Payment Gateway Provider Breached, Plain Text Data Accessed
Summary
However, the format and method of connection for certain outbound messages enabled the unauthorized person to capture and ultimately then gain access to plain text payment card transaction authorization requests.” CHARGE Anywhere said the malware has been removed from its network since it was discovered Sept. 22. The payment authorization requests, CHARGE Anywhere said, may include cardholder name, account number, expiration date and verification code. “When banks receive these alerts, they can conduct heightened monitoring of transactions to detect and prevent unauthorized charges.” The company also set up a page where consumers can search for merchants by name and location to determine if they were affected by the breach. Security experts and government entities have issued warnings about malware targeting point-of-sale systems and the need to encrypt data. Last week, a Minnesota District Court judge ruled Target negligent in its breach, allowing a litany of class-action lawsuits from consumers and financial organizations to proceed.