Last week I blogged about seven restaurants filing a lawsuit against Radiant Systems after the recent breach. (Radiant Systems Sued Over Data Breach - Million$ $ought)



Here's some more on the subject:  The overview below is from Wired and the analysis is from Avivah Litan, distinguished analyst at Gartner...

"Seven restaurants have sued the maker of a bank card-processing system for failing to secure the product from a Romanian hacker who breached their systems.



The restaurants, located in Louisiana and Mississippi, have filed a class-action suit against Georgia-based Radiant Systems for producing a point-of-sale (POS) system that they say was not compliant with payment card industry security standards and resulted in an undetermined number of customers having their debit and credit card numbers stolen.



The suit alleges that the system stored all of the data embedded on the bank card magnetic stripe after the transaction was completed — a violation of industry security standards that made the systems a high-risk target for hackers. Also named in the suit is Computer World, a Louisiana-based retailer, which sold and maintained Radiant’s Aloha POS system."
Continue Reading at Wired



Meanwhile,  Gartner has published an analysis of the Radiant Systems/ComputerWorld breach and ramifications thereof:



Lawsuit Highlights the Hidden Risks of PCI 'Compliance'

A lawsuit serves as a reminder that card-accepting businesses can be held liable for Payment Card Industry security compliance failures, even when they have been told their vendors or service providers are fully compliant.



X

News Analysis

Event

On 23 November 2009, a law firm representing seven restaurants in Louisiana and Mississippi announced that it has filed a class-action lawsuit against Radiant Systems, an Alpharetta, Georgia-based maker of point-of-sale (POS) systems, and Computer World Inc., a Scott, Louisiana-based POS system distributor. The suit alleges that Radiant Systems and Computer World sold the restaurants Aloha POS systems that were incorrectly described as compliant with Payment Card Industry (PCI) related security standards, despite having been informed by Visa that they were not. The suit further alleges that these systems and related poor business practices contributed to major data security breaches that resulted in multiple cases of identity theft and some of the restaurants being fined by credit-card issuers or required to submit to forensic audits.

Analysis

Gartner is not a law firm, and makes no judgment as to the merits of this or any other lawsuit. However, these allegations — whether or not they are ultimately upheld in court — point to serious, long-standing problems with the PCI compliance process. Card brands such as Visa and MasterCard typically send alerts about noncompliant products or services to their member banks, not to card-accepting businesses and other direct purchasers of these technologies. For this reason, it is unfair for the card brands and processing companies to penalize end users who are unaware of problems with the technology. POS system purchasers — particularly small businesses — cannot be expected to be experts in the credit card processing certification process, especially when they don’t necessarily have access to the communications surrounding the process.

Merchants are ultimately responsible for validating vendors' and service providers' claims, but the card brands should implement proactive awareness programs when they know that vulnerable payment technologies are in active use. They should also provide standard contract language that card-accepting businesses can insert into contracts with vendors or service providers to ensure that their products or services are compliant with PCI-DSS or PA-DSS, and that forces the vendors or service providers to assume liability for breaches resulting from deficiencies in their hardware, software or processes.

Recommendations

Card-accepting businesses:

Card brands:

  • Communicate alerts directly and proactively to card-accepting companies, and issue guidance to these companies on how to manage contracts and liability issues with technology and service suppliers.

Recommended Reading

"Where Does End-to-End Encryption for PCI End?" — U.S. payment processors are introducing proprietary end-to-end encryption services to their retailer customers in an attempt to strengthen security for card data in transit. By Avivah Litan



"Using Tokenization to Reduce PCI Compliance Requirements"
— “Tokenization” of cardholder data can be used to reduce the scope of PCI compliance audits, but the available products and services are still limited and immature. By Avivah Litan and John Pescatore



(You may need to sign in or be a Gartner client to access the documents referenced in this First Take.)

Posted by John B. Frank Tuesday, December 1, 2009 0 comments



This Program Provides Secure Prepaid Cards to Consumers in Retail and Other Locations



GOLDEN VALLEY, Minn.--(BUSINESS WIRE)--Veritec, Inc. (OTCBB: VRTC.OB), a developer of mobile banking debit card solutions and a pioneer and developer of proprietary two-dimensional matrix technology, today announced that its subsidiary, Veritec Financial Systems, Inc. (“VTFS”), entered into a memorandum of agreement with Cities in Touch (“CIT”) of Hot Springs, Arkansas to integrate VTFS’ mobile banking software platform with CIT’s ATM and debit card issuing kiosk systems.



VTFS markets and sells prepaid card programs and provides back-end prepaid card processing services on behalf of Security First Bank to card sponsoring organizations. VTFS markets its prepaid card programs under its MTC and Blinx On-Off brands. In addition to serving as an ATM machine, CIT’s kiosk systems enable consumers to securely cash checks, pay bills, transfer money and obtain pay day loans. By integrating VTFS’ and CIT’s respective systems, consumers will benefit by being issued secure reloadable debit cards that may be used at most ATM machines and when making retail purchases. VTFS’ debit cards are more secure than cash in that consumers will be able to turn their debit cards “on” and “off” with their mobile phones.



“Veritec is very pleased to enter into this agreement with Cities in Touch,” said Van Tran, Executive Chair of Veritec. “CIT provides convenient as well as special and important services to members of our community, and Veritec is able to help these consumers by providing a reloadable and highly secure financial product that is a better and safer alternative to cash.”



“Veritec’s prepaid card products and services will enable CIT to be in a position to offer new and exciting products and services to its customers,” said Randy Dodd, President of CIT. “It has also provided CIT with a service that helps us reduce the need for keeping a significant amount of cash in our kiosks and this helps make CIT’s operations and the kiosk owners’ operations more secure.”



The parties expect to conclude the terms of a definitive agreement during the month of December, 2009.



About Veritec, Inc., VTFS and Security First Bank



Veritec, Inc. is a pioneer and developer of proprietary two-dimensional matrix technology. The company’s portfolio of products includes its proprietary VeriCode® and VSCode® 2D matrix symbology solutions, BioID - VSCode® multi-purpose card solutions, and suite of products known as PhoneCodes™ for delivering electronic tickets, coupons and gift cards to mobile devices (www.veritecinc.com). Veritec Financial Systems, Inc. is a wholly owned subsidiary of Veritec, Inc. VTFS develops and licenses mobile banking debit, gift and prepaid card solutions and serves as a third party processor to banks for debit card transactions on the company’s mobile banking platform (www.vtfs.com). Security First Bank of Fresno, California is a California commercial bank authorized to engage in the commercial banking business. Deposits are insured by the FDIC up to the applicable limits of the law (www.securityfirstfresno.com).



About Cities in Touch



Established in 1996, Cities in Touch is a Hot Springs, Arkansas company. CIT’s goal is to furnish a state of the art kiosk which houses an ATM and provides bill payment, wire transfers, check cashing, payday advance, prepaid phone, wireless PIN, wireless recharge, prepaid debit cards and advertising, all in one unit that can be installed in a user friendly atmosphere, offering all of these services through the technology of a touch screen monitor. CIT’s ability to provide information through public access terminals offers resources for people everywhere, anytime. We customize ads, logos, animations and graphics. CIT is, in effect, a partner with the merchant for the full term of an agreement and therefore has a financial interest in the success of every Kiosk/ATM terminal. Our software has been designed in-house and allows us to write plug-ins to adapt to most environments. We pride ourselves in being a total turn-key company with the ability to build our own enclosures and provide the hardware, software and other peripherals that can take a project from start to finish (www.citiesintouch.com).



Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

17th Annual ATM, Debit & Prepaid Forum



Rewind ATM, Debit & Prepaid Forum 2009





“The topics this year were very diverse and covered many relevant topics.

I didn’t want to miss any sessions.”

Jill Weber, ATM Network Manager, Citizens Bank



On October 18-20, 2009, more than 650 payment industry players gathered in Las Vegas for the 17th Annual ATM, Debit & Prepaid Forum. We are sorry that you were not able to attend this year.  Based on feedback from conference attendees, the quality of information presented by speakers, the level of detail, the industry expertise, the depth and breadth of information was unparalleled!




Here’s your chance to access twenty-two sessions
* from the 17th Annual ATM, Debit & Prepaid Forum in webcast format. The webcasts of 22 conference sessions are available for purchase for only $99.






To preview the session webcast, click here.



To purchase the webcast package, click here.





Click here for a preview of the session webcast:

KEYNOTE ADDRESS:

Creating a Framework for Payments Innovation




Dominic Venturo, Chief Innovation Officer

Retail Payment Solutions,
U.S. Bank





These webcasts provide you with audio, and the accompanying session slides, plus the interactive Q&A at the end of the sessions.



Purchase NOW!


*Only sessions with speaker authorization are available for purchase. Individual sessions are not available for purchase. All 22 sessions are sold as one webcast package for $99.

Posted by John B. Frank 0 comments



MENTOR, Ohio, Dec. 1, 2009 (GLOBE NEWSWIRE) -CardinalCommerce, the worldwide leading enabler of payment brands, today announced the hiring of Charles R. Vojtas, an IT veteran with front line retail eCommerce and mobile Commerce experience. Vojtas will serve as CardinalCommerce's Vice President of Design and Development.



Charles Vojtas brings over 13 years of Information Technology experience and expertise and has held key positions including Manager of Corporate Development and Director, Development at Footlocker.com/Eastbay. His hands-on experience within the eCommerce retail world in design and development, quality control, mobile commerce implementations and overall eCommerce strategy have allowed him to successfully establish a proven track record of success in the direct to consumer marketplace.



Mr. Vojtas will be responsible for managing the ongoing development of Cardinal's product suite including: Cardinal Centinel(R), the worldwide leading technology which enables over 25 eCommerce payment brands through one integration; Cardinal MAX, the mobile platform allowing merchants to expand into mobile commerce, banking, marketing, and payments; and 2IDENTIFI, authentication solutions for financial institutions.



All Cardinal platforms have experienced significant growth in 2009.



"The experience and knowledge that Mr. Vojtas brings to his role is timely with the current and expected growth all of our products and services," said Michael A. Keresman, III, Chief Executive Officer, CardinalCommerce. "We welcome Mr. Vojtas on board and look to strengthen all of our offerings as a result."



Charles Vojtas stated: "First, I'm truly grateful to have worked for a company like footlocker.com/Eastbay.



"I learned Customers demand security, payment options, and portability. Now, at Cardinal, I recognize the tremendous growth potential for our eCommerce and mobile commerce platforms with CardinalCommerce solutions delivering on all three, providing easily integrated tools to answer these demands. I am particularly excited about the opportunity I will have to engage companies directly, partnering with them to integrate these solutions, and seeing the benefit it will bring to their platforms and to their Customers."



About CardinalCommerce




CardinalCommerce Corporation is the global leader in enabling authenticated payments, secure transactions, and alternative payment brands for both eCommerce and mobile commerce.



Cardinal Centinel(R)* enables payment brands such as Verified by Visa, MasterCard(R) SecureCode, Amazon Payments, Bill Me Later(R), ClickandBuy(R), Cred-Ex(R), Ebates, eBillme, eLayaway, Google Checkout, Green Dot(R) MoneyPak(R), JCB J/Secure, Mazooma, Moneta(R), MyECheck, NACHA(R) Secure Vault Payments (SVP), OneTouch Online Purchasing, paysafecard, PayPal, RevolutionCard, SafetyPay, TeleCheck(R), Ukash, and more to a network of thousands of merchants and merchant service providers.



Our mobile commerce platform, Cardinal MAX, makes it simple for retailers to sell and market products through the mobile channel. Cardinal's proprietary and easily deployable technology provides consumers, merchants, credit/debit card issuers, and processors the ability to conduct authenticated Internet, wireless and mobile transactions safely and securely. Our bank authentication platform, 2IDENTIFI, offers authentication solutions for financial institutions and processors.



Headquartered in Cleveland, Ohio, with facilities in the United States, Europe, and Africa, Cardinal services a worldwide Customer base. For more information, visit www.cardinalcommerce.com



Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments



Cybercriminals plant poisoned webpages which install malicious Trojan horse

Here's the Warning from Sophos:



IT security and data protection firm is warning computer users keen to read the latest developments in the story about the Tiger Woods car accident that they may be walking straight into a trap set by hackers.



Sophos discovered that hackers were not slow to take advantage of the breaking news story, and by early Saturday morning had created webpages which claimed to contain video footage related to the incident, but that were really designed to spread dangerous malware.



By using content related to the top golfer's mysterious car accident and his alleged relationship with New York party girl Rachel Uchitel, the cybercriminals have made their attack timely and ensured that it will feature high up in search engine results, increasing the chances of unsuspecting victims visiting the site.



"The Tiger Woods story has been one of the top news stories around the world this weekend, and search engine statistics show that many people have been hunting for developments via the web. Hackers don't waste any time jumping on the coat-tails of a hot news story like this, in their attempt to infect as many computer users as possible," said Graham Cluley, senior technology consultant at Sophos. "Foolhardy internet users who believe they are about to watch video footage related to Tiger Woods's current troubles may find the website is trying to surreptitiously install a Trojan horse onto their computer, handing control over to cybercriminals."



Sophos notes that if computer users do visit the poisoned webpages, a malicious Trojan horse known as Troj/Proxy-JN can be installed on their computers, allowing hackers to relay spam via the victim's PC without their knowledge.



"This is a threat both for home users and companies. Many people may return from the weekend and use their office PCs to find out the latest news this morning - only to have their computers silently infected," continued Cluley.





More information about this threat, including images of an infected webpage, is available on Graham Cluley's blog


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments







Bill Kurtis, Wayne Best and Bob Carr to Address Global Electronic Commerce Leaders



(Seattle, WA—December 1, 2009) The Merchant Risk Council (MRC) is excited to announce the Keynote Speakers for the MRC’s 2010 Annual e-Commerce Payments and Risk Conference at the Wynn Las Vegas Resort on March 16-18, 2010.



Wayne Best, economist from Visa, Inc. will deliver the opening keynote address, while Bob Carr, founder and CEO of Heartland Payment Systems and Bill Kurtis, investigative reporter and television personality, provide the conference’s closing keynote speeches.



“We are thrilled to have Wayne, Bob and Bill join us in Las Vegas for our annual conference,” said Tom Donlea, MRC Executive Director. “These speakers, as well as the other scheduled conference presenters, will give our attendees a panoramic view of the issues that most affect e-Commerce security and profitability.”



The 2010 Annual Conference and MRC Platinum Meeting will include more than 50 speakers and panelists, 40 unique sessions, and more than 45 payment and risk industry exhibitors – all delivering unique and valuable insight and information on the growth, diversity and risks associated with global online payment trends and strategies, managing and reducing chargebacks, identifying global cyber threats, and utilizing the newest fraud prevention tools.



“The electronic commerce industry is becoming increasingly diverse,” said MRC Board Chairman, Tom Sullivan, Sr. Director, Global Payments & Risk, Expedia, Inc. “There are so many new players providing products and services that are fundamentally changing how the world communicates and does business.” Sullivan adds, “The MRC conference has evolved into the premier annual event, where a wide variety of e-Commerce and multi-channel merchants share payments, security and fraud best practices.”



Over the past decade, the MRC has evolved from a select group of merchants, networking about online fraud prevention, into the world’s foremost organization dedicated to educating the industry on issues relating to e-Commerce risk and payments. The 2010 Annual Conference unites the world’s top internet and multi-channel merchants, credit card brands, electronic payment processors and providers, risk management providers, law enforcement agencies and various consultants and educators in discussing how to make shopping on the internet easier, safer and more efficient for all involved.



Those scheduled to participate in the 2010 Annual e-Commerce Payments and Risk Exhibit Hall include: Accertify, American Express, Bill Me Later, Chase Paymentech, ClearCommerce, CyberSource, Digital River, Discover, Ethoca, Experian, 41st Parameter, GlobalCollect, iovation, JCB, Kount, LexisNexis, Litle & Co., Quova, Retail Decisions, RSA, Trustwave, Verifi and Vindicia.



For registration or exhibition information for this conference, or to receive MRC membership information, please visit the MRC’s website at www.merchantriskcouncil.org.



About the Merchant Risk Council



The Merchant Risk Council (MRC) is a merchant-led trade association focused on electronic commerce risk and payments globally. The MRC leads industry networking, education, benchmarking and advocacy programs to make electronic commerce more efficient, safe and profitable.



Today, with the power of its member-base, the MRC is the leading trade association for managing payments, preventing online fraud and promoting secure e-Commerce. The MRC is dedicated to working with e-Commerce and multi-channel merchants, payment processors, credit card issuers, credit card companies, alternative payment providers, risk management experts, and law enforcement to make the Internet a safer and more profitable place to conduct business.



The MRC Board of Directors and Advisors includes: Accertify, Apple, Chase Paymentech, CyberSource Corporation, Dell Inc., Discover, Expedia Inc., Gap Inc. Direct, GlobalCollect, Linden Lab, Microsoft, Neiman Marcus Direct, PayPal, Trustwave, Visa Inc. and Wal-Mart.



The MRC is headquartered in Seattle, Washington.



CLICK HERE for Information and Registration for the MRC's 2010 Annual e-Commerce Payments and Risk Conference

March 16-18, 2010 at Wynn Las Vegas




# # #





Posted by John B. Frank 0 comments



Fiserv, Inc.now offers the new vertical-format Visa card - an innovative design option that displays all card information vertically rather than horizontally.  According to  Fiserv, this "breakthrough look" supposedly captures cardholder interest and provides a new way to showcase an issuer's logo.  Newer, but not new. (see Garanti's version below right)



Fiserv Takes an Innovative Turn on Visa Cards

New vertical format captures cardholder attention




Brookfield, Wis., December 1, 2009 - Fiserv, Inc. (NASDAQ: FISV), the leading global provider of financial services technology solutions, now offers the new vertical-format Visa(R) card ? an innovative design option that displays all card information vertically rather than horizontally. This breakthrough look captures cardholder interest and provides a new way to showcase an issuer's logo.



"Fiserv is continually innovating to deliver product and service enhancements that help clients differentiate their card offerings and grow transaction volumes," said Jorge Diaz, division president, Output Solutions, Fiserv. "Our clients are looking for creative ideas that stimulate card activation rates. Vertical cards have visual uniqueness to attract cardholders and encourage increased usage."



The vertical cards are one of several innovations from Fiserv. Others include:

  • The Card Collection(TM) is an exclusive offering of 78 card designs that reflect a broad range of lifestyle themes, money motifs and regional images. Pay-as-you-go ordering eliminates inventory carrying expense and risk of obsolescence.

  • MyCardCreation(SM) makes it simple and affordable for cardholders to create cards with their own pictures on them.

  • Contactless Cards can speed up checkout and maximize convenience by enabling a cardholder to simply hold the card near a terminal or tap the terminal instead of swiping the card.

"The key to increasing transaction revenue is giving cardholders the kinds of cards they'll reach to use over and over," said Diaz. "Fiserv continues to add equipment, processes and technology to provide innovative solutions - like the exciting new vertical cards - to please cardholders and help our clients achieve their card program goals."



Output Solutions from Fiserv is a leading provider of business-critical communications to the financial services, healthcare, telecommunications, investment services and retail markets. Fiserv offers the industry's most complete and secure card-production services, including design, production, embossing, personalization and encoding capabilities. Reinforcing the company's core competency in payments, Output Solutions was ranked first in the last three Madison Advisors Print Industry Best Practices Studies, when measuring the business practices associated with the manufacturing and delivery of personalized documents such as statements, transaction confirmation and checks for print/mail and electronic delivery.



About Fiserv

Fiserv, Inc. (NASDAQ: FISV) is the leading global provider of information management and electronic commerce systems for the financial services industry, driving innovation that transforms experiences for financial institutions and their customers. Ranked No. 1 on the FinTech 100 survey of top technology partners to the financial services industry, Fiserv celebrates its 25th year in 2009. For more information, visit www.fiserv.com.







#   #

Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers