Showing posts with label credit card fraud. Show all posts
Showing posts with label credit card fraud. Show all posts

Thursday, February 7, 2019

Is your business PCI compliant? Avoid fines for breaches!

Major breaches like TJMaxx and Target have been widely publicized in the past, but breaches at smaller businesses have received very little attention. This is mainly because information about these smaller occurrences have been very hard to come by due to two reasons.

First, not all states have disclosure laws requiring merchants to disclose breaches and secondly, card associations are not required to disclose individual cases.

According to a Wall Street Journal article, most breaches come from small businesses who are not up to date with technology or compliance laws. Here are some of the article highlights:
  • More than 80% of the credit card breaches have occurred at small businesses.
  • Visa levied $3.3 million in fines for non compliance against small businesses in just one year.
  • MasterCard did not disclose their fines.
  • Any business that accepts credit cards must agree to be PCI complaint.
Take for example the case study of Lodi Beer, a microbrewery and restaurant in California who unknowingly stored 11,728 credit card records in their point of sale system. (Track data from the credit card's magnetic strip cannot be stored according to PCI standards). When that data was breached, Visa and MasterCard fined Abanco, the restaurant's merchant account provider, $27,000. Abanco then in turn passed that fine onto the restaurant. In addition to the fines, this merchant has spent over $50,000 in remediation costs, legal fees, upgrades, etc. That is a huge amount of money for a small business. Had they been up to date with their technology, this situation could have been avoided.

Here are some interesting facts that you should know about PCI compliance standards:
  • Visa, MasterCard and the other card brands have put the responsibility  of maintaining compliance status on the processor or merchant account provider. They've successfully done this with a policy of making them responsible for paying fines when breaches occur.
  • While these processors are responsible for fines, they will almost always pass whatever they're fined onto the merchant.
  • If merchants are ultimately responsible for the fines, it is their responsibility to maintain PCI standards and stay up to date with their technology.

IES would love to help you become compliant. Give us a call at 781-816-9437 or check us out online at iesAdvisors.com.

Thursday, September 10, 2015

Less than 1 month until EMV kicks in...is your business ready?

If you are a business owner, you should have heard by now that the United States is transitioning to full adoption of EMV chip enabled cards to reduce credit card fraud. The change is coming October 1, 2015.

How could EMV affect your business?
Today, if businesses swipe a counterfeit or stolen card, the bank assumes the loss. To encourage businesses to adopt the more secure technology of EMV chip cards, a liability shift is going into effect on October 1, 2015, where card issuers plan on shifting that loss to merchants.

What do I need to do?
Your credit card processing company should have contacted you by now to inform you of the changes and schedule new equipment to be delivered. (If they have not, you may want to call them). Depending on the company you use, that equipment may or may not come with a charge.

Do I need to switch all my equipment to EMV technology?
This scenario is most likely for small business owners who are being forced to pay for new equipment. It's just a matter of risk measurement...Consider the amount of your typical sale - are your customers buying a $10 pizza or a $500 laptop? Do you personally know most of your customers? What percentage of your customers use credit cards?

Will it be illegal to run a credit card without using EMV technology?
No, it will not be illegal to run a credit card using a typical mag card reader; just be aware that in the case of a charge back or fraudulent use, your business will be forced to take the loss not the bank.

If your business is facing challenges with EMV, give IES a call at 781-816-9437. We can answer your questions and help streamline the change, should you choose to upgrade.

Tuesday, December 23, 2014

Confirmed: 1.16 million credit card numbers stolen in Staples breach.

Staples said that malware infected the checkout stations at 115 of its 1,400 U.S. stores. It began removing the software in mid-September. Investigations in the meantime revealed that shoppers who made purchases at these stores across the country going back as far as July may have had their credit card numbers, expiration dates, verification codes and their names stolen in the hack.

In a statement, Staples said that 1.16 million credit and debit cards may have been affected.
Michael Regal, editor at large for Bloomberg News said on "CBS This Morning: Saturday" that consumers should not be held responsible for any fraudulent charges following the breach, but urged anyone who's shopped at the store in recent months to check their credit card statements carefully for any unusual activity.

Staples is offering free credit monitoring, identity theft insurance and a free credit report to any customers who used a credit or debit card at the affected stores during the breach. It posted the specific locations and dates online.