Government ID, Smart Cards, Identification and Authentication

Heartland Payment Systems breached, campus solutions not impacted

Tuesday, January 20, 2009

Payments processor Heartland Payment Systems has learned it was the victim of a security breach within its processing system in 2008. The company believes the intrusion has been contained. Heartland’s campus solution, the Give Something Back Network, was not impacted by the intrusion.

“We found evidence of an intrusion last week and immediately notified federal law enforcement officials as well as the card brands,” said Robert H.B. Baldwin, Jr., Heartland’s president and chief financial officer. “We understand that this incident may be the result of a widespread global cyber fraud operation, and we are cooperating closely with the United States Secret Service and Department of Justice.”


Hackers somehow placed malicious software into Heartland’s payment system and were able to obtain credit and debit card numbers. No merchant data or cardholder Social Security numbers, personal identification numbers, addresses or telephone numbers were involved in the breach. Nor were any of Heartland’s check management systems; Canadian, payroll, campus solutions or micropayments operations; Give Something Back Network; or the recently acquired Network Services and Chockstone processing platforms.

After being alerted by Visa and MasterCard of suspicious activity surrounding processed card transactions, Heartland enlisted the help of several forensic auditors to conduct a thorough investigation into the matter. Last week, the investigation uncovered malicious software that compromised data that crossed Heartland’s network.

Heartland immediately took a number of steps to further secure its systems. In addition, Heartland will implement a next-generation program designed to flag network anomalies in real-time and enable law enforcement to expeditiously apprehend cyber criminals.

Heartland has created a website - www.2008breach.com - to provide information about this incident and advises cardholders to examine their monthly statements closely and report any suspicious activity to their card issuers. Cardholders are not responsible for unauthorized fraudulent charges made by third parties. [end] 

Tennessee’s Board of Regents has chosen Heartland Payment Systems’ Campus Solutions division to handle financial aid disbursement and refund management through Heartland’s Acceluraid financial aid disbursement product. The contract covers six universities, 13 community colleges and 27 technology centers.

read more »

Heartland Payment Systems Campus Solutions division has recruited 12 higher education districts and campuses totaling 20 different colleges to manage the schools’ financial aid disbursement services utilizing Heartland’s Acceluraid electronic disbursement product.

read more »

Students at Park Hills, Mo.-based Mineral Area College will be receiving their financial aid refunds faster this year through a prepaid card issued by Central National Bank in Oklahoma.

read more »

Heartland Payment Systems Campus Solutions division, in partnership with Bridgeway Solutions, an identification and security solutions provider, has been chosen as one of South Carolina’s preferred system providers for electronic disbursement of financial aid refunds and payments to students.

read more »

Florida students have more payment options thanks to wireless WaveRiders

A new laundry payment and management system at the University of Florida accepts the GatorOne campus ID card as well as credit and debit cards.

read more »

Mobile payment solution provider I Love Velvet announced that it has reached the second level of EMV certification (EMV2) which authorizes PIN and integrated chip payments from debit, credit and smart cards around the world.

read more »