Equifax Hackers Stole 200k Credit Card Accounts in One Fell Swoop

Visa and MasterCard are sending confidential alerts to financial institutions across the United States this week, warning them about more than 200,000 credit cards that were stolen in the epic data breach announced last week at big-three credit bureau Equifax. At first glance, the private notices obtained by KrebsOnSecurity appear to suggest that hackers were first able to steal credit card numbers from Equifax starting in November 2016. But Equifax says the accounts were all stolen at the same time — when hackers accessed the company’s systems in mid-May 2017. Continue reading Equifax Hackers Stole 200k Credit Card Accounts in One Fell Swoop

MasterCard launches Credit Card with Built-In Fingerprint Scanner

MasterCard has unveiled its brand new payment card that has a built-in biometric fingerprint scanner, allowing customers to authorize payments with their fingerprint, without requiring a PIN code or a signature.

The company is already testing the new … Continue reading MasterCard launches Credit Card with Built-In Fingerprint Scanner

Mastercard acquires NuData Security

Mastercard has entered into an agreement to acquire NuData Security, a technology company that helps businesses prevent online and mobile fraud using session and biometric indicators. Terms of the agreement were not disclosed. Mastercard will build on its commitment to drive greater protection in the digital space, integrating NuData to its already robust suite of fraud management and security products. The acquisition will also strengthen its efforts around device-level security and authentication, enabling near real-time … More Continue reading Mastercard acquires NuData Security

Payments Giant Verifone Investigating Breach

Credit and debit card payments giant Verifone [NYSE: PAY] is investigating a breach of its corporate computer networks that could impact companies running its point-of-sale solutions, according to multiple sources. Verifone says the extent of the breach was “limited” and that its payment services network was not impacted.

San Jose, Calif.-based Verifone is the largest maker of credit card terminals used in the United States. It sells point-of-sale terminals and services to support the swiping and processing of credit and debit card payments at a variety of businesses, including retailers, taxis, and fuel stations.

On Jan. 23, 2017, Verifone sent an “urgent” email to all company staff and contractors, telling them that they had 24 hours to change all company passwords. Continue reading Payments Giant Verifone Investigating Breach

Fast Food Chain Arby’s Acknowledges Breach

Sources at nearly a half-dozen banks and credit unions independently reached out over the past 48 hours to inquire if I’d heard anything about a data breach at Arby’s fast-food restaurants. Asked about the rumors, Arby’s told KrebsOnSecurity that it recently remediated a breach involving malicious software installed on payment card systems at hundreds of its restaurant locations nationwide. Continue reading Fast Food Chain Arby’s Acknowledges Breach

Distributed Guessing Attack Reels in Payment Card Data

A research paper describes vulnerabilities enabling distributed guessing attacks which allow an attacker to collect payment card data across a number of sites without triggering alerts. Continue reading Distributed Guessing Attack Reels in Payment Card Data

A new tool can crack a credit card number in six seconds

Credit Card Payment In what amounts to a very clever brute force attack a group of researchers has figured out how to find credit card information – including expiration dates and CVV numbers – by querying ecommerce sites. The process, which was outlined in IEEE Security & Privacy, involves guessing and testing hundreds of permutations of expiration dates and CVV numbers on hundreds of… Read More Continue reading A new tool can crack a credit card number in six seconds

Biometric Authentication: Finding a Balance Between UX and IT Security

When it comes to authentication, most security professionals see it as a necessary evil. It provides security at the expense of the end user’s desire for a frictionless experience. That way of thinking, however, was challenged at the Opus Research Intelligent Authentication 2016 conference. The two-day event made a point to highlight authentication not only […]

The post Biometric Authentication: Finding a Balance Between UX and IT Security appeared first on Security Intelligence.

Continue reading Biometric Authentication: Finding a Balance Between UX and IT Security