Categories: SecurityWorkspace

Global Payments: Breach Hit Less Than 1.5m Credit Cards

Fewer than 1.5 million credit cards were affected by a security breach reported on Friday, according to Global Payments (GPN), the bankcard payment processor affected by the incident.

On Friday security journalist Brian Krebs reported that MasterCard and Visa sent “non-public alerts” to banks in the US earlier in March regarding a breach. Krebs’ report speculated the incident may have involved more than 10 million card numbers, citing unnamed sources in the financial sector. Later in the day GPN acknowledged that it was the processor involved.

North America affected

The breach took place between 21 January and 25 February, according to the alerts sent by Visa and MasterCard.

GPN acknowledged that “less than 1,500,000” card numbers may have been “exported” by criminals, with the numbers involved all from North America.

The information stolen included card numbers, but not the names, addresses or social security numbers of cardholders, according to GPN. Friday’s report had suggested the breach may have involved full card details, including both Track 1 and Track 2 data, which would have allowed cards to be counterfeited.

“Based on the forensic analysis to date, network monitoring and additional security measures, the company believes that this incident is contained,” the company said in a statement.

GPN, whose shares were halted following the report, said it remained open for business and is working with regulators and law enforcement to limit the incident’s impact on cardholders.

“We are making rapid progress toward bringing this issue to a close,” stated GPN chairman and chief executive Paul Garcia.

Over the weekend, Visa distanced itself from GPN, removing the company from its list of compliant service providers, according to the Wall Street Journal. The company said it has asked GPN to revalidate its compliance with the Payment Card Industry Data Security Standard (PCI DSS).

Visa and MasterCard said on Friday there had been no breach of their own systems. Visa said it has provided payment card issuers with the affected account numbers, enabling them to take appropriate action to protect consumers.

How well do you know Internet security? Try our quiz and find out!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Russia Accused Of Cyberattack On Germany’s Ruling Party, Defence Firms

German foreign minister warns Russia will face consequences for “absolutely intolerable” cyberattack on ruling party,…

11 hours ago

Alphabet Axes Hundreds Of Staff From ‘Core’ Organisation

Google is reportedly laying off at least 200 staff from its “Core” organisation, including key…

11 hours ago

Apple Announces Record Share Buyback, Amid iPhone Sales Decline

Investor appeasement? Apple unveils huge $110 billion share buyback program, as sales of iPhone decline…

15 hours ago

Tesla Backs Away From Gigacasting Manufacturing – Report

Tesla retreats from pioneering gigacasting manufacturing process, amid cost cutting and challenges at EV giant

1 day ago

US Urges No AI Control Of Nuclear Weapons

No skynet please. After the US, UK and France pledge human only control of nuclear…

1 day ago