Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

MasterCard security breach may affect 40 MILLION cardholders

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
UpInArms Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:10 PM
Original message
MasterCard security breach may affect 40 MILLION cardholders
http://www.marketwatch.com/news/newsfinder/pulseone.asp?dateid=38520.7083127199-836905396&siteID=mktw&scid=0&doctype=806&

SAN FRANCISCO (MarketWatch) -- MasterCard International said late Friday that a security breach at a third-party payment processor has exposed more than 40 million cardholders to potential fraud. MasterCard said it discovered the breach at Tucson, Ariz.-based CardSystems Solutions Inc., which allowed an unauthorized individual to infiltrate the firm's network and access cardholder data. MasterCard has told its customer banks about specific card accounts that may have been compromised, so they can take the appropriate measures to protect their cardholders, the company added. Almost 14 million of the cards affected are MasterCard branded.

...very short newsblurb...
Printer Friendly | Permalink |  | Top
Dickie Flatt Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:12 PM
Response to Original message
1. Whoops!
Printer Friendly | Permalink |  | Top
 
Roland99 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:17 PM
Response to Original message
2. Beautiful. My personal bankcard and my company CC are both MC.
Printer Friendly | Permalink |  | Top
 
AngryOldDem Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:44 PM
Response to Reply #2
15. Can't say I'm surprised
We got a nice love note from Citicorp, which holds our mortgage, this week, that said our financial information may have been breached because of a security lapse, so sorry. I kind of figured the credit card end of this would appear sooner or later.

Gives me a whole new reason to look forward to seeing the mailman now.
Printer Friendly | Permalink |  | Top
 
AuntiBush Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:42 AM
Response to Reply #2
65. Same Here. Join the "My Identity Is God Knows Where Club"
Know exactly how you feel. First it as Visa, now this.
Printer Friendly | Permalink |  | Top
 
lovuian Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:20 PM
Response to Original message
3. 40 Million WHOAH!!! this is BIG TIME fraud!!! The credit card
business is on its way out!!!
Printer Friendly | Permalink |  | Top
 
Karenina Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:21 PM
Response to Original message
4. OK, kids...
This is REEEEE-DICULOUS. Absolutely r-i-d-i-c-u-l-o-u-s. I have a request that any yung'un been following these "breaches of security" from NEXIS/LEXIS/SAIC/CITI/ALPHABETSOUPWITHOUTENDAMEN who has better computer skills than yer old Tante (now THERE'S a hard one! :crazy:)
PLEASE POST ON THIS THREAD A LIST WITH LINKS OF DATA DECLARED "LOST" in the last 9 months. Can you spell "pattern of behaviour," boys and girls? I KNEW you could! Here's a harder one: "identity theft."
Printer Friendly | Permalink |  | Top
 
tanyev Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:23 PM
Response to Reply #4
5. Egg-zackly.
That's my question. How many incidents does that make now in the last few months? Waaaay too many.
Printer Friendly | Permalink |  | Top
 
Democrats_win Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:27 PM
Response to Reply #5
6. dupe
Edited on Fri Jun-17-05 04:28 PM by Democrats_win
Printer Friendly | Permalink |  | Top
 
Democrats_win Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:27 PM
Response to Reply #5
7. Follow the money and you'll find a golden parachute for a CEO.
Printer Friendly | Permalink |  | Top
 
SpiralHawk Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:28 PM
Response to Reply #4
8. Well, there's identity theft, and then there's Presidential theft
Sorry suckin state of affairs either which way
Printer Friendly | Permalink |  | Top
 
Karenina Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:23 PM
Response to Reply #8
18. Indeed it is.

Printer Friendly | Permalink |  | Top
 
UpInArms Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:52 PM
Response to Reply #4
23. Results 1 - 10 of about 262,000 for consumers compromised data lost.
Printer Friendly | Permalink |  | Top
 
Algomas Donating Member (576 posts) Send PM | Profile | Ignore Sat Jun-18-05 04:16 AM
Response to Reply #4
37. If the government don't like what I say...
They can make all my money go away. This is a very, very, very black op.
Printer Friendly | Permalink |  | Top
 
Ms. Toad Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 12:31 PM
Response to Reply #4
46. Well...I'm not so sure it is a new pattern of behavior
rather than new reporting of an old pattern. There are a number of relatively new laws that require reporting of breaches that companies were never required to report before.

California's bill "requires that an organization disclose any security breach of unencrypted personal information to the affected California residents. The actual breach does not need to occur in the state of California for the law to apply. As long as a company has customers in California they are required to notify them. Personal information is defined in the bill as the individual's first name and last name combined with one or more of the following portions of data when either the name or the data is not encrypted:

* Social Security Number
* Drivers license number or California ID number
* Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual's financial account"

http://www.guarded.net/solutions_reg_compliance_california.html

Doesn't mean it wasn't happening just as regularly before - just that companies could legally keep it secret. If this breach did not involve data belonging to California residents (or residents of other states that have passed copycat laws), I expect we would not have heard about it (or NEXIS/LEXIS/SAIC/CITI etc.)

(Note - the "sink in" time for the implications of this law have been relatively long because of the unusual aspect that it is the residence of the person whose data was lost that triggers whether it applies. Why would a company in New Jersey, without any physical location in California, even think to research California law for a breach that happened in its plant in Georgia, for example? It took at least a year for the breadth of the impact to really reach corporate consciousness - which is not too far off from the recent spate of publicly announced breaches.)
Printer Friendly | Permalink |  | Top
 
UpInArms Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 02:38 PM
Response to Reply #4
54. Personal data breaches in 2005:
­ Feb. 15: Data collection firm ChoicePoint Inc. begins notifying
about 35,000 Californians that their personal information may have been compromised on ChoicePoint databases.


­ Feb. 16: ChoicePoint acknowledges that data on 110,000 Americans
outside of California may have been stolen as well.


­ Feb. 25: Bank of America Corp. announces that it had lost computer
tapes with personal information for 1.2 million credit cards used by
federal employees.


­ March 8: Shoe retailer DSW Inc. says the credit card numbers of more
than 100,000 customers may have been accessed illegally.


­ March 9: Information broker LexisNexis says identity thieves had
tapped into data on more than 30,000 people through one of its
databases.


­ April 12: LexisNexis announces that the number of people whose data
was compromised is closer to 310,000 than 30,000.


­ April 14: Personal data for more than 180,000 MasterCard holders are
reported stolen from Polo Ralph Lauren Corp.


­ April 18: DSW says as many as 1.4 million credit card numbers were
exposed, rather than the 100,000 estimated earlier.


­ June 6: Citigroup Inc. says computer tapes containing Social
Security numbers of 3.9 million customers were lost by United Parcel
Service Inc.


­ Friday: MasterCard International says a security flaw may have
exposed as many as 40 million credit card accounts to fraud.
Printer Friendly | Permalink |  | Top
 
AuntiBush Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:46 AM
Response to Reply #4
68. See My Post Below at
Printer Friendly | Permalink |  | Top
 
Dover Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:36 PM
Response to Original message
9. Just do a google under "security breach" for starters
Printer Friendly | Permalink |  | Top
 
Just Me Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:41 PM
Response to Original message
10. Um, alright. WTF is up?
Edited on Fri Jun-17-05 04:42 PM by Just Me
Way way WAY too many incidences of this happening!!! :scared:

Who could possibly handle that kind of data dumping? :eyes:
Printer Friendly | Permalink |  | Top
 
Jose Diablo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:31 PM
Response to Reply #10
19. CIA, DoD, FBI, NSC
Edited on Fri Jun-17-05 05:36 PM by Jose Diablo
take your pick, any and all.

Edit:Call it a preparation stage for National ID, to protect the consumers. It's a set-up. The cops want this, so the federalies are 'softening' the opposition.
Printer Friendly | Permalink |  | Top
 
EVDebs Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:36 AM
Response to Reply #19
62. Total Information Awareness offshored to the Bahamas, Ben Bell III
www.zmetro.com/archives/000901.php

under guise of CAPPS II

"It began as one of the Bush administration's most ambitious homeland security efforts, a passenger screening program designed to use commercial records, terrorist watch lists and computer software to assess millions of travelers and target those who might pose a threat.
The system has cost almost $100 million. But it has not been turned on because it sparked protests from lawmakers and civil liberties advocates, who said it intruded too deeply into the lives of ordinary Americans. The Bush administration put off testing until after the election.

Now the choreographer of that program, a former intelligence official named Ben H. Bell III, is taking his ideas to a private company offshore, where he and his colleagues plan to use some of the same concepts, technology and contractors to assess people for risk, outside the reach of U.S. regulators, according to documents and interviews.

Bell's new employer, the Bahamas-based Global Information Group Ltd., intends to amass large databases of international records and analyze them in the coming years for corporations, government agencies and other information services. One of the first customers is information giant LexisNexis Group, one of the main contractors on the government system that was known until recently as the second generation of the Computer Assisted Passenger Pre-screening Program, or CAPPS II. The program is now known as Secure Flight."

Your financial and medical info will be Offshored into the waiting hands of Bell. However, as James Bamford points out in Body of Secrets, other countries intell and crime families can and will access that info too (p. 479 paperback re 'foreign databases').



Printer Friendly | Permalink |  | Top
 
Carni Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:44 AM
Response to Reply #19
66. I totally agree and furthermore accounts are compromised, so what?
The consumer is not liable for any bogus charges -- the banks are.

This is just a set up to freak people out so they can carry on with their national ID thing and screw the consumer further...I don't know how they'll do that but they will think of a way I'm sure!
Printer Friendly | Permalink |  | Top
 
Daphne08 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 07:17 PM
Response to Reply #10
31. I don't know, but someone is orchestrating this, I would bet!
I just don't know who or why.



Printer Friendly | Permalink |  | Top
 
seafan Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:41 PM
Response to Original message
11. Let's see... there's Seisint/LexisNexis, Citi, Bank of America,
Choice Point, U. of Calif at Berkeley, DOT records in Nevada, Master Card International... that's just off the top of my head.

This is a deliberate pattern. Our beloved country is stinking of corruption.
Printer Friendly | Permalink |  | Top
 
HockeyMom Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:45 PM
Response to Reply #11
16. Bank of America
is in the process of linking all their online banking between different states and their merger with Fleet Bank.

Great timing. Wonderful news.
Printer Friendly | Permalink |  | Top
 
Karenina Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:20 PM
Response to Reply #16
17. I'm serious as a heart attack
Can anyone list these companies AND the numbers of those whose information has been compromised???

We're talking at LEAST TENS OF MILLIONS. (Please pay no attention to the "outsourcing" of medical records... We're just focusing on FINANCIAL RECORDS in this thread.)
Printer Friendly | Permalink |  | Top
 
Endangered Specie Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:41 PM
Response to Original message
12. This is why I firmly believe in checks and cash
(and maybe debit cards)

I avoid all credit cards, those things are scary :tinfoilhat:
Printer Friendly | Permalink |  | Top
 
teryang Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:46 PM
Response to Reply #12
22. I'm with you
Problem is that you can't get certain services without using credit card.
Printer Friendly | Permalink |  | Top
 
susanna Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 09:37 PM
Response to Reply #12
33. Unfortunately, my bank's debit card
Edited on Fri Jun-17-05 09:38 PM by susanna
is tied to MC. So you can't always get away from the underlying CC giant infrastructure. :-(

On edit: you CAN get away from it, but it is a Class A hassle when you're in the middle of a lot of financial activity and can't switch your account without causing trouble.
Printer Friendly | Permalink |  | Top
 
notadmblnd Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:43 PM
Response to Original message
13. man am I glad I don't have credit cards anymore
got rid of them 3 years ago and I never want one again.
Printer Friendly | Permalink |  | Top
 
Straight Shooter Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 04:44 PM
Response to Original message
14. Wheeeee! I've finally been compromised.
I knew a security breach would hit MCNB sooner or later.

An unauthorized individual? Does he work for the bush administration?

I just paid off my latest statement. Hmmm ... time to think about letting that thing go.
Printer Friendly | Permalink |  | Top
 
Deja Q Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:34 PM
Response to Original message
20. And we consumers get togo through the mess they created. No responsibility
FUCKING SICK.

Their system, their safeguards, their profits. Where the hell is their responsibility in our "ownership society"?!

Nobody's life should be destroyed because of their ineptitude.

But this is nothing; not compared to the future.
Printer Friendly | Permalink |  | Top
 
amazona Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 01:05 PM
Response to Reply #20
49. plenty of responsibility
Mastercard has a zero percent liability clause. If your account is breached by a thief, you don't owe a penny. Federal law says if your account is robbed, you owe no more than $50.

Sounds to me like plenty of accountability.

I've been a victim, and I think we were out a whole whopping $10 to file the report and have it notarized. $10 is not nothing, but it is not life-destroying either.

Hysteria does not serve anyone's purpose.
Printer Friendly | Permalink |  | Top
 
Deja Q Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 02:01 PM
Response to Reply #49
52. Federal law... when will * dismantle that consumer protection?
Okay, I stand corrected re: Mastercard. That's good to know.
Printer Friendly | Permalink |  | Top
 
gulliver Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:36 PM
Response to Original message
21. Not sure it's just MasterCard...
"Almost 14 million of the cards affected are MasterCard branded." What about the other 26 million?
Printer Friendly | Permalink |  | Top
 
wishlist Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 06:29 PM
Response to Reply #21
27. American Express cardholders were also affected
An article I read this evening mentioned American Express being involved in this security breach.
Printer Friendly | Permalink |  | Top
 
AllegroRondo Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 10:17 AM
Response to Reply #21
42. MasterCard discoverd the breach
the breach actually occured at a third party processor in Tucson. Yes, they process for Visa and AMEX also.
Printer Friendly | Permalink |  | Top
 
RebelOne Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 12:51 PM
Response to Reply #21
79. I did hear on CNN that it was also Visa cards.
My Bank of American CC and my check card are both Visa.
Printer Friendly | Permalink |  | Top
 
FormerOstrich Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:53 PM
Response to Original message
24. I was wondering it the breach was from off-shore
operations but I can't determine if the company outsources off-shore or not. Wouldn't surprise me ....

Key Facts & Figures
Offices in Atlanta, Georgia and Tucson, Arizona
In operation for more than 15 years
Processes transactions for over 105,000 small to mid-sized businesses
Processes more than $15 billion in Visa, MasterCard, American Express, Discover, on-line debit and EBT transactions annually


http://www.cardsystems.com/about.html
Printer Friendly | Permalink |  | Top
 
Shallah Kali Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 05:57 PM
Response to Original message
25. Petition asking congress to enact identity theft protection
Urge Congress to enact strong identity theft protection for consumers
http://www.thepetitionsite.com/takeaction/483961807

As identity theft scandals mount, it seems as if it’s only a matter of time before virtually everyone will fall victim to this insidious form of fraud.

That’s not as far-fetched as it sounds. The Federal Trade Commission estimates that 9.9 million Americans are victimized by identity theft every year. That’s 19 new ID theft victims every minute.

Nearly every week we hear about new security breaches at companies like ChoicePoint, Lexis-Nexis, Bank of America and numerous universities. Recent security breaches from these sources put more than two million Americans at risk of having their identities stolen by crooks.

Congress has finally taken the first step to provide consumers with basic safeguards to protect our personal information and prevent identity theft. There are several bills pending in the U.S. Congress that seek to:


* Require information brokers to enforce tight security practices to keep your data safe;

* Mandate that companies notify you if your information has been compromised; and
* Limit the widespread use and display of Social Security numbers that puts your identity at risk.

