Government ID, Smart Cards, Identification and Authentication

Card Compromise Statistics Prove that PCI DSS Compliance Protects Businesses and Customers

Wednesday, March 11, 2009

Through October 29, 2008, Trustwave’s forensics practice has investigated 443 cases of cardholder data compromise. The information contained within this article is the culmination of almost seven years of card compromise investigations.

Key Developments in 2008: The Theft of Cardholder Data in Transit

In 2008, the most notable development in payment card compromises is the theft of cardholder data at rest (stationary on a system component) to its theft in transit (moving through a system). Trustwave experts have noted that attackers, are stealing data in real-time by eavesdropping on a certain device and stealing the data as it passes to or through a particular system rather than stealing data that is stored on that system.

One example of this is an attackers’ use of unauthorized applications—referred to as malware—that steals cardholder data from a computer’s Random Access Memory. What’s perhaps most unsettling about the trend is that a merchant can use a payment application that complies with the Payment Application Data Security Standard (PA-DSS) or Visa’s Payment Application Best Practices (PABP), but still fall victim to a compromise.

There are 750 words in the rest of this article …

Library Access Required

Library subscribers have access to the full archives of more than 10,000 original news items and feature articles published by AVISIAN’s suite of ID technology publications (ContactlessNews.com, CR80News.com, DigitalIDNews.com, FIPS201.com, NFCNews.com, RFIDNews.org, SecureIDNews.com, and ThirdFactor.com).

For just $49, you receive unlimited password-protected access to content on all of AVISIAN’s sites for an entire year. Your subscription helps fund the continued creation of independent, insightful content. Find out more.

Sign in as a Subscriber

If you are already a subscriber, you may sign in now. Enter your Email Address and Password and click Sign In.

Email Address →
Password →
Action →

If you have forgotten your password, enter just your Email Address, and click Send Password.

Email Address →
Action →

Oracle has released a new version of Oracle Retail Point-of-Service that aims to increase security, operational efficiency and functionality in part by integrating biometrics.

Oracle partnered with DigitalPersonal to add integrated biometrics to the POS package. Users of the software will login using their fingerprint, which will replace the need for PINs or passwords. This feature intends to reduce fraud by eliminating the possibility of unauthorized employees using a manager ID or swipe card to access the POS and approve overrides.

read more »

More than three-quarters POS terminals enabled

Adoption of EMV as the universal payment standard gained further traction in 2011, with official figures revealing that more than 42% of all payment cards and nearly 76% of all terminals in circulation globally are based on EMV technology. These numbers, however, do not reflect the U.S.

read more »

United Arab Emirates (UAE) travelers prefer making payments via mobile rather than using cash or credit card, according to a recent survey commissioned by travel technology and transaction processor Amadeus.

read more »

Superdrug, one of Britain’s largest beauty and health retailers, has introduced contactless payment for its in-store customers, according to Retail Gazette.

Created by Streamline and Visa Europe, the contactless system will enable customers to make payments of up to £15 (approx. USD $23) by simply waving their contactless bank card at the more than 50 participating Superdrug stores in London and Liverpool.

read more »

Barclaycard Global Commercial Payments has announced the launch of the UK’s first contactless corporate payment card.

All new cardholders can make purchases of £15 or under by simply holding the card over a reader. Aside from greater convenience for customers, the cards enable businesses to track all small transactions that until now were typically made with cash.

read more »

GlobalPlatform extended its compliance program for validation that secure products meets the requirements of GlobalPlatform’s new basic financial configuration.

This advancement meets industry demand for a qualification process which confirms that a financial card product operates within the payment landscape.

read more »