Visa, Amex Cut Ties with CardSystems

By David Worthington | Published July 21, 2005, 9:13 AM

In a first of its kind move, Visa USA and American Express Co. have dropped the hammer on an affiliated payment processor several months after its was revealed that a massive security breach exposed the records of millions of its cardholders.

CardSystems Solutions put the account information of approximately 40 million credit card holders at risk for fraud by mishandling data stored in its database. Customers' names, credit card numbers and expiration dates were revealed in the breach.

Of those 40 million, 200,000 were marked as being at high risk for fraud: 100,000 Visa cards, 68,000 from MasterCard, and 30,000 cards from other credit card companies that use CardSystems to process transactions. The breach was the largest of its kind ever to be reported.

Associated instances of fraud have already been uncovered.

A spokesperson for American Express has stated that it will sever its relationship with CardSystems as early as October. The spokesperson declined to provide any further comment.

Visa was more vocal in a memorandum that it sent to its participating banks. "CardSystems has not corrected, and cannot at this point correct, the failure to provide proper data security for those accounts," said Tim Murphy, Visa's senior vice president for operations. "Visa USA has decided that CardSystems should not continue to participate as an agent in the Visa system."

American Express and Visa expect that merchants and cardholders will continue to experience normal service despite their decision to bar CardSystems from processing their transactions.

Although it did not say whether it would follow Visa's lead, a spokesperson for MasterCard told BetaNews, "MasterCard’s acquiring banks are fully aware that we are working with CardSystems to bring their systems into compliance in as short a time as possible. However, if CardSystems cannot demonstrate that they are in compliance by that date, their ability to provide services to MasterCard members will be at risk."

MasterCard is holding weekly meetings with CardSystems Solutions to monitor its progress in drafting a detailed plan to meet its MasterCard security requirements by August 31, 2005. MasterCard says that it is not aware of any deficiencies that are incapable of being remediated.

A spokesperson for Discover Financial Services, which also uses CardSystems to process transactions, could not be reached by press time.

Some industry watchers see the move as a prime example of industry self regulation.

"Visa's decision sends a strong message to the industry about their willingness to enforce the PCI Data Security Standard to the fullest extent. We'll see if MasterCard and American Express follow suit," Jeremiah Grossman, Chief Technology Officer of WhiteHat Security, told BetaNews.

In June, the U.S. government's Federal Financial Institutions Examination Council began investigating the network security systems and data handling practices of CardSystems. The FBI has launched a separate investigation.

CardSystems is accused of centralizing all of its accumulated account information onto a single server for research purposes, in violation of the security protocol and policies of nearly all credit card companies.

Hackers obtained access to the server and placed a downloader that transmitted credit card data.

CardSystems Solutions has been providing services to credit card companies for nearly 15 years and has processed as much as $15 billion in transactions annually. The company is privately held and is based in Tucson Arizona.

A CardSystems spokesperson did not respond to requests for comment in time for publication.

Comments

Sounds logical to me. They should have pulled the plug way early before this huge disaster took place. They violated the security protocols, how can anyone even try to defend them? Or what basis can they have in defending themselves when they have made such a violation in security protocols?

I wouldnt be surprised if CardSystems fade off or goes bankrupt soon.

Score: 0

|

The credit card companies cant' pull out immediately, there's too much money involved to totally cut the cord.

Can you imagine how much money they'd lose if one of their major source of CC sales were cut? They'd stop making the 2.x percent off every company that accepts their cards. That amounts to ALOT of money.

BTW, it's illegal to charge a premium to use CC or to allow a "cash discount", however, the CC companies feel it's fine to charge their customers?!?

Score: 0

|

"BTW, it's illegal to charge a premium to use CC or to allow a "cash discount", however, the CC companies feel it's fine to charge their customers?!?"

Guess what, it is and it isn't. <-- Huh? We have local County/State offices that accept credit cards for payment, they make you pay a "convenience charge" to use your credit card, which is a way around a credit card surcharge or "premium," either legally or not. Many companies in magazines mention in fine print "prices reflect x% cash discount." Guess what, they get away with it...

Score: 0

|

wow, after 15 years and they screw it up, now they're in the middle of a breakdown.
but then again, keep in mind that it's difficult to migrate to a new system, the migration would cost them (Visa, Amex, MasterCard, etc.) more, and that is something to reconsider.
They'd have to evaluate the new system, will it be safer and better or at least of the same quality to CardSystems.
This can affect the customers' experience. I just hope it's not severe.

Score: 0

|

I work at a financial institution. We mailed letters to nearly 4,000 affected by the CardSystems Solutions security breach. The letter specifically states that their card will be canceled. What a headache this incident has been for the financial industry. Not to mention the card holders that it effected while they are on vacation trying to use their cards.

We did apologize for the inconvenience and explain that these steps were taken to protect them as well as the financial institution from unauthorized usage.

Score: 0

|

if i were a credit card company I would pull out. I can't beleve they put almost all the credit card information on one computer

Score: 0

|

they are being punished, they will be out of business before the year is out. If I was working there, I would be planning my exit soon.

Score: 0

|

Good. They violated everyone's trust. They should be punished.

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET