NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security

Security


Heartland and RBS WorldPay No Longer PCI Compliant

Vista removes the two payment processors from its list of DSS certified providers

By Lucian Constantin, Web News Editor

16th of March 2009, 08:41 GMT

Adjust text size:


Heartland and RBS no longer on Visa's compliant providers list
Enlarge picture
Following serious security breaches and data theft incidents at Heartland Payment Systems and RBS WorldPay, Vista has removed the two processors from its list (PDF) of providers compliant with the payment industry's security standards, PCI DSS. According to industry experts, this leaves its hundreds of customers in a tough position and susceptible to fines.

RBS WorldPay offers payment-processing solutions that cover credit, debit, Electronic Bank Transfers, gift cards, customer loyalty cards, checks, ATM, and tailored solutions for retail, restaurant, petroleum, convenience stores, grocery, hospitality, transport, and cardholders not present in these sectors. On 23 December 2008, the company announced that, at the beginning of November, unidentified parties had illegally obtained access to its computer systems and potentially compromised the personal information of 1.5 million customers.

RBS also noted that 100 payroll cards had been fraudulently used and had, subsequently, been disabled. It was later revealed that these cards had been employed in one of the most complex and well-coordinated fraud schemes to have ever been instrumented. Over 130 different ATM machines in 49 cities worldwide were hit in a 30-minute period, the crooks successfully withdrawing a whooping $9 million.

Heartland Payment Systems processes payments for over 250,000 mostly small and mid-size businesses and merchants in the U.S. and is considered to be the sixth-largest payment processor in the country. On 20 January 2009, the company announced that, during an internal audit prompted by a Visa warning, it had discovered that transaction data passing through its network had been intercepted and a significant number of credit cards had been compromised.

Financial fraud experts criticized the timing chosen by both companies to make these incidents public, just before Christmas and on the Inauguration Day, respectively. After carefully considering the results of the investigation, Visa has decided that the two companies can no longer be considered in compliance with the Data Security Standard (DSS) established by the Payment Card Industry Security Council.

"Retailers and other companies are not allowed to do business with processors that are not PCI compliant, so this puts all of Heartland's customers and all of RBS's customers out of compliance," Gartner analyst Avivah Litan comments, according to The Register. Companies that are processing a large number of transactions are required to be audited once every year by a qualified security assessor (QSA).

"Visa will consider relisting both organizations following their submissions of their PCI DSS reports on compliance," Visa has announced in a statement. According to SCMagazine, both companies have confirmed that they are in the process of recertification. Heartland has noted that it is currently undergoing the audit for 2009 and expects to be assessed as compliant until May, while RBS WorldPay is confident it will obtain the certification by April.

TAGS:

Heartland Payment Systems | RBS WorldPay | PCI compliance | Data Security Standard | Visa CISP list
Read by 1,331 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


New Payment Processor Data Breach on the Horizon

RBS WorldPay Security Breach Earns Fraudsters $9 Million

U.S. Payment Processor Suffers Major Security Breach

T.J. Maxx Hacker Sentenced to 30 Years in Prison

RBS WorldPay Data Leak Affects 1.5 Million Cardholders

160,000 Users Affected by CheckFree Domain Hijacking

American Express Fails to Promptly Address XSS Flaw

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM