Visa, Amex Cut Ties with CardSystems

By David Worthington | Published July 21, 2005, 9:13 AM

In a first of its kind move, Visa USA and American Express Co. have dropped the hammer on an affiliated payment processor several months after its was revealed that a massive security breach exposed the records of millions of its cardholders.

CardSystems Solutions put the account information of approximately 40 million credit card holders at risk for fraud by mishandling data stored in its database. Customers' names, credit card numbers and expiration dates were revealed in the breach.

Of those 40 million, 200,000 were marked as being at high risk for fraud: 100,000 Visa cards, 68,000 from MasterCard, and 30,000 cards from other credit card companies that use CardSystems to process transactions. The breach was the largest of its kind ever to be reported.

Associated instances of fraud have already been uncovered.

A spokesperson for American Express has stated that it will sever its relationship with CardSystems as early as October. The spokesperson declined to provide any further comment.

Visa was more vocal in a memorandum that it sent to its participating banks. "CardSystems has not corrected, and cannot at this point correct, the failure to provide proper data security for those accounts," said Tim Murphy, Visa's senior vice president for operations. "Visa USA has decided that CardSystems should not continue to participate as an agent in the Visa system."

American Express and Visa expect that merchants and cardholders will continue to experience normal service despite their decision to bar CardSystems from processing their transactions.

Although it did not say whether it would follow Visa's lead, a spokesperson for MasterCard told BetaNews, "MasterCard’s acquiring banks are fully aware that we are working with CardSystems to bring their systems into compliance in as short a time as possible. However, if CardSystems cannot demonstrate that they are in compliance by that date, their ability to provide services to MasterCard members will be at risk."

MasterCard is holding weekly meetings with CardSystems Solutions to monitor its progress in drafting a detailed plan to meet its MasterCard security requirements by August 31, 2005. MasterCard says that it is not aware of any deficiencies that are incapable of being remediated.

A spokesperson for Discover Financial Services, which also uses CardSystems to process transactions, could not be reached by press time.

Some industry watchers see the move as a prime example of industry self regulation.

"Visa's decision sends a strong message to the industry about their willingness to enforce the PCI Data Security Standard to the fullest extent. We'll see if MasterCard and American Express follow suit," Jeremiah Grossman, Chief Technology Officer of WhiteHat Security, told BetaNews.

In June, the U.S. government's Federal Financial Institutions Examination Council began investigating the network security systems and data handling practices of CardSystems. The FBI has launched a separate investigation.

CardSystems is accused of centralizing all of its accumulated account information onto a single server for research purposes, in violation of the security protocol and policies of nearly all credit card companies.

Hackers obtained access to the server and placed a downloader that transmitted credit card data.

CardSystems Solutions has been providing services to credit card companies for nearly 15 years and has processed as much as $15 billion in transactions annually. The company is privately held and is based in Tucson Arizona.

A CardSystems spokesperson did not respond to requests for comment in time for publication.

Comments

View comments by with a score of at least

Sounds logical to me. They should have pulled the plug way early before this huge disaster took place. They violated the security protocols, how can anyone even try to defend them? Or what basis can they have in defending themselves when they have made such a violation in security protocols?

I wouldnt be surprised if CardSystems fade off or goes bankrupt soon.

Score: 0

|

The credit card companies cant' pull out immediately, there's too much money involved to totally cut the cord.

Can you imagine how much money they'd lose if one of their major source of CC sales were cut? They'd stop making the 2.x percent off every company that accepts their cards. That amounts to ALOT of money.

BTW, it's illegal to charge a premium to use CC or to allow a "cash discount", however, the CC companies feel it's fine to charge their customers?!?

Score: 0

|

"BTW, it's illegal to charge a premium to use CC or to allow a "cash discount", however, the CC companies feel it's fine to charge their customers?!?"

Guess what, it is and it isn't.

Score: 0

|

wow, after 15 years and they screw it up, now they're in the middle of a breakdown.
but then again, keep in mind that it's difficult to migrate to a new system, the migration would cost them (Visa, Amex, MasterCard, etc.) more, and that is something to reconsider.
They'd have to evaluate the new system, will it be safer and better or at least of the same quality to CardSystems.
This can affect the customers' experience. I just hope it's not severe.

Score: 0

|

I work at a financial institution. We mailed letters to nearly 4,000 affected by the CardSystems Solutions security breach. The letter specifically states that their card will be canceled. What a headache this incident has been for the financial industry. Not to mention the card holders that it effected while they are on vacation trying to use their cards.

We did apologize for the inconvenience and explain that these steps were taken to protect them as well as the financial institution from unauthorized usage.

Score: 0

|

if i were a credit card company I would pull out. I can't beleve they put almost all the credit card information on one computer

Score: 0

|

they are being punished, they will be out of business before the year is out. If I was working there, I would be planning my exit soon.

Score: 0

|

Good. They violated everyone's trust. They should be punished.

Score: 0

|

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.