Ask the Experts: Preventing card data breaches
What actions can be taken, both by consumers and the card associations, to prevent another major card data breach, such as those that occurred at T.J. Maxx and Heartland Payment Systems? David Shackleford, chief security officer at Configuresoft Inc., weighs in.
February 11, 2009
In late October, Heartland Payment Systems, a Princeton, N.J.-based company that provides payment processing for roughly 200,000 U.S. businesses, was contacted by Visa and MasterCard about reports of fraudulent activity taking place on cards it had processed. A forensic examination revealed vicious malware on the company's server that was recording private cardholder data, and presumably transmitting it to a third party.
It was disturbing news for a company that processes roughly 100 million transactions per month, 40 percent of which are for small-to-medium-sized restaurants.