Heartland Breach Expenses Pegged at $140M - So Far
Jaikumar Vijayan writes on ComputerWorld:
The costs to Heartland Payment Systems Inc. from the massive data breach that it disclosed in January 2009 appear to be steadily adding up.
Quarterly financial results released by Heartland last week show that the card payment processor has accrued $139.4 million in breach-related expenses. The figure includes a settlement totaling nearly $60 million with Visa, another of about $3.5 million with American Express and more than $26 million in legal fees.
That total also includes $42.8 million that Heartland has set aside to fund proposed settlements with several other litigants over the breach. One example of what the fund is set up for is Heartland's offer to settle several consumer class action lawsuits against it for $4 million.
So far, Heartland has recovered about $30 million from insurance companies. Even with the updated figures, Heartland so far has spent considerably less than the staggering $250 million that TJX Companies Inc. estimated it would eventually spend to address its massive 2006 data breach.
More
here.
Heartland Data Breach: List of Victims Grows - First Arrests Made
Linda McGlasson writes on BankInfoSecurity.com:
The list of financial institutions impacted by the Heartland Payment Systems (HPY) breach now tops 220. In related news, three men in Florida were arrested earlier this week on multiple charges of credit card fraud, and some of the card numbers they allegedly used are tied to the Heartland hack.
The Leon County, FL. Sheriff's office arrested area residents Tony Acreus, Jeremy Frazier and Timothy Johns, who had allegedly used stolen credit card numbers since November, according to Sgt. Tony Drzewiecki, spokesman for the sheriff's office.
According to the Tallahassee, FL. Democrat, the suspects were running "a very sophisticated and complex criminal enterprise." Law enforcement is investigating how the three men were able to obtain credit card numbers from the Heartland breach, which was first announced on January 20.
Meanwhile, in just over a week, the number of financial institutions that have come forward to say they have been contacted by their credit card companies Visa and MasterCard in relation to the breach has jumped from fewer than 50 to more than 200.
More
here.
Visa Suspends Heartland: A Little Revisionist History?
Evan Schuman writes on StorefrontBacktalk:
Visa struck back at both Heartland on Thursday (March 12), suspending the data breach victim and removing it from Visa’s online list of PCI DSS compliant providers. Visa’s chief enterprise risk officer, Ellen Richey, told banks the news in an E-mail Thursday.
Richey described Heartland’s status as being “in a probationary period,” during which it can still accept payments, assuming it meets various new requirements. Heartland “is now in a probationary period, during which it is subject to a number of risk conditions including more stringent security assessments, monitoring and reporting. Subject to these conditions, Heartland will continue to serve as a processor in the Visa system.”
Heartland issued a statement Friday (March 13) that didn’t address Visa’s suspension, but was clearly prompted by it. “Heartland Payment Systems is pleased to continue our long relationship with Visa. Heartland is cooperating fully with Visa and other card brands and we are committed to having a safe and secure processing environment,” the statement said, which added that Heartland was certified as PCI-DSS compliant in April 2008 and “expects to continue to be assessed as PCI-DSS compliant in the future. We’re undergoing our 2009 PCI-DSS assessment now, which Heartland believes will be complete no later than May 2009 and will result in Heartland, once again, being assessed as PCI-DSS compliant.”
In Richey’s E-mail, she also referenced Heartland’s comments to Visa that it hopes to assessed PCI compliant soon. Heartland “will be relisted once it revalidates its PCI DSS compliance using a Qualified Security Assessor and meets other related compliance conditions.”
More
here.
Heartland on Defense at U.S. Senate Hearing
Eric Chabrow writes on BankInfoSecurity.com:
The ranking member of the Senate Homeland Security and Governmental Affairs Committee told the chief executive of Heartland Payment Systems that she was "astonished" a breach the company's information system lasted for nearly 1½ years without being detected.
At a panel hearing Monday on protecting industry against growing cyber threats, Sen. Susan Collins, R.-Maine, asked Heartland CEO Robert Carr to explain how this delay happened. Carr responded that a breach is usually detected when the processing payer is notified of fraudulent use of cards, and that didn't occur until the end of 2008.
"Isn't there software in the systems to detect such a breach?" Collins asked.
"There is, and the cyber criminals are very good at masking themselves," Carr replied. "To be able to scan systems to determine what the malware is, you have to understand something about the attack vector, and you need to know something about the malware to find it. All of us in the industry go through annual assessments, but the bad guys are working together to get around all those assessment."
Carr told the panel Heartland is taking two major steps to prevent this type of breach to reoccur. Working through the Financial Services Information Sharing and Analysis Center, Heartland and other payment processors established Payments Processing Information Sharing, a forum for sharing information about fraud, threats, vulnerabilities and risk mitigation practices.
More
here.
Banks, Credit Unions Scramble in Wake of Heartland Breach
Jaikumar Vijayan writes on ComputerWorld:
In the first real indication of the scope of the recently disclosed breach at Heartland Payment Systems, banks and credit unions from Washington to Maine have begun to reissue thousands of credit and debit cards over the past few days.
