MADISON, Wis.-A data breach announced last week at Heartland Payment Systems, one of the largest to date and possibly affecting 100 million credit and debit cards, has raised the issue of the need for tighter Payment Card Industry (PCI) Data Security Standards, suggests CUNA Mutual Group.
The Princeton, N.J.-based Heartland Payment Systems, a third-party card processor used by 250,000 merchants nationwide, reported that it was the victim of a security breach within its processing system sometime in 2008. The incident is the result of a widespread global cyber-fraud operation, according to Heartland, which said that no merchant data or cardholder Social Security numbers, unencrypted personal identification numbers, addresses, or telephone numbers were involved in the breach.
Heartland was "PCI compliant," explained CUNA Mutual Plastic Card Insurance Product Executive Chuck Cashman. "Hopefully we can continue to put pressure on the (PCI Security Standards Council) to further tighten rules. And I know that's going to get pushback from the merchant side because they think PCI is too strict now. But this breach is the perfect example of how PCI has to be constantly looked at, evaluated, and upgraded."
Cashman told Credit Union Journal that CUNA Mutual has been working with state leagues to support efforts for greater data breach security and could "step up" those efforts.
Heartland reported that malicious software compromised data that crossed its network and that stolen data includes names, credit and debit card numbers, and expiration dates. In October, CUNA Mutual notified Visa and MasterCard of higher-than-normal fraud activity after credit unions began informing the insurer of a spike in plastic card fraud and related activities. "CUNA Mutual Risk Management detected that something big was happening," Cashman said. "We reported our findings to both card associations to help facilitate an investigation to determine if a breach had occurred and, if so, its origin."
According to Cashman, the breach is believed to have started in May and fraud has "likely been occurring since that time. This is a very volatile breach. Before this we used to advise that credit unions monitor their portfolios closely. But this one calls for heightened monitoring."
CUNA Mutual's most recent RISK Alert (left) recommends review of card association alerts to determine "high risk" exposure for future fraud. "Doing so will help them determine what course of action to consider," Cashman said.
Actions To Take
With cards, CUNA Mutual recommends:
* Review Accounts Involved in the Breach. Determine which cards on the card association alerts are active.
* Review Other Accounts. ID which cards on the alerts are non-active and have been closed due to fraud. ID if the fraud pattern on the closed accounts matches that described in the card associations' alerts.
* Monitor or Block and Reissue. Assess compromised cards to determine whether to:
* Monitor the affected cards. If opting to monitor, contact Visa or MasterCard to determine how the CU's action will impact future recovery efforts.
Block and reissue the affected cards. Reissued cards will be encoded with new track information.
For info: www.cunamutual.com under the "Protection Resource Center."