Act now! Urge your Congressional Representatives to enact strong identity theft protection legislation!


Woops we're sorry doesn't cut it when people are getting ripped off.
Printer Friendly | Permalink |  | Top
 
Up2Late Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 06:29 PM
Response to Original message
26. Good thing I canceled mine after my last Identity Theft with Citi
Edited on Fri Jun-17-05 06:29 PM by Up2Late
:crazy:
Printer Friendly | Permalink |  | Top
 
wishlist Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 06:33 PM
Response to Original message
28. ABC News tonight said Mastercard has known about breach since May
ABC questioned why Mastercard failed to disclose the breach for several weeks since they apparently found out last month but only now revealed the problem.
Printer Friendly | Permalink |  | Top
 
nickdw Donating Member (62 posts) Send PM | Profile | Ignore Fri Jun-17-05 07:00 PM
Response to Original message
29. HMOs, banks and insurance companies are doing it
Edited on Fri Jun-17-05 07:05 PM by nickdw
I think there's some coded journalism getting bandied about..

The HMOs, banks and insurance monopolies are the ones breaking the law, or will be once the laws are reshaped soon. This journalistic and governmental charade of blaming everything on rogue hackers is a front. I think the corporate monopoly mafias are the ones the good people in the media are trying to expose.

40 million is a lot of people. What operating system was used in the creation and maintenance of the data containing the personal information? Windows? Microsoft products are inherently insecure by default and cannot be reverse engineered to be secure, much.

Open Source is the way to go. In other words: transparency in software and network operations. The FTC won't let it happen until Orson Swindle , that little old shillster and that white bitch resign as commissioners. They've all taken bribes from Microsoft and the insurance companies. I'll wager Sen. Gordon Smith has gotten bribed too ( he was chairing the hearing on Identity Theft yesterday ). As for the FBI -- In addition to pursuing criminal investigations like they're supposed to they've been known to partake in economic espionage if there's a high enough bidder who will buy the data, likely done through intermediaries ( and that's where the CIA or spook-sponsored enterprises may come in ).

A lot of this is speculation, however much of it is justified and may be validated in the future but not by me. I'm very suspicious of the FTC and any hearings on Identity Theft with this Congress.
Printer Friendly | Permalink |  | Top
 
thecrow Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 07:05 PM
Response to Original message
30. Gotta love those Friday evening news dumps.!
Hey maybe we should open a new forum... "Friday Night News Dumps"
Printer Friendly | Permalink |  | Top
 
Joacheme Misrahe Donating Member (100 posts) Send PM | Profile | Ignore Fri Jun-17-05 08:22 PM
Response to Original message
32. This shouldn't effect DUers I would hope
as well as other progressives.

After the bankruptcy bill I closed ALL my cards - including 2 with MBNA. I would hope that other progressives did the same to send a message to them.
Printer Friendly | Permalink |  | Top
 
bain_sidhe Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Jun-17-05 11:07 PM
Response to Reply #32
34. And speaking of the bankruptcy bill...
isn't it interesting that the amendment to protect victims of identity theft was defeated. Just a coincidence, of course.
Printer Friendly | Permalink |  | Top
 
Occulus Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 12:52 AM
Response to Reply #34
35. and speaking of identity theft...
Don't these companies now offer identity theft insurance?

...


We need a national credit revolt. SIMPLY. STOP. PAYING.

ALL their customers. Someone needs to find out if they keep a master member list, get it somehow, and send out the word that on xxx date, all customers are to stop paying, for good, in protest.

Starve them of income, bankrupt them, and shut them down forever. We need to reboot this system, starting everyone off from scratch, before its corruption chokes us all.

After they're gone, place a six month moratorium upon the creation of new accounts. During this time, have a major public education campaign regarding responsible credit, then after that time period, restart the credit industry with extreme limits. People may posses two cards, each with a limit representing a percentage of their income. Single purchases exceeding that limit would be allowed for necessary purchases only- repairs for the one car a person owns, or dental work, or any number of other large but required financial obligations.

Not for milk and cookies over and over, nor for any other elective purpose, unless one can prove a monthly balance payment. Three of those months in a row, and your limit rises, again, based on one's income. Three more, and it rises again. And so on.

Or something like that. I'm not saying that's even a good system, but it does address credit limits exceeding one's own income. It's one way to address credit card abuse on the part of both the lender and the customer.

We need something better than the credit system we have, one that makes it a bad idea for both the lender and the customer for a customer's debt to get out of hand. We need to address credit card companies' predilection to offer large credit limits to high-risk persons. We need to address credit limits that themselves outpace the income of the customer.

