CardSystems Solutions, the credit-card payment processor at the center of one of the biggest data breaches in recent history, said on Thursday that it hoped to comply with the industry's security standards by the end of next month, at least eight months after data thieves installed software on its computer network to facilitate a break-in.
CardSystems disclosed last month that its computer network in Tucson, Arizona, had been compromised, putting the sensitive account information of as many as 40 million cardholders at risk for fraud.
The company's chief executive, John Perry, acknowledged that CardSystems had been improperly storing data, violating Visa and MasterCard security rules.
On Thursday, CardSystems said it had hired AmbironTrustWave, a security auditor based in Chicago, to assess its data-protection technology, policies and practices. Perry said on June 19 that data thieves had obtained from CardSystems' computer network a file containing the names, account numbers and security code data of about 200,000 cardholders. A person briefed on the matter said that software had been installed secretly on the network to facilitate the theft.
MasterCard and Visa said storing the information on the 200,000 cardholders, even for what Perry called "research purposes," was in violation of their security rules.
At the time, Perry said that the company was taking steps to remedy that practice and that it "no longer stored that data on files." It is unclear if CardSystems was working with another security specialist at that time, but since the incident was disclosed, it said it has bought new software to bolster data protection.
While MasterCard disclosed the incident on June 18, it said that it had focused on CardSystems from as early as April this year. MasterCard did not conclude that the processor's systems had been breached until a forensic investigation by Cybertrust of Herndon, Virginia, in mid-May. But an Australian bank said that it was able to detect fraud related to CardSystems as early as the end of last year.
Even before the breach, CardSystems had taken steps to improve its security. In December 2003, it hired Cable and Wireless Americas, now part of Savvis Communications, to conduct a similar security audit for compliance with Visa rules. Savvis said the company made some improvements and was certified by Visa in June last year. MasterCard said CardSystems was never certified as compliant with its security rules; Visa said CardSystems was no longer in compliance after Visa investigated the processor in May.
Nonetheless, CardSystems was allowed to handle millions of consumer transactions by both card companies and other major brands like Discover Financial and American Express.
RETHINK? The defense ministry and Navy Command Headquarters could take over the indigenous submarine project and change its production timeline, a source said Admiral Huang Shu-kuang’s (黃曙光) resignation as head of the Indigenous Submarine Program and as a member of the National Security Council could affect the production of submarines, a source said yesterday. Huang in a statement last night said he had decided to resign due to national security concerns while expressing the hope that it would put a stop to political wrangling that only undermines the advancement of the nation’s defense capabilities. Taiwan People’s Party Legislator Vivian Huang (黃珊珊) yesterday said that the admiral, her older brother, felt it was time for him to step down and that he had completed what he
Taiwan has experienced its most significant improvement in the QS World University Rankings by Subject, data provided on Sunday by international higher education analyst Quacquarelli Symonds (QS) showed. Compared with last year’s edition of the rankings, which measure academic excellence and influence, Taiwanese universities made great improvements in the H Index metric, which evaluates research productivity and its impact, with a notable 30 percent increase overall, QS said. Taiwanese universities also made notable progress in the Citations per Paper metric, which measures the impact of research, achieving a 13 percent increase. Taiwanese universities gained 10 percent in Academic Reputation, but declined 18 percent
CHINA REACTS: The patrol and reconnaissance plane ‘transited the Taiwan Strait in international airspace,’ the 7th Fleet said, while Taipei said it saw nothing unusual The US 7th Fleet yesterday said that a US Navy P-8A Poseidon flew through the Taiwan Strait, a day after US and Chinese defense heads held their first talks since November 2022 in an effort to reduce regional tensions. The patrol and reconnaissance plane “transited the Taiwan Strait in international airspace,” the 7th Fleet said in a news release. “By operating within the Taiwan Strait in accordance with international law, the United States upholds the navigational rights and freedoms of all nations.” In a separate statement, the Ministry of National Defense said that it monitored nearby waters and airspace as the aircraft
UNDER DISCUSSION: The combatant command would integrate fast attack boat and anti-ship missile groups to defend waters closest to the coastline, a source said The military could establish a new combatant command as early as 2026, which would be tasked with defending Taiwan’s territorial waters 24 nautical miles (44.4km) from the nation’s coastline, a source familiar with the matter said yesterday. The new command, which would fall under the Naval Command Headquarters, would be led by a vice admiral and integrate existing fast attack boat and anti-ship missile groups, along with the Naval Maritime Surveillance and Reconnaissance Command, said the source, who asked to remain anonymous. It could be launched by 2026, but details are being discussed and no final timetable has been announced, the source