Several have also begun disclosing fraud associated with payments cards that were reported to them by Visa and MasterCard as having been exposed in the breach.
A Pennsylvania law firm today filed the first class action lawsuit related to the breach. The lawsuit was filed by Chimicles & Tikellis LLP of Haverford, PA on behalf of Alicia Cooper, a resident of Woodbury, MN, and others who might have been affected by the breach.
More
here.
More Heartland Details Leak Out (And Some May Be Trying To Leak Back In)
Evan Schuman writes on StorefrontBacktalk:
Details surrounding the Heartland data breach continue to dribble out, with one respected payment systems newsletter reporting that the forensic investigators Heartland brought in were Cybertrust and Neohapsis.
Heartland had tried keeping those names confidential, an effort that was succeeding prior to the Wednesday, Feb. 4 issue of The Nilson Report. That newsletter also quoted from a MasterCard alert, which provided new details about what was taken and when.
“According to a MasterCard alert, this sniffer program stole card numbers and expiration dates from credit and debit cards processed by Heartland from May 14, 2008, through Aug. 19, 2008, as the information entered Heartland’s payment switch,” the Nilson story said. “Only an estimated 5 percent of the stolen card numbers also included names. The malware was likely deactivated when Heartland conducted regular system upgrades as part of its PCI Data Security Standards (PCI DSS) compliance program, although it’s possible that the hackers shut it down to try and avoid being traced.”
In other Heartland news, it seems that officials there may be preparing to backtrack on some of the details they previously disclosed. Since Friday (Jan. 30), Heartland has been promising a written statement to clarify—and apparently back off from—some of the details they revealed in interviews. As of Wednesday (Feb. 4) night, no such statement had materialized, nor were Heartland officials willing to discuss what would be in the statement.
More
here.
Feds Identify Overseas Suspect In Heartland Case
Evan Schuman writes on StorefrontBacktalk:
The Secret Service has identified an overseas suspect in the Heartland data breach case and the matter has been turned over to the U.S. Justice Department, according to someone close to the investigation.
Few additional law enforcement details were immediately available, other than that the government believes it has identified the cyber thief involved, has “pinpointed” that suspect’s location and that it’s outside of North America, the source said.
A little more background on the case was also disclosed Friday (Jan. 23) by Heartland itself. The processor first learned of the breach (when alerted by Visa and Mastercard) in late October/early November, said Heartland spokesman Jason Maloni. Previously, the only comment had been that it had been alerted in late Fall, which could have been as late as Dec. 20.
Maloni also revealed that when the sniffer software had been discovered by Heartland, the application had already been deactivated, presumably by the cyber thieves who had planted it. “It was inactive when we found it,” Maloni said.
More
here.
First Heartland Arrests, With New Twist To Bogus Gift Card Scheme
Evan Schuman writes on StorefrontBacktalk:
U.S. Secret Service and local law enforcement have confirmed the arrests of three Florida men on hundreds of counts of credit card fraud, using cards that police said were made using data stolen from credit card processor Heartland Payment Systems. But the arrests revealed a new kind of gift fraud technique, one where the fraudsters need never use identification and don’t have to pay for the equipment to manufacture bogus cards.
The Tallahassee arrests of Timothy Julsaint Johns, 21, Jeremy A. Frazier, 20, and Tony Acreus, 20, are very far from closing this case. Federal officials are still focusing on an overseas group—apparently in Eastern Europe—that accessed the data from Heartland. It’s not unusual for such groups to then sell the numbers in bulk to various smaller criminal groups, which then turn the data into bogus credit cards and false gift cards and then use those documents to purchase goods, which are then sold for cash.
Just this week, the Secret Service and the FBI issued an alert describing the methodology behind what it termed “a considerable spike in cyber attacks” against e-tailers. That detailed an alert typically means that authorities already are tracking the suspects, who most likely are fully aware they are being tracked. Hence, there’s little investigative risk to issuing an alert to try and minimize additional data theft attempts using the same procedures.
Meanwhile, the full impact of the Heartland breach has not been confirmed, but the number of financial institutions that say that they have been impacted by the Heartland continues to rise, now hitting 221.
More
here.
TJX Hacker to Plead Guilty to Heartland Breach
Kim Zetter writes on Threat Level:
Admitted TJX intruder Albert Gonzalez has entered into a plea agreement on charges that he hacked into Heartland Payment Systems, Hannaford Brothers, 7-Eleven and two other unnamed national retailers.
The revelation comes in a filing made by Gonzalez’s attorney in U.S. District Court in New Jersey, where the Heartland charges were filed in August.
A federal judge on Tuesday officially transferred the New Jersey case to Massachusetts, where Gonzalez is seeking to merge it with two other cases in which he’s already pleaded guilty.
Gonzalez, a former Secret Service informant known by the online nicks “segvec” and “Cumbajohnny,” was charged in New Jersey in August, along with two unnamed Russian hackers. They were accused of stealing more than 130 million debit and credit cards from card-processing company Heartland and the other target companies.
More
here.
Heartland Gets Religion on Security
Ben Worthen writes on the Wall Street Journal "Digits" Blog:
Heartland Payment Systems CEO Bob Carr is an unlikely spokesman for tech security. But that’s what he’s emerging as.
The credit-card processor suffered one of the largest data breaches ever disclosed last year. But rather than taking the time-honored approach of staying quiet and hoping that the negative publicity goes away, Carr is talking openly about what went wrong, the problems with the industry’s security standards, and a new product his company developed to help merchants protect customer data.
Heartland is the middleman in card purchases. When customers swipe their cards at stores, the data on them are transmitted to processors like Heartland, which passes them on to the banks that issued the cards. The company announced in January that a hacker had managed to gain access to this card information for the 100 million transactions it handles each month.
Aside from the scale, the breach stood out from the hundreds of others reported each year because Heartland had recently passed a security audit.
More
here.
Hacker Gonzalez Sentenced to 20 Years for Heartland Breach
Nancy Weil writes on ComputerWorld:
Hacker Albert Gonzalez, who participated in a cybercrime ring that stole tens of millions of credit and debit card numbers, was sentenced to 20 years in prison today.
The sentence imposed by U.S. District Court Judge Douglas P. Woodlock was for Gonzalez's role in a hacking ring that broke into computer networks of Heartland Payment Systems, which processed credit and debit card transactions for Visa and American Express and retailers Hannaford Supermarkets and 7-Eleven.
The sentence will run concurrently with two other 20-year sentences meted out Thursday, also in the U.S. District Court for the District of Massachusetts by a different federal judge, Patti B. Saris. Gonzalez pleaded guilty in all three cases last December, with the U.S. Department of Justice agreeing to seek no more than 25 years in prison in each case, with all sentences to run concurrently.
More
here.
TJX Hacker Charged with Heartland, Hannaford Breaches
Kim Zetter writes on Threat Level:
The constellation of hacks connected to the TJX hacker is growing.
Albert “Segvec” Gonzalez, a former Secret Service informant who is already awaiting trial over his involvement in the TJX hack, has been indicted by a federal grand jury in New Jersey, along with two unnamed Russia-based conspirators, with hacking into Heartland Payment Systems, the New Jersey based card processing company, as well as Hannaford Brothers, 7-Eleven, Inc, and two unnamed national retailers, according to the indictment unsealed Monday.
Prosecutors say they’re investigating other breaches and have not ruled out Gonzalez’s involvement in even more intrusions.
“[The fact that] we’re not seeing a huge array of hackers capable of doing this, but rather a more select group, demonstrates that there is a level of sophistication involved in these hacks,” said Assistant U.S. Attorney Erez Liebermann from the Justice Department’s New Jersey district office.
According to the court document, the hackers stole more than 130 million credit and debit card numbers from Heartland and Hannaford combined, which authorities believe constitutes the largest data breach and identity theft case ever prosecuted in the U.S. But these are just the latest in a string of high-profile breaches that have been connected to Gonzalez.
More
here.
SunTrust Banks Notifies Customers About Heartland Compromise
Linda McGlasson writes on BankInfoSecurity.com:
Sun Trust, a Southern banking corporation, ($179 billion in assets) mailed its Florida customers letters this week regarding SunTrust bank cards that were compromised in the Heartland Payment Systems breach that was first made public on January 20. The bank has 551 branches in the state and a total of 1,694 branches in 12 southern states. The letter informed customers that their personal information may have been compromised.
In the letter, Sun Trust Bank says it is issuing new cards with new numbers. Atlanta, GA-based Sun Trust spokesperson Hugh Suhr says the bank won't reveal how many of its customers were affected. But Suhr says these letters were only some of the notification letters sent to customers. Suhr explains that it took several months to mail out the letters, and the bank began mailing customers when first notified after Visa notified them after the January 20 public notification. Suhr adds Sun Trust first notified customers who were immediately affected by the compromise by fraudulent activity on their cards. No other details were available from the bank.
More
here.
PCI’s Grading System Is Failing
David Taylor writes on StorefrontBacktalk:
For months, retailers and Congress have been attacking retail security standards, but few realize that the problem is not in the standard itself. The problem is a grading system that causes most retailers to be out of compliance most of the time because the rules require 100 percent compliance. How often in school did you score 100 percent?
The system is oriented to forcing retailers to fail and it does this by being utterly insensitive to risk, which is surprising because the financial services industry runs on risk management. So if big finance runs on risk management, why are retail payment security rules running away from it?
At the recent Electronic Transactions Association (ETA) conference, Visa and MasterCard executives again defended the standard against industry and government criticisms that the standard is insufficient to prevent breaches. They cited instances where merchants (e.g., Hannaford) and processors (e.g., Heartland) who claimed to be PCI compliant were actually not compliant during the extended period of time during which the breach occurred. That happened because, from a technical perspective, “companies can fall in and out of compliance,” and because sometimes “the PCI assessment is not comprehensive enough,” according to the executives. From these statements, it sounds like the blame for why a “compliant” company can get breached is due to either technology or the assessors. But I maintain that the culprit in all of this is the grading system used to measure PCI compliance, and it’s time for a change.
More
here.