Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Thursday, February 7, 2019

Is your business PCI compliant? Avoid fines for breaches!

Major breaches like TJMaxx and Target have been widely publicized in the past, but breaches at smaller businesses have received very little attention. This is mainly because information about these smaller occurrences have been very hard to come by due to two reasons.

First, not all states have disclosure laws requiring merchants to disclose breaches and secondly, card associations are not required to disclose individual cases.

According to a Wall Street Journal article, most breaches come from small businesses who are not up to date with technology or compliance laws. Here are some of the article highlights:
  • More than 80% of the credit card breaches have occurred at small businesses.
  • Visa levied $3.3 million in fines for non compliance against small businesses in just one year.
  • MasterCard did not disclose their fines.
  • Any business that accepts credit cards must agree to be PCI complaint.
Take for example the case study of Lodi Beer, a microbrewery and restaurant in California who unknowingly stored 11,728 credit card records in their point of sale system. (Track data from the credit card's magnetic strip cannot be stored according to PCI standards). When that data was breached, Visa and MasterCard fined Abanco, the restaurant's merchant account provider, $27,000. Abanco then in turn passed that fine onto the restaurant. In addition to the fines, this merchant has spent over $50,000 in remediation costs, legal fees, upgrades, etc. That is a huge amount of money for a small business. Had they been up to date with their technology, this situation could have been avoided.

Here are some interesting facts that you should know about PCI compliance standards:
  • Visa, MasterCard and the other card brands have put the responsibility  of maintaining compliance status on the processor or merchant account provider. They've successfully done this with a policy of making them responsible for paying fines when breaches occur.
  • While these processors are responsible for fines, they will almost always pass whatever they're fined onto the merchant.
  • If merchants are ultimately responsible for the fines, it is their responsibility to maintain PCI standards and stay up to date with their technology.

IES would love to help you become compliant. Give us a call at 781-816-9437 or check us out online at iesAdvisors.com.

Tuesday, September 27, 2016

Yahoo hack: It's not just Verizon; AT&T customers should be worried too.

The massive hack that Yahoo disclosed last week is a headache for Verizon, the telecom giant set to take ownership of the company early next year.

Rival AT&T should be nervous too...

That's because many AT&T customers get the option to use a Yahoo Mail account to manage services like home broadband, wireless and pay-television services.

It's the outgrowth of a partnership from 15 years ago between Yahoo and AT&T (then called SBC Communications), bringing AT&T broadband customers to Yahoo's search engine and media services, including Yahoo Mail. At the time, critics hailed the deal as a landmark partnership that would better combat the growing power of AOL and Microsoft's MSN portal.

Today, AOL is part of Verizon, Microsoft's MSN is no more and AT&T likely isn't feeling so great about the deal.

Yahoo said Thursday that the hack compromised at least half a billion accounts containing user names, email addresses and passwords. That makes it the biggest attack ever. US Senator Mark Warner has asked the Securities and Exchange Commission to investigate the matter.                                    
The hack puts AT&T in an uncomfortable position. The company is still waiting for data from Yahoo on the specific customers who may have been affected, according to a person familiar with their dealings.

"We began investigating immediately and requested information from Yahoo necessary to determine which email accounts may have been compromised," the company said in a statement. "In the meantime, we are in the process of notifying potentially affected customers."

Chances are, a significant number of AT&T customers are affected.

AT&T was in the middle of breaking up with Yahoo before the attack, having announced in May that it would instead tap Synacor to handle its internet and mobile portal business.
The loss of the deal, worth an estimated $100 million a year, came at a time when chatter had heated up over potential suitors for Yahoo. AT&T was among the rumored bidders, but Verizon snagged the internet pioneer with a $4.8 billion offer.

For now, AT&T is offering little advice to its customers beyond the standard line: regularly change your passwords.

That, along with these other tips, is advice everyone should heed.

Monday, September 26, 2016

This is what you should do if your Yahoo account was hacked.

The company said on Thursday at least 500 million user accounts were affected by a massive data breach. The hack happened in 2014, when "state-sponsored actor" stole account information, including names, emails, passwords, telephone numbers and answers to some security questions.

So what should you do if you have a Yahoo account?

First and foremost, you'll want to change your password immediately. All Yahoo account holders should also change their security questions and answers.

If your account is one Yahoo suspects was compromised, you'll be prompted to enter a new password as soon as you log on. If you used the same password on other accounts, change those, too.

Here are other steps to take to secure your online accounts.

