Showing posts with label Target. Show all posts
Showing posts with label Target. Show all posts

Thursday, February 7, 2019

Is your business PCI compliant? Avoid fines for breaches!

Major breaches like TJMaxx and Target have been widely publicized in the past, but breaches at smaller businesses have received very little attention. This is mainly because information about these smaller occurrences have been very hard to come by due to two reasons.

First, not all states have disclosure laws requiring merchants to disclose breaches and secondly, card associations are not required to disclose individual cases.

According to a Wall Street Journal article, most breaches come from small businesses who are not up to date with technology or compliance laws. Here are some of the article highlights:
  • More than 80% of the credit card breaches have occurred at small businesses.
  • Visa levied $3.3 million in fines for non compliance against small businesses in just one year.
  • MasterCard did not disclose their fines.
  • Any business that accepts credit cards must agree to be PCI complaint.
Take for example the case study of Lodi Beer, a microbrewery and restaurant in California who unknowingly stored 11,728 credit card records in their point of sale system. (Track data from the credit card's magnetic strip cannot be stored according to PCI standards). When that data was breached, Visa and MasterCard fined Abanco, the restaurant's merchant account provider, $27,000. Abanco then in turn passed that fine onto the restaurant. In addition to the fines, this merchant has spent over $50,000 in remediation costs, legal fees, upgrades, etc. That is a huge amount of money for a small business. Had they been up to date with their technology, this situation could have been avoided.

Here are some interesting facts that you should know about PCI compliance standards:
  • Visa, MasterCard and the other card brands have put the responsibility  of maintaining compliance status on the processor or merchant account provider. They've successfully done this with a policy of making them responsible for paying fines when breaches occur.
  • While these processors are responsible for fines, they will almost always pass whatever they're fined onto the merchant.
  • If merchants are ultimately responsible for the fines, it is their responsibility to maintain PCI standards and stay up to date with their technology.

IES would love to help you become compliant. Give us a call at 781-816-9437 or check us out online at iesAdvisors.com.

Friday, October 3, 2014

JP Morgan Chase admits to a significant data breach.

Today, JP Morgan Chase revealed that information on 76 million households and 7 million businesses was stolen from their systems due to malware on an employee laptop. This is added to the Home Depot and Target breaches. Here are a few things you can do to protect your personal information...
  • Change all banking passwords
  • Do not reuse passwords amongst banks
  • Monitor all of your accounts (even those not with JP Morgan)
  • Ask for alerts:
    • Daily balance via email & text message
    • Alerts for transactions over $500 (or whatever level you desire)
    • Alerts for number of daily transactions
    • Alerts when balance falls below a certain amount
  • Use 2-factor authentication
  • Avoid using debit cards
  • Minimize online banking
Demand Chase hold it’s software and security vendors accountable for their lapses - after all, they spend millions (if not billions) of dollars on this software. We as individuals cannot force Microsoft, Adobe, Oracle, Cisco, and other software manufacturers to improve their security. It will take a large customer like JP Morgan Chase to force the software industry to deliver secure, hardened software.

Sources:
NYTimes.com
BusinessInsider.com

Tuesday, March 25, 2014

Target Hack: The Movie...coming soon to a theater near you.

Does the computer breach at Target have the makings of a movie? Throw in a shotgun-toting security analyst, Russian hackers, drugs and a SWAT team and Hollywood appears to think so.

Sony has bought the rights to a New York Times article about Brian Krebs, the security blogger who was the first to expose December's security breach at Target.

The article, "Reporting From the Web's Underbelly," was written by Nicole Perlroth and details how Krebs' blog about cybercrime has prompted criminals to hack him repeatedly, send heroin and excrement to his home and falsely accuse him of murder.

"A lot of what Brian does would scare the hell out of traditional newsroom editors," Russ Walker, Krebs's former editor at The Washington Post, said in the Times article. "I don't think he crossed the lines journalistically, but he was living a different type of experience."

The movie is expected to be a cyberthriller written by Richard Wenk, whose credits include "16 Blocks," "The Mechanic" and "The Expendables 2."

Krebs himself seems amused by the notion that his life and unglamorous work may soon be dramatized by Hollywood.

"Judging from accounts of the screenwriter's other movies, if this flick actually gets made someone vaguely resembling me probably will be kicking some badguy butt on the Silver Screen," he wrote Friday in a post on his security blog.

"I still have yet to work out the details with Sony, but beyond remuneration, I would be delighted if I could influence the selection of the leading man," he added.

"In the past week, I've been told I look like both Jim Carrey and Guy Pierce, but I'm not so sure. But if I had to pick one of my favorite actors, I'd love to see Edward Norton in the role."

As many as 40 million customers had their personal information compromised in the Target breach. Krebs found out about it through sources in the hacker underworld and was the first to contact Target about it.

Source: CNN