding the duration of the breach, Global Payments--named as the affected payment card processor in late March--released a statement this week saying that it's not responsible for the changing perceptions. "We have not publicly communicated any time periods and there is a full investigation underway. It would be premature and inappropriate for us to speak to or confirm any timeframes until the investigation is complete," read a statement posted to a website created by Global Payments.

[ Is your IT team proactive enough about security? Read more at Why Security Teams Need To Play More Offense. ]

"The company sincerely apologizes for any concern this has caused, and please know that we continue to work with industry third parties, regulators and law enforcement to assist in all efforts to minimize cardholder and customer impact," it said. (In an ironic twist, the site disables the browser's ability to select or copy any text on the page.)

Global Payments this week confirmed that fraud alerts for up to 1.5 million card numbers had been issued by the affected card brands, which are all in North America. "In any matter of this nature, the card brands cast a wide net to protect consumers, and we supply as much information as possible to assist over the course of the investigation," said Global Payments. But it warned that the count of card numbers "taken or stolen from our network" may continue to increase as the related investigation progresses.

Global Payments, which was PCI-compliant before the breach, confirmed on March 30, 2012, that it had discovered the breach and "self-reported this incident" in early March, meaning it notified the card brands--American Express, MasterCard, and Visa--for which it processes transactions.

Shortly thereafter, Visa removed the company from its list of PCI-compliant service providers and canceled its security seal of approval, although that doesn't preclude Global Payments from processing transactions for Visa card brands.

MasterCard, meanwhile, said last month that it was awaiting the results of an investigation into the breach before deciding what next steps to take. But Wednesday, MasterCard said that it too had removed Global Processing from its list of approved vendors.

Global Payments confirmed the changes in the statement it released this week. "Some card brands removed us from their list of PCI compliant service providers. They have requested we revalidate our PCI status, which we will do following the current investigation. We anticipate that we will be reinstated to those lists at the conclusion of the revalidation and any required remediation," it said.

Besides PCI problems, Global Payments may also face a shareholder lawsuit. On March 30, law firm Robbins Umeda, which specializes in securities litigation, released a statement saying that it was "investigating possible breaches of fiduciary duty and other violations of the law by certain officers and directors at Global Payments."

The firm said it wanted to discover "whether officers and directors of Global Payments, a credit card transaction processing company, breached their fiduciary duties to shareholders by failing to maintain adequate data security systems and by making improper statements about the company's business and security infrastructure."

Global Payments processed $120 billion in MasterCard and Visa transactions for merchants in 2011. It's the seventh-largest such merchant processor, according to the Nilson Report. But the company has seen its stock price plunge by 11% in the last three months.

Put an end to insider theft and accidental data disclosure with network and host controls--and don't forget to keep employees on their toes. Also in the new, all-digital Stop Data Leaks issue of Dark Reading: Why security must be everyone's concern, and lessons learned from the Global Payments breach. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "This is the last time we hire Game of Thrones Security"
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0242
PUBLISHED: 2019-12-09
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
CVE-2015-3424
PUBLISHED: 2019-12-09
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
CVE-2015-3425
PUBLISHED: 2019-12-09
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.
CVE-2015-7892
PUBLISHED: 2019-12-09
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.
CVE-2015-0841
PUBLISHED: 2019-12-09
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.