Change passwords often
Yahoo is asking anyone who hasn't changed their password since 2014 to update it. This is good advice for everyone: Passwords should be changed often. You won't always get a timely notice from a company that an account was compromised -- and sometimes it might not even know about a hack until much later. In this case, it took two years for the company to confirm the breach.

Never use the same password twice
If hackers get the password for one of your online accounts, they can try to use it to access your other accounts that take the same credentials.

Pick better passwords
Consider using a phrase instead of single words that are more easily guessed. Don't go for common phrases like cliches: Pick a combination of words that don't go together -- i.e. rather than "herecomesthesun," go for something like "waterfiresnowsunshine".

Avoid using common passwords like 1-2-3-4-5-6 or p-a-s-s-w-o-r-d, and include a mixture of numbers, letters and characters.

Use a password manager
Since strong unique passwords are a huge pain to memorize, try a password manager like 1Password or LastPass. These platforms generate and store passwords and security answers for every account you have, so you only have to remember a single master password.

Update those security questions
If you forget a password, using security questions is an easy way to gain access back into your own account -- its not like you'll ever forget your mom's maiden name. But some Yahoo security answers and questions were a part of the breach. The company has already disabled any unencrypted security answers on its accounts.

If you frequently use the same security questions and answers for other online accounts, you'll want to change those, as well. Attackers could use the information taken from Yahoo to obtain access to other online accounts that contain even more sensitive information.

Avoid choosing the obvious questions and don't provide answers that are easy to find online through Google searches or social media sites.

Be alert
The company is urging users to look through their Yahoo accounts (email, calendar, groups, etc.) for any signs of suspicious activity. Although it doesn't say what to look for, start by checking outgoing emails.

Be extra careful about clicking on links or opening downloads from unknown email addresses. If anyone emails asking for your password, it's a red flag -- even if it looks like it's coming from a legitimate place like Yahoo or a bank. Never share any account information or passwords over email.

Turn on two-factor authentication
On its own, a password isn't a strong line of defense. Adding a second type of authentication, like a one-time code sent over text message or generated by an app, can greatly secure your online accounts.

Yahoo is recommending people turn on its two-factor authentication tool: Yahoo Account Key. It even eliminates the need to memorize a Yahoo password.

If you use the Yahoo Android or iOS app, log in to your account, go to your profile and select Account Key. You can also set it up in a web browser. Each time you try to access your account, Yahoo will send a confirmation to your phone.

While it's certainly an extra step, make it a part of your daily routine. Next time there's a story about a massive data breach, you'll be glad you did.

Tuesday, December 23, 2014

Confirmed: 1.16 million credit card numbers stolen in Staples breach.

Staples said that malware infected the checkout stations at 115 of its 1,400 U.S. stores. It began removing the software in mid-September. Investigations in the meantime revealed that shoppers who made purchases at these stores across the country going back as far as July may have had their credit card numbers, expiration dates, verification codes and their names stolen in the hack.

In a statement, Staples said that 1.16 million credit and debit cards may have been affected.
Michael Regal, editor at large for Bloomberg News said on "CBS This Morning: Saturday" that consumers should not be held responsible for any fraudulent charges following the breach, but urged anyone who's shopped at the store in recent months to check their credit card statements carefully for any unusual activity.

Staples is offering free credit monitoring, identity theft insurance and a free credit report to any customers who used a credit or debit card at the affected stores during the breach. It posted the specific locations and dates online.

Friday, October 3, 2014

JP Morgan Chase admits to a significant data breach.

Today, JP Morgan Chase revealed that information on 76 million households and 7 million businesses was stolen from their systems due to malware on an employee laptop. This is added to the Home Depot and Target breaches. Here are a few things you can do to protect your personal information...
  • Change all banking passwords
  • Do not reuse passwords amongst banks
  • Monitor all of your accounts (even those not with JP Morgan)
  • Ask for alerts:
    • Daily balance via email & text message
    • Alerts for transactions over $500 (or whatever level you desire)
    • Alerts for number of daily transactions
    • Alerts when balance falls below a certain amount
  • Use 2-factor authentication
  • Avoid using debit cards
  • Minimize online banking
Demand Chase hold it’s software and security vendors accountable for their lapses - after all, they spend millions (if not billions) of dollars on this software. We as individuals cannot force Microsoft, Adobe, Oracle, Cisco, and other software manufacturers to improve their security. It will take a large customer like JP Morgan Chase to force the software industry to deliver secure, hardened software.

Sources:
NYTimes.com
BusinessInsider.com