Thursday, February 05, 2009

More Heartland Details Leak Out (And Some May Be Trying To Leak Back In)

Evan Schuman writes on StorefrontBacktalk:

Details surrounding the Heartland data breach continue to dribble out, with one respected payment systems newsletter reporting that the forensic investigators Heartland brought in were Cybertrust and Neohapsis.

Heartland had tried keeping those names confidential, an effort that was succeeding prior to the Wednesday, Feb. 4 issue of The Nilson Report. That newsletter also quoted from a MasterCard alert, which provided new details about what was taken and when.

“According to a MasterCard alert, this sniffer program stole card numbers and expiration dates from credit and debit cards processed by Heartland from May 14, 2008, through Aug. 19, 2008, as the information entered Heartland’s payment switch,” the Nilson story said. “Only an estimated 5 percent of the stolen card numbers also included names. The malware was likely deactivated when Heartland conducted regular system upgrades as part of its PCI Data Security Standards (PCI DSS) compliance program, although it’s possible that the hackers shut it down to try and avoid being traced.”

In other Heartland news, it seems that officials there may be preparing to backtrack on some of the details they previously disclosed. Since Friday (Jan. 30), Heartland has been promising a written statement to clarify—and apparently back off from—some of the details they revealed in interviews. As of Wednesday (Feb. 4) night, no such statement had materialized, nor were Heartland officials willing to discuss what would be in the statement.

More here.

Friday, March 13, 2009

Visa Suspends Heartland: A Little Revisionist History?

Evan Schuman writes on StorefrontBacktalk:

Visa struck back at both Heartland on Thursday (March 12), suspending the data breach victim and removing it from Visa’s online list of PCI DSS compliant providers. Visa’s chief enterprise risk officer, Ellen Richey, told banks the news in an E-mail Thursday.

Richey described Heartland’s status as being “in a probationary period,” during which it can still accept payments, assuming it meets various new requirements. Heartland “is now in a probationary period, during which it is subject to a number of risk conditions including more stringent security assessments, monitoring and reporting. Subject to these conditions, Heartland will continue to serve as a processor in the Visa system.”

Heartland issued a statement Friday (March 13) that didn’t address Visa’s suspension, but was clearly prompted by it. “Heartland Payment Systems is pleased to continue our long relationship with Visa. Heartland is cooperating fully with Visa and other card brands and we are committed to having a safe and secure processing environment,” the statement said, which added that Heartland was certified as PCI-DSS compliant in April 2008 and “expects to continue to be assessed as PCI-DSS compliant in the future. We’re undergoing our 2009 PCI-DSS assessment now, which Heartland believes will be complete no later than May 2009 and will result in Heartland, once again, being assessed as PCI-DSS compliant.”

In Richey’s E-mail, she also referenced Heartland’s comments to Visa that it hopes to assessed PCI compliant soon. Heartland “will be relisted once it revalidates its PCI DSS compliance using a Qualified Security Assessor and meets other related compliance conditions.”

More here.

Monday, May 10, 2010

Heartland Breach Expenses Pegged at $140M - So Far

Jaikumar Vijayan writes on ComputerWorld:

The costs to Heartland Payment Systems Inc. from the massive data breach that it disclosed in January 2009 appear to be steadily adding up.

Quarterly financial results released by Heartland last week show that the card payment processor has accrued $139.4 million in breach-related expenses. The figure includes a settlement totaling nearly $60 million with Visa, another of about $3.5 million with American Express and more than $26 million in legal fees.

That total also includes $42.8 million that Heartland has set aside to fund proposed settlements with several other litigants over the breach. One example of what the fund is set up for is Heartland's offer to settle several consumer class action lawsuits against it for $4 million.

So far, Heartland has recovered about $30 million from insurance companies. Even with the updated figures, Heartland so far has spent considerably less than the staggering $250 million that TJX Companies Inc. estimated it would eventually spend to address its massive 2006 data breach.

More here.

Monday, September 14, 2009

Heartland on Defense at U.S. Senate Hearing

Eric Chabrow writes on BankInfoSecurity.com:


The ranking member of the Senate Homeland Security and Governmental Affairs Committee told the chief executive of Heartland Payment Systems that she was "astonished" a breach the company's information system lasted for nearly 1½ years without being detected.

At a panel hearing Monday on protecting industry against growing cyber threats, Sen. Susan Collins, R.-Maine, asked Heartland CEO Robert Carr to explain how this delay happened. Carr responded that a breach is usually detected when the processing payer is notified of fraudulent use of cards, and that didn't occur until the end of 2008.

"Isn't there software in the systems to detect such a breach?" Collins asked.

"There is, and the cyber criminals are very good at masking themselves," Carr replied. "To be able to scan systems to determine what the malware is, you have to understand something about the attack vector, and you need to know something about the malware to find it. All of us in the industry go through annual assessments, but the bad guys are working together to get around all those assessment."

Carr told the panel Heartland is taking two major steps to prevent this type of breach to reoccur. Working through the Financial Services Information Sharing and Analysis Center, Heartland and other payment processors established Payments Processing Information Sharing, a forum for sharing information about fraud, threats, vulnerabilities and risk mitigation practices.

More here.

Thursday, June 18, 2009

Heartland Gets Religion on Security

Ben Worthen writes on the Wall Street Journal "Digits" Blog:

Heartland Payment Systems CEO Bob Carr is an unlikely spokesman for tech security. But that’s what he’s emerging as.

The credit-card processor suffered one of the largest data breaches ever disclosed last year. But rather than taking the time-honored approach of staying quiet and hoping that the negative publicity goes away, Carr is talking openly about what went wrong, the problems with the industry’s security standards, and a new product his company developed to help merchants protect customer data.

Heartland is the middleman in card purchases. When customers swipe their cards at stores, the data on them are transmitted to processors like Heartland, which passes them on to the banks that issued the cards. The company announced in January that a hacker had managed to gain access to this card information for the 100 million transactions it handles each month.

Aside from the scale, the breach stood out from the hundreds of others reported each year because Heartland had recently passed a security audit.

More here.

Saturday, February 14, 2009

First Heartland Arrests, With New Twist To Bogus Gift Card Scheme

Evan Schuman writes on StorefrontBacktalk:

U.S. Secret Service and local law enforcement have confirmed the arrests of three Florida men on hundreds of counts of credit card fraud, using cards that police said were made using data stolen from credit card processor Heartland Payment Systems. But the arrests revealed a new kind of gift fraud technique, one where the fraudsters need never use identification and don’t have to pay for the equipment to manufacture bogus cards.

The Tallahassee arrests of Timothy Julsaint Johns, 21, Jeremy A. Frazier, 20, and Tony Acreus, 20, are very far from closing this case. Federal officials are still focusing on an overseas group—apparently in Eastern Europe—that accessed the data from Heartland. It’s not unusual for such groups to then sell the numbers in bulk to various smaller criminal groups, which then turn the data into bogus credit cards and false gift cards and then use those documents to purchase goods, which are then sold for cash.

Just this week, the Secret Service and the FBI issued an alert describing the methodology behind what it termed “a considerable spike in cyber attacks” against e-tailers. That detailed an alert typically means that authorities already are tracking the suspects, who most likely are fully aware they are being tracked. Hence, there’s little investigative risk to issuing an alert to try and minimize additional data theft attempts using the same procedures.

Meanwhile, the full impact of the Heartland breach has not been confirmed, but the number of financial institutions that say that they have been impacted by the Heartland continues to rise, now hitting 221.

More here.

Wednesday, September 08, 2010

Report: RBS WorldPay Hacker Gets Four Years' Probation

Robert McMillan writes on PC World:

The mastermind behind one of the biggest hacking paydays in history has been sentenced to four years' probation and an US$8.9 million fine, according to published reports.

Victor Pleshchuk, 28, was sentenced to four years' probation on Wednesday, according to Bloomberg News. He is considered the leader of a group of criminals who organized a 2008 precision strike on RBS WorldPay, the payment processing division of the Royal Bank of Scotland.

In addition to the reduced sentence of probation, Pleshchuk must also pay back more than 275 million rubles ($8.9 million) to RBS WorldPay, Bloomberg reports.

Russia is trying to fight a reputation for being soft on cybercrime, but this light sentence won't do much to change that perception. Security experts say that Pleshchuk falls into the same category of highly accomplished cybercriminals as Albert Gonzalez, best known for hacking into retailer TJX Companies and the Heartland Payment Systems payment processing network. In March, Gonzalez was sentenced to 20 years in federal prison.

More here.

Friday, February 13, 2009

Heartland Data Breach: List of Victims Grows - First Arrests Made

Linda McGlasson writes on BankInfoSecurity.com:

The list of financial institutions impacted by the Heartland Payment Systems (HPY) breach now tops 220. In related news, three men in Florida were arrested earlier this week on multiple charges of credit card fraud, and some of the card numbers they allegedly used are tied to the Heartland hack.

The Leon County, FL. Sheriff's office arrested area residents Tony Acreus, Jeremy Frazier and Timothy Johns, who had allegedly used stolen credit card numbers since November, according to Sgt. Tony Drzewiecki, spokesman for the sheriff's office.

According to the Tallahassee, FL. Democrat, the suspects were running "a very sophisticated and complex criminal enterprise." Law enforcement is investigating how the three men were able to obtain credit card numbers from the Heartland breach, which was first announced on January 20.

Meanwhile, in just over a week, the number of financial institutions that have come forward to say they have been contacted by their credit card companies Visa and MasterCard in relation to the breach has jumped from fewer than 50 to more than 200.

More here.

Tuesday, December 08, 2009

TJX Hacker to Plead Guilty to Heartland Breach

Kim Zetter writes on Threat Level:

Admitted TJX intruder Albert Gonzalez has entered into a plea agreement on charges that he hacked into Heartland Payment Systems, Hannaford Brothers, 7-Eleven and two other unnamed national retailers.

The revelation comes in a filing made by Gonzalez’s attorney in U.S. District Court in New Jersey, where the Heartland charges were filed in August.

A federal judge on Tuesday officially transferred the New Jersey case to Massachusetts, where Gonzalez is seeking to merge it with two other cases in which he’s already pleaded guilty.

Gonzalez, a former Secret Service informant known by the online nicks “segvec” and “Cumbajohnny,” was charged in New Jersey in August, along with two unnamed Russian hackers. They were accused of stealing more than 130 million debit and credit cards from card-processing company Heartland and the other target companies.

More here.

Thursday, October 08, 2009

Cyber Thieves Find Workplace Networks Are Easy Pickings

Byron Acohido writes on USA Today:

It took only a modicum of skill for a cybergang to steal 94 million credit and debit card payment records from the TJX retail chain — and follow that up by hauling in 130 million records from credit card processor Heartland Payment Systems.

Court records reveal that those record-setting break-ins were almost too easy. Even more surprising: The thieves were able to take their sweet time extracting the data, in each case going undetected for more than a year.

What happened to TJX and Heartland was not unusual. And details unveiled in the prosecution of gang members involved in both thefts have shed fresh light on a business truism demanding more scrutiny: Workplace networks have turned out to be much more porous and difficult to defend than anyone ever anticipated.

Overly complex IT systems are producing endless opportunities for cyberthieves, who need only to master simple hacking techniques to get their hands on sensitive data. The result: Data breaches continue to plague companies, hospitals, universities and government agencies — any entity that collects data and conducts business on a digital network.

More here.

Thursday, August 20, 2009

Gonzalez's Lawyer to Contend He Was Not The Kingpin of Heartland, Hannaford Breaches

Jaikumar Vijayan writes in ComputerWorld:

The attorney for Albert Gonzalez, the man indicted Monday on charges related to the massive data thefts at Heartland Payment Systems and four other retailers, claims it was another member of Gonzalez's gang who was the real leader of the heists.

In an interview with the New York Times, Gonzalez's lawyer, Rene Palomino, said he was prepared to argue that the person who organized the break-ins at Heartland and elsewhere was really Damon Patrick Toey of Miami.

Palomino said Toey is the individual who was identified only as "P.T," an unindicted co-conspirator in Monday's indictment papers. Palomino also told the Times that one of the unnamed Russian conspirators mentioned in the indictment is an individual named Maksym Yastremskiy, who is currently serving a 30-year sentence in a Turkish prison.

Toey was one of 11 individuals, including Gonzalez, who were indicted last year on charges related to the data thefts at TJX Companies Inc., Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.

More here.

Monday, August 17, 2009

TJX Hacker Charged with Heartland, Hannaford Breaches

Kim Zetter writes on Threat Level:

The constellation of hacks connected to the TJX hacker is growing.

Albert “Segvec” Gonzalez, a former Secret Service informant who is already awaiting trial over his involvement in the TJX hack, has been indicted by a federal grand jury in New Jersey, along with two unnamed Russia-based conspirators, with hacking into Heartland Payment Systems, the New Jersey based card processing company, as well as Hannaford Brothers, 7-Eleven, Inc, and two unnamed national retailers, according to the indictment unsealed Monday.

Prosecutors say they’re investigating other breaches and have not ruled out Gonzalez’s involvement in even more intrusions.

“[The fact that] we’re not seeing a huge array of hackers capable of doing this, but rather a more select group, demonstrates that there is a level of sophistication involved in these hacks,” said Assistant U.S. Attorney Erez Liebermann from the Justice Department’s New Jersey district office.

According to the court document, the hackers stole more than 130 million credit and debit card numbers from Heartland and Hannaford combined, which authorities believe constitutes the largest data breach and identity theft case ever prosecuted in the U.S. But these are just the latest in a string of high-profile breaches that have been connected to Gonzalez.

More here.

Wednesday, March 11, 2009

Motorola Security Chief: 'Outlaws and Terrorists' Amplify Security Challenges

Ellen Messmer writes on NetworkWorld:

The current era is marked by tumultuous change, high speed and huge danger, said Motorola's corporate security officer Bill Boni, based on his perspective of more than 30 years as a security practitioner.

"Outlaws and terrorists are now positioned to compete -- and sometimes win -- against nation states," said Boni in his presentation Monday at the Infosec conference. Criminals are coming together to "leverage the Internet," sometimes more effectively than the good guys do, he said. Add in the global economic crisis, and Boni said the current era is the most dangerous he can recall.

"I've never seen the world this unstable and dangerous," said Boni, who recently was put in charge of Motorola's physical security as well as information security. From terrorist attacks such as the devastating attack on a hotel in Mumbai to infiltration of payment card networks, as occurred at Heartland Payment Systems, it's clear "there's unprecedented risk to organizations and people," Boni noted.

For security professionals trying to protect corporate assets, there is a need to respond quickly to changes to help companies survive in these trying times, he pointed out. "Speed is the mega-trend facing the organization," Boni said.

More here.

Thursday, August 20, 2009

In Gonzalez Hacking Case, a High-Stakes Fight Over a Ukranian's Laptop

Kim Zetter writes on Threat Level:

When Turkish police arrested Maksym “Maksik” Yastremskiy — a Ukrainian wholesaler of stolen identity data — in July 2007, they didn’t just collar one of the most-wanted cybercriminals in the world. They also got a trove of evidence about Yastremskiy’s buyers and suppliers, all locked in an encrypted vault on his laptop computer.

Now federal prosecutors are hoping to introduce a copy of Yastremskiy’s files in its case against accused hacker Albert “Segvec” Gonzales. Chat logs and other information on the disk allegedly show that Gonzalez was Yastremskiy’s major supplier of credit and debit card numbers.

But Gonzalez’s attorney is fighting to keep the data, and similar information seized from a server in Latvia, far away from the New York court room where Gonzalez is scheduled to stand trial next month on the first of three federal indictments. The argument unfolding over the disks illustrates the challenges and controversies of using electronic evidence gathered in foreign jurisdictions, and sheds more light on the unusual methods used to investigate what authorities have called the largest identity theft case in U.S. history.

Gonzalez and his co-conspirators staged high-profile breaches at TJX, Heartland Payment Systems, Dave & Buster’s and other retailers and payment processors.

One notable revelation in the government’s own filings [.pdf] is that Yastremskiy’s arrest did not mark the first time the Secret Service gained access to his computer files. On June 14, 2006 the Secret Service worked with local authorities to conduct a “sneak-and-peek” search of Yastremskiy’s laptop while he was traveling through Dubai, in the United Arab Emirates. The agency secretly obtained a copy of the man’s hard drive in the search.

More here.

Friday, March 26, 2010

Hacker Gonzalez Sentenced to 20 Years for Heartland Breach

Nancy Weil writes on ComputerWorld:

Hacker Albert Gonzalez, who participated in a cybercrime ring that stole tens of millions of credit and debit card numbers, was sentenced to 20 years in prison today.

The sentence imposed by U.S. District Court Judge Douglas P. Woodlock was for Gonzalez's role in a hacking ring that broke into computer networks of Heartland Payment Systems, which processed credit and debit card transactions for Visa and American Express and retailers Hannaford Supermarkets and 7-Eleven.

The sentence will run concurrently with two other 20-year sentences meted out Thursday, also in the U.S. District Court for the District of Massachusetts by a different federal judge, Patti B. Saris. Gonzalez pleaded guilty in all three cases last December, with the U.S. Department of Justice agreeing to seek no more than 25 years in prison in each case, with all sentences to run concurrently.

More here.

Tuesday, January 27, 2009

Banks, Credit Unions Scramble in Wake of Heartland Breach

Jaikumar Vijayan writes on ComputerWorld:

In the first real indication of the scope of the recently disclosed breach at Heartland Payment Systems, banks and credit unions from Washington to Maine have begun to reissue thousands of credit and debit cards over the past few days.

Several have also begun disclosing fraud associated with payments cards that were reported to them by Visa and MasterCard as having been exposed in the breach.

A Pennsylvania law firm today filed the first class action lawsuit related to the breach. The lawsuit was filed by Chimicles & Tikellis LLP of Haverford, PA on behalf of Alicia Cooper, a resident of Woodbury, MN, and others who might have been affected by the breach.

More here.

Monday, August 24, 2009

Credit, Debit Card Industry at Odds Over Security

A Reuters newswire article by Ross Kerber, via MSNBC, reports that:

Fresh details of large-scale cyber attacks against data processor Heartland Payment Systems and supermarket chain Hannaford Brothers show the challenges facing the efforts of the United States credit-card industry to upgrade security measures.

While both companies say their computer networks met the tough new standards meant to prevent data breaches, Visa said Heartland at least may have let its guard down.

The positions reflect broader disagreements in the industry, as squabbling between merchants and financial firms over technology and the cost of systems upgrades continues to impede progress, said Robert Vamosi, an analyst for California consulting firm Javelin Strategy & Research.

"They both need to fight fraud and they are fighting each other," he said.

The financial stakes are getting higher. Fraud involving credit and debit cards reached $22 billion last year, up from $19 billion in 2007, according to Javelin.

More here.

Saturday, April 25, 2009

SunTrust Banks Notifies Customers About Heartland Compromise

Linda McGlasson writes on BankInfoSecurity.com:

Sun Trust, a Southern banking corporation, ($179 billion in assets) mailed its Florida customers letters this week regarding SunTrust bank cards that were compromised in the Heartland Payment Systems breach that was first made public on January 20. The bank has 551 branches in the state and a total of 1,694 branches in 12 southern states. The letter informed customers that their personal information may have been compromised.

In the letter, Sun Trust Bank says it is issuing new cards with new numbers. Atlanta, GA-based Sun Trust spokesperson Hugh Suhr says the bank won't reveal how many of its customers were affected. But Suhr says these letters were only some of the notification letters sent to customers. Suhr explains that it took several months to mail out the letters, and the bank began mailing customers when first notified after Visa notified them after the January 20 public notification. Suhr adds Sun Trust first notified customers who were immediately affected by the compromise by fraudulent activity on their cards. No other details were available from the bank.

More here.

Friday, March 19, 2010

Unprecedented 25-Year Sentence Sought for TJX Hacker

Kevin Poulsen writes on Threat Level:

Computer hacker Albert Gonzalez deserves a quarter-century behind bars for leading a gang of cyberthieves who stole tens of millions of credit and debit card numbers from a transaction processor and several giant retail chains, federal prosecutors argued in a court filing Thursday night.

“[T]he sentences would be the longest ever imposed in an identity theft case and among the longest imposed for a financial crime, which is appropriate because Gonzalez was at the center of the largest and most costly series of identity thefts in the nation’s history,” wrote Boston-based assistant U.S. attorney Stephen Heymann. “He knowingly victimized a group of people whose population exceeded that of many major cities and some states.”

The government also disputed a defense claim that Gonzalez suffers from Asperger’s disorder, a mild form of autism that was grounds for a slightly reduced sentence in a previous hacking prosecution.

Gonzalez, 28, is set for sentencing next week on three indictments covering virtually every headline-making bank-card theft in recent years, including intrusions at TJX, DSW Shoe Warehouse, Office Max, Hannaford Brothers, 7-Eleven, and Heartland Payment Systems, which alone exposed magstripe data on 130 million credit and debit cards. He performed the intrusions while an informant for the Secret Service.

More here.

Thursday, August 20, 2009

Stolen Credit Card Data Goes for Cheap on Cyber-Black Market

Brian Prince writes on eWeek:

The black market economy of the cyber-world is always busy, especially in an age of massive data breaches like the ones that occurred at Heartland Payment Systems and Hannaford Brothers.

According to research from Kaspersky Lab posted Aug. 17, U.S. credit cards are not worth as much as you might think. While analyzing malware, Kaspersky Lab virus analyst Dmitry Bestuzhev came across a Website with pricing information for the credit cards swiped by cyber-crooks. The highest prices belonged to German credit cards, which sold for $6 (USD) a piece. U.S. Visa cards sold for $2.

"It's certainly difficult to say how many sites like this there are now," Bestuzhev said. "I believe it's not very many because the bad guys don't need to largely market their business. Their customers know them already and if there is a new one, it is passed along by others. It's a kind of club where cyber-criminals 'know each other' in terms of online life."

They also provide customer service—there was technical support available in German and English.

More here.