Lots of problems with this system, and security is only one of them.
Printer Friendly | Permalink |  | Top
 
Joacheme Misrahe Donating Member (100 posts) Send PM | Profile | Ignore Sat Jun-18-05 01:17 AM
Response to Reply #35
36. Have you been drinking the kool-aid?
"During this time, have a major public education campaign regarding responsible credit"

Contrary to what MBNA will tell you MOST credit problems especially those leading to bankruptcy are the result of unexpected bad situations (job loss, high medical bills, etc.) not "responsible credit" issues.
Printer Friendly | Permalink |  | Top
 
Occulus Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 10:23 AM
Response to Reply #36
44. Oh, I know, I know.
I'm thinking more about the predatory lending practices that allow CC companies to offer no-intrest "introductory offers" to people already in bad straits, on fixed incomes, whatever. I know people whose credit is completely shot via a messy divorce, for example, which left them holding the bag for their spouses' excesses, and they're getting CC offers, and from not onoe lender, but several, or the tables they set up on college campuses in the opening days of school.

It's sickening. Something needs to be done.

Printer Friendly | Permalink |  | Top
 
anarchy1999 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 04:21 AM
Response to Original message
38. Well thank you we have VISA, small solace, I'm sure we are next.
Great job, "homeland security", my ass.
Printer Friendly | Permalink |  | Top
 
ElsewheresDaughter Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 10:21 AM
Response to Reply #38
43. VISA was also hacked and data was stolen
Edited on Sat Jun-18-05 10:30 AM by ElsewheresDaughter
NEW YORK -- A computer hacker may have accessed more than 40 million credit card accounts in what could be the largest in a series of recent security breaches involving consumer data, officials said.

MasterCard International Inc. announced Friday that the breach was traced to Atlanta-based CardSystems Solutions Inc., which processes credit card and other payments for banks and merchants. All brands of credit cards could be affected.

<snip>
MasterCard said 14 million of its customers may have been exposed to fraud. A spokeswoman for American Express said a small number of its cardholders were affected, but would not give an exact number. Discover Financial Services Inc. wouldn't say whether its customers were affected. Visa USA and a large issuer of cards, MBNA Corp., did not return calls for comment Friday.


http://www.webpronews.com/business/topbusiness/wpn-54-20050618MasterCardOpenBookForIDTheft.html

Printer Friendly | Permalink |  | Top
 
Swamp Rat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 04:41 AM
Response to Original message
39. There's a LOT of consecutive prison terms this thief might get.
One person can rob 40 million - so much for credit card security.
Printer Friendly | Permalink |  | Top
 
cthrumatrix Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 08:46 AM
Response to Original message
40. 40M Credit Card Accounts Could Be Affected (this is a problem)
40M Credit Card Accounts Could Be Affected

By JOE BEL BRUNO, AP Business Writer

NEW YORK - A computer hacker may have accessed more than 40 million credit card accounts in what could be the largest in a series of recent security breaches involving consumer data, officials said.

MasterCard International Inc. announced Friday that the breach was traced to Atlanta-based CardSystems Solutions Inc., which processes credit card and other payments for banks and merchants. All brands of credit cards could be affected.

snip

MasterCard announced the breach in a news release Friday, saying it was notifying its card-issuing banks of the problem.

CardSystems then released its own statement, saying it first learned of a potential breach on May 22. The company said it was told by the FBI not to release any information to the public; its statement Friday had been vetted by the agency.

"We were absolutely blindsided" by MasterCard's announcement, CardSystems' chief financial officer, Michael A. Brady, told The Associated Press.

snip

http://news.yahoo.com/s/ap/credit_cards_breach;_ylt=Ai1GbU0bSr.nJw_lRkb1Y_wDW7oF;_ylu=X3oDMTBiMW04NW9mBHNlYwMlJVRPUCUl


Printer Friendly | Permalink |  | Top
 
AllegroRondo Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 10:09 AM
Response to Original message
41. Reading more carefully
it looks like the breach actually occured with a third party processor in Tucson, and MasterCard discovered the breach. Only 14 million of the 40 million cards belong to MasterCard - so dont think you're safe if you have something else.
Printer Friendly | Permalink |  | Top
 
Occulus Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 10:24 AM
Response to Reply #41
45. Heh. I'll say it again-
we need a national credit revolt.
Printer Friendly | Permalink |  | Top
 
fortyfeetunder Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 12:47 PM
Response to Reply #45
47. I second that
because how many people are going to get nailed on any fraud related damage to their credit card, like in identity theft that has to be resolved, resulting in a negative credit rating?

For all the money the CC companies have been sucking out of us, those greedy bastards, we need to show them WHO has the power....
Printer Friendly | Permalink |  | Top
 
mom cat Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 01:01 PM
Response to Original message
48. Up to 40m credit cards 'hacked' (BBC).....(PRICELESS!!!!!!!!!)
Up to 40m credit cards 'hacked' (BBC)

http://news.bbc.co.uk/2/hi/americas/4107236.stm

All brands of cards could be affected
A computer hacker may have broken into more than 40 million credit card accounts, US company officials say.
MasterCard International said the breach was traced to a company in Atlanta which processes transactions for banks and merchants.

All brands of credit cards could be affected, it warned.

The company, CardSystems Solutions, said it identified the breach last month and immediately contacted the FBI, which was investigating.

MasterCard announced the breach in a news release on Friday, saying security "vulnerabilities" had allowed an unauthorised individual to infiltrate the network of CardSystems and access the cardholder data.

It said 14 million of its customers may have been exposed to fraud. Another 22 million were Visa cards, said a spokeswoman for the Visa company.

MasterCard spokeswoman Sharon Gamsin told the Associated Press news agency the data - names, banks and account numbers - could be used to steal funds, but not identities. The company was notifying banks that issue MasterCards.


