Posts

Showing posts with the label Payment Card Fraud

Payment Security: Understanding the Four Corner Model

Image
Introduction Online shopping digital payment transactions may seem quite simple, but in reality, just one single transaction sets off multiple, long-chain reactions. The Payment Card Industry comprises debit cards, credit cards, prepaid, e-purse/e-wallet, and POS payment transactions that enable easy payment transactions for consumers. However, the card scheme is a popular payment transaction process which is also a central payment network that uses credit and debit cards to process payments.  The card scheme comes in two variants namely the Three-Party Scheme and the Four Party Scheme payment model. The Four Corner Model also popularly known as Four-Party Scheme is the model under which most of the payment systems in the world operate. It is used in almost all standard card payment systems around the globe. So, explaining in detail the payment model, we have shared details on how the Four Corner Model works while also explain the role of every entity involved in it The Payment Ne...

Achieving PCI DSS Compliant Firewalls within a Small Business

Image
The most important and integral part of any data security begins with having firewalls installed in the environment. Not just that, installing firewalls is an essential requirement of the Payment Card Industry Data Security Standard (PCI DSS ). However, simply installing a firewall on the network perimeter will not make your organization PCI DSS compliant. PCI DSS draws out specific requirements pertinent to firewalls under requirement 1 and its sub-requirements on how firewalls should be installed, updated, maintained along with other firewall rules. Elaborating more on this, we have explained in this article basic PCI DSS firewall requirements, and the need for small businesses to install firewalls. But before getting into the details of it, let us first understand the meaning of a PCI DSS compliant firewall. What is a PCI DSS Compliant Firewall? Firewalls are used to segment or isolate networks and are an essential component to   limit cyber threats and protect internal networks...

How Much is Your Data Worth on the Dark Web?

You may not know much about the dark web, but it may know things about you. What is the Dark Web? The dark web is a part of the internet that is not visible to search engines. What makes the dark web, dark? it allows users to anonymise their identity by hiding their IP addresses. This makes those using the dark web nearly impossible to identify. Only 4% of the internet is available to the general public, which means a vast 96% of the internet is made up of the deep web. It’s important to note here, that the dark web is just a small section of the internet but it’s a powerful small sector. How much are your bank details worth? The dark web is full of stolen personal bank credentials. It’s common to see MasterCard, Visa, and American Express credentials on the dark web from a variety of different countries. Credit card data in the US, UK, Canada and Australia increased in price anywhere from 33% to 83% in the time from 2015 to 2018. The average price for a UK Visa or Mastercard ...

British Airways Hack Update: Caused by Injected Script & PCI DSS Non-Compliance is Suspected

Image
On Friday (7th September 2018),  British Airways disclosed   between 21st August 2018 and 5th September 2018, 380,000 BA customer's payment card transactions were compromised by a third party through its website and mobile app. This data included the customer's full name, email address, debit\credit card 16 digit number (PAN), expiry date and card security code i.e. CVV, CV2 Details of how the hack was orchestrated have now come to light.  In  a blog post RiskIQ researchers  have claimed to have found evidence that a web-based card skimmer script was injected into the BA website, very  similar to the approach used by the Magecard group, who are believed to be behind a similar attack against the  Ticketmaster website recently . Web-based card skimmer script attacks have been occurring since 2015. In this case, once the customer has entered their payment card details and then submits the payment either on a PC or on a touchscreen de...

British Airways Customer Data Stolen in Website and Mobile App Hack

Image
In a statement, British Airways stated: " From 22:58 BST August 21 2018 until 21:45 BST September 5 2018 inclusive, the personal and financial details of customers making bookings on ba.com and the airline’s app were compromised ." The airline said they will be notifying affected customers, and if anyone has been impacted to contact their bank or credit card providers. The Telegraph reported 380,0000 payments were compromised, and that BA customers had experienced payment card fraud as a result before the BA breach disclosure, which strongly suggests unencrypted debit\credit cards were stolen. There are no details about the data theft method at the moment, but given the statement said the BA website and BA mobile app was compromised, I think we could be looking at another example of an insecure API being exploited, as per the  Air Canada breach  and the T-Mobile breach last month. We'll see what comes out in the wash over the next few days and weeks, but...

Cyber Security Roundup for April 2018

The fallout from the F acebook privacy scandal rumbled on throughout April and culminated with the closure of the company at the centre of the scandal, Cambridge Analytica . Overview of Facebook and Cambridge Analytica Facebook's Zuckerberg faces formal summons from MPs Facebook to contact 87 million users affected by data breach Canada data firm AIQ may face legal action in UK Facebook to vet UK political ads for May 2019 local elections Facebook to exclude billions from European privacy laws Ikea was forced to shut down its freelance labour marketplace app and website 'TaskRabbit'  following a 'security incident'. Ikea advised users of TaskRabbit   to change their credentials if they had used them on other sites, suggesting a significant database compromise. TSB bosses came under fire after a botch upgraded to their online banking system , which meant the Spanished owned bank had to shut down their online banking facility, preventing usage by over 5 mi...

Cyber Security Roundup for March 2018

In the wake of the global political fallout over the Salisbury nerve agent attack, there are reports of a growing threat of Russian state or Russian state-affiliated hacking groups conducting cyber attack reprisals against UK organisations, government officials have directly warned bosses at electricity, gas and water firms, Whitehall departments and NHS hospitals to prepare for a state-sponsored cyber assault .  Russian group Fancy Bear (APT28) were suspected of being behind an unsuccessful attack against the UK anti-doping agency , and China tied hacking group APT15 were found to have infiltrated a UK government contractor’s computer systems by NCC researchers . Large-scale data breaches were disclosed with Under Armour’s Fitness App MyFitnessPal (1.5 million personal records compromised) , Orbitz (880k payment cards at risk) , and at a Walmart partner (1.3 million personal records compromised) . The latter was caused when an AWS S3 bucket holding a Walmart dat...