The
Printer Friendly | Permalink |  | Top
 
lies and propaganda Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 01:35 PM
Response to Reply #48
50. funny, the BBC link has an
Edited on Sat Jun-18-05 01:37 PM by lies and propaganda
firm in Atlanta that was hacked, and the post this was combined with from MarketWatch has Tucson, Az.
Just find that a bit strange.

edited for need of editing
Printer Friendly | Permalink |  | Top
 
RPM Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Jun-18-05 01:47 PM
Response to Original message
51. that will be one doozy of a class action
any lawyers listening???
Printer Friendly | Permalink |  | Top
 
vogonjiltz Donating Member (298 posts) Send PM | Profile | Ignore Sat Jun-18-05 02:19 PM
Response to Original message
53. I maxxed out my master card, bring it on!!
Printer Friendly | Permalink |  | Top
 
UpInArms Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Jun-19-05 10:23 PM
Response to Original message
55. update: Lost Credit Card Data Improperly Kept, Company Admits
http://www.nytimes.com/2005/06/20/technology/20credit.html

The chief of the credit-card processing company whose computer system was penetrated by data thieves, exposing 40 million cardholders to a risk of fraud, acknowledged yesterday that the company should not have been retaining consumer records lost to the thieves.

The official, John M. Perry, chief executive of CardSystems Solutions, indicated that the records known to have been stolen covered roughly 200,000 of the 40 million compromised credit-card accounts, from Visa, MasterCard and other card issuers. He said the data was in a file being stored for "research purposes" to determine why certain transactions had gone unauthorized or uncompleted.

<snip>

The security breach was first reported Friday when MasterCard International said a lapse at CardSystems had allowed the installation of a rogue computer program that could extract data from the system, potentially compromising 40 million accounts of various credit cards.

<snip>

MasterCard said that it had detected atypical levels of fraudulent charges on its cards as early as mid-April and, joined by Visa in mid-May, had requested that CardSystems allow its independent forensics team to investigate. It was not until May 22 that the security specialists identified the rogue computer program as the source, MasterCard said.

...more...
Printer Friendly | Permalink |  | Top
 
AuntiBush Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:27 AM
Response to Original message
56. MasterCard: 40 MILLION Credit Card Accounts EXPOSED
Edited on Mon Jun-20-05 10:17 AM by AuntiBush
June 20, 2005: 1 Hour Ago from Google News, 11:13 AM EST.


MasterCard: 40M Credit Card Accounts Exposed
By Clint Boulton

In what is considered one of the largest security breaches, MasterCard International said information on more than 40 million credit cards lay exposed at credit card processor CardSystems Solutions.

Exposed data included holder names, banks and account numbers. No Social Security numbers, birth dates or other personal information were stored on the accounts.

Roughly 13.9 million cards were of the MasterCard brand, said MasterCard, which pinpointed the breach at CardSystems, an Atlanta-based company that processes transactions between financial services firms and merchants. Visa and American Express also said data was exposed through CardSystems.

http://www.internetnews.com/security/article.php/3513866


Update 2:
Credit Card Company Admits Fault in Hacking Incident All Headline News
http://news.google.com/nwshp?hl=en&gl=us&oi=newst

Update 3:
CardSystems: Shouldn't Have Kept Records Forbes
http://www.forbes.com/home/feeds/ap/2005/06/20/ap2100336.html
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:27 AM
Response to Reply #56
57. This could turn out to be good news
I'm not saying I have no sympathy for cardholders who are in a precarious postion, quite the contrary.

If people see that their information will be continously breached, for whatever reason, they might stop using cards all the time. That would really send the CC companies reeling.
Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:27 AM
Response to Reply #57
58. I don't see the problem
they were just downloaded, what's the big deal?
Printer Friendly | Permalink |  | Top
 
shraby Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:27 AM
Response to Reply #58
59. If you don't see a problem with
card holders names and account numbers being taken, you aren't thinking.
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:36 AM
Response to Reply #58
61. Oh, and you think someone was just
having a look see and they won't really *do* anything with that information?

I've got an ocean in Kansas to sell you, too.
Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:41 AM
Response to Reply #61
64. hey, go visit a downloading thread
that's not stealing, so how can this be stealing? possession of the info isn't illegal, doing something with it is the crime.
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:49 AM
Response to Reply #64
71. People gaing access to private information
don't usually just sit on it.

I don't have a problem with people who test security systems, looking for weaknesses and then reporting it to the company so they can fix it.

But if I'm a customer, I don't want my information in the hands of someone who doesn't need it. I don't care what they think is legal, or their "right" to see. I don't want them seeing it. Period. They don't need to know how much I spent at Target last month or that I bought BC pills. And MC should know better by now.
Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:54 AM
Response to Reply #71
72. indeed, having someone steal from you is painful
or the potential that someone stole from you. That was the point.
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 11:00 AM
Response to Reply #72
73. No, that was MY point
what was yours? :shrug:
Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 11:07 AM
Response to Reply #73
74. there are as many posts on this board today
defending the downloading of software, music, movies and other information without paying for it as there are on this thread complaining about this theft. either both are theft, or neither is, that was my point.

And there are people, and I'm not saying you're one of them, who are gung ho about stealing from others, who complain vociferously when it is their pocket that is picked. but I guess I was being too subtle?
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 11:58 AM
Response to Reply #74
75. Oh I see,
Edited on Mon Jun-20-05 12:14 PM by supernova
you were using my basic point about right to a certain degree of privacy of information to rag on music downloaders? How kind of you. :sarcasm:

A couple of things about d/l'ing art:

1) It is meant for public consumption. You create something and put it on a disk or film. You want people to see it, hear it, discuss it. Art isn't worth anything except sentimental value to the the artist if it's kept in a closet. The very value of art depends on its value to the public. There are probably a lot of no-name 17th and 18th Century composers who might have written some great music, but their names have no currency past their lifetimes so their work is lost to us.

Private information for private individuals is not the same thing as public work, art, created expressly for public consumption. Private individuals don't ask, or hire PR people, to spread their private financial info over the globe. But record companies and movie stuios do hire these people to spread their work around. The people who stole the MC info are exposing customers to risk who didn't ask for that information to be released. And artist must release his work to the public.

2a) The fans who trade music online have a point for which the RIAA has yet to provide a satisfactory answer: How often do they have to keep buying the same music over and over, just keep up with the format du jour? It seems to me that if you buy an album (the concept work), you ought to be able to play that album on whatever apparatus is handy. You already paid the artist and the record company the first time you bought it. You shouldn't have to replace your collection every ten years because the format is obsolete.

2b) Anyway, the problem has arisen because the fans have gotten ahead of the distribution system of the companies that produce the work. The fans have expressly said, since Napster, that they prefer to d/l their art and share it with others.

Do I think artists need to be fairly compensated for their work? Of course. The companies need to come up with a viable model for working with the current system, even though they didn't create, nor do they control it. Going after 14-year olds in their moms' basements and university students, the audience, is wrong-headed. What's the point of alientating your potential audience and customers? If you think music and movie sales such now, just wait. Oh yea, and while you are at it, figure out a way for the Chinese to reign in their bootleg market. Yea, good luck with that.

2c) As a result of file-sharing, musical tastes are much more broad. People are exposed to music that in another time, they wouldn't have heard. And they are liking it. As a result of the net, music lovers can find things they like and that are much more compelling to them than the simple dreck that the studios are offering. The number of variations of "Hit Me, Baby" that Brittany sing and get away with it are dwindling to nil.

You know what? I don't know what the answer is. I don't know what a new artist compensation model taking into account P2P activity would look like. But I do know that somebody will invent it. And that somebody will make a killing.

For now, put the blame where it belongs, on movie studios and record companies who can't continously evolve in their use of technology, just like the rest of us have to.

Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 12:19 PM
Response to Reply #75
76. ahh, so you don't like the business model
therefore it's accceptable to steal. Good to know. So once an artist 'releases' work to the public, it enters the public domain? the format and structure (plus the code) of DU is the IP of the Admins (and or whoever they license it from) it is worthless without an audience, therefore you would support me creating www.demoraticunderground.com, 'sharing' the design and coding for public consumption? good to know.

By the way, RIAA has never gone after someone for downloading. It goes after people for uploading information that they do not have permission to share. That's not passive sampling, that's breaking well established IP law. It is no different from photocopying a book to give to someone, and I think we can all agree that isn't right, yes?

I sympathise with the format de jour problem, but really, since most music avaliable online came from CDs, that logic doesn't count. You can buy digital music, and in most cases, put it on your harddrive without a problem, no one, not even the industry complains about that. And if that's what people were doing, there'd be no problem. But that's not it, right?

last point, and it's repetative: you may not think the industry is 'keeping up with technology' but then the data companies aren't keeping up with hacker technology either, are they? Why should they do it, if they don't want to? the music actually belongs to them, they published it, if they don't want to give it away online, they don't have to.
but this is obviously off topic, and I must have hit a sorespot 9guilt complex, rationalisation? who knows) so we should let it die.
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 12:46 PM
Response to Reply #76
78. No I didn't say it was acceptable to steal
I DID say artists should be compensated fairly for their work.

What I did say, in essence, is that P2P technology is hear to stay, and that studios would serve themselves, artists, and their customers well to find a way to work with it, not against it. P2P is a great technology, we just have to find a way to work with it. What that is, I don't know. If you try to sue it to death, it will just splinter and go further underground. But it will always be there.

This is a weak argument for the same reason it was last time:
...you may not think the industry is 'keeping up with technology' but then the data companies aren't keeping up with hacker technology either, are they? Why should they do it, if they don't want to? the music actually belongs to them, they published it, if they don't want to give it away online, they don't have to.

Why? While you're right that data companies aren't keeping up either, they are losing the rights to their most valuable resources. A data company's assests lie in its ability to keep confidentiality. A music company's resources lie in their ability to keep and attract popular (read: public) talent. I would think any business would want to keep up with their most precious assets.
Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 12:56 PM
Response to Reply #78
80. exactly
I think you agree with me, funny enough. Why? While you're right that data companies aren't keeping up either, they are losing the rights to their most valuable resources. A data company's assests lie in its ability to keep confidentiality. A music company's resources lie in their ability to keep and attract popular (read: public) talent. I would think any business would want to keep up with their most precious assets. if a company doesn't meet your expectations, shop elsewhere, get other people to shop elsewhere, or simply do without.

you would think that a company would, but you can't make it, except by refuseing to patronize it.
Printer Friendly | Permalink |  | Top
 
AuntiBush Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:44 AM
Response to Reply #58
67. I have some FANTASTIC Swamp Property in FL... Going Cheap.
You could use your MasterCard... just wire it over to Paypal.com.

:)

Brain Process: A lost art.
Printer Friendly | Permalink |  | Top
 
northzax Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:47 AM
Response to Reply #67
70. so when it's someone like you getting ripped off
it's a problem, but when it's just a rich person, you're ok with it?
Printer Friendly | Permalink |  | Top
 
AuntiBush Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jun-21-05 07:56 PM
Response to Reply #70
83. Huh. You mis-read my post. Far from rich, sorry.
You mis-understood my post.
Printer Friendly | Permalink |  | Top
 
EVDebs Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:27 AM
Response to Reply #56
60. The Citigroup/Travelers merger done illegally at the time forced repeal
of the Glass Steagall Act that would have prevented these abuses. Now every affiliate both foreign and domestic has access to YOUR personal financial (and now even medical) info worldwide.

DOJ and FTC jurisdiction are only US; in meantime, companies are paying hush money to extortionists overseas, resulting in higher rates for US customers. Sen Feinstein is well aware of this fiasco but the R's in Congress are behind non-disclosure to the US public as to how bad the situation really is"

"...Alan Paller, director of research at the Bethesda, Md.-based SANS Institute, said the California law is probably necessary because of the kinds of crime that are occurring. A group in Russia and Ukraine has been acquiring customer data, extorting money to prevent its release and then selling it anyway. Paller believes some companies are paying off the extortionists in an attempt to contain the damage."

California leads way on ID theft legislation
http://www.computerworld.com/securitytopics/security/hacking/story/0,10801,76721,00.html
Printer Friendly | Permalink |  | Top
 
Carni Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:46 AM
Response to Reply #60
69. Now THIS IS a big deal--and speaking of citibank
Has anyone else noticed that most store credit cards are now held by citibank? How comforting that their biggest shareholder is a Saudi Prince.
Printer Friendly | Permalink |  | Top
 
EVDebs Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 12:40 PM
Response to Reply #69
77. Also, look into CAPPS II with Ben Bell III in the Bahamas
Things look like they've been offshored for a reason (total information awareness never died, they just offshored it !
Printer Friendly | Permalink |  | Top
 
Carni Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 05:14 PM
Response to Reply #77
81. It doesn't surprise me!
These bushevik SOB's are all robbing this country blind.
Printer Friendly | Permalink |  | Top
 
AuntiBush Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 10:40 AM
Response to Reply #56
63. Master Card, FBI, Net Credit Card Links w/Information
Edited on Mon Jun-20-05 10:41 AM by AuntiBush


Short queries using Google can turn up sites that have posted critical credit card information to the Internet.
Ranks for Sale
http://www.rankforsales.com/n-ax/695-seo-aug-04-04.html

Credit and ATM Cards - What To Do If They're Lost or Stolen
Credit, ATM and Debit Cards: What to do if They're Lost or Stolen ... Again, tell the card issuer the date your card was lost or stolen, or when you first ...
http://www.ftc.gov/bcp/conline/pubs/credit/atmcard.htm

MasterCard credit card information may have been stolen from HSBC ...
HSBC customers ... NetCreditCard.info Get news like this delivered to your email address. ...
http://www.newstarget.com/007315.html

Laptop with credit card info for 80000 DOJ workers stolen ...
FBI and Fairfax, Va., police are investigating the theft of a laptop that contained the names and credit card numbers of about 80000 US Department of ...
http://www.computerworld.com/governmenttopics/government/legalissues/story/0,10801,102146,00.html

FRB: Choosing a Credit Card
If your credit card is lost or stolen--and then is used by someone without your permission--you do not have to pay more than $50 of those charges.
http://www.federalreserve.gov/pubs/shop/default.htm
Printer Friendly | Permalink |  | Top
 
rainbow4321 Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Jun-20-05 05:34 PM
Response to Original message
82. Credit card info inappropriately retained ("stored for research purposes"
http://www.dallasnews.com/sharedcontent/dws/bus/stories/062005dnbuscredit.2a1f4ab9.html

The head of the credit card processing company whose computer system was breached by hackers, exposing millions of credit card accounts, has acknowledged that his firm should not have been keeping the consumer records in the first place.

The official, John Perry, chief executive of Atlanta-based CardSystems Solutions Inc., said that the records known to have been stolen covered roughly 200,000 of the 40 million compromised credit card accounts, from Visa, MasterCard, and other companies.

He said the data was being stored for “research purposes” to determine why some transactions had registered as unauthorized or uncompleted. “We should not have been doing that,” Perry said in Monday's editions of The New York Times. Under rules established by Visa and MasterCard, processors cannot retain cardholder information after handling transactions.

“CardSystems provides services and is supposed to pass that information on to the banks and not keep it,” Joshua Peirez, a MasterCard official, told the Times. “They were keeping it.”
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Dec 27th 2024, 04:49 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC