Frauds and Ends
  • Our Solutions
  • Customers
  • Partners
  • News & Events
  • Blog
    • Latest Blog Posts
    • About the Authors
    • Subscribe to Blog via Email
  • Company
  • Resource Center



January 23, 2009

Payment Processor Breach Puts Consumers and Merchants at Risk

The Washington Post reported that another large Payment Processor disclosed that they had been breached, potentially exposing 100’s of millions of credit card details to fraudsters.

Robert Baldwin, CFO of Heartland Payment Systems conceed that credit card numbers, expiry dates and names were compromised but commented that

The nature of the [breach] is such that card-not-present transactions are actually quite difficult for the bad guys to do because one piece of information we know they did not get was an address

Im wondering if fraudsters and hackers with this level of sophistication also have access to a White Pages or Facebook search?

Even if information such as CVV code data is not compromised along with the card data, an online merchant still has the option not to decide to make this extra verification information mandatory. Worse, I had a meeting with an Online Payment Gateway yesterday who described how fraudsters pose as legitamet merchant accounts but will then authorize a large volume of stolen credit card transactions which ultimately leave the payment gateway holding hundreds of thousdands in losses.

The Heartland Breach is only one of many, which calls into question the entire notion of a merchant or gateway being able to confidently process a credit card transaction based just on the user’s credentials alone. The shear number of both compromised credit card accounts and compromised computers that fraudsters can conduct transactions through mean that new solutions need to be sought out.

Programs like Verified by Visa mitigate this risk somewhat by requiring an additional password to authentiate the transaction, however this introduces friction into the purchasing experience and is not widely supported.

ThreatMetrix provides its Merchant and Payment Gateway customers with an alternative identity verification method that has zero impact to the customer and her purchasing experience by transparently profiling, identifying and recognizing the actual device used in the transaction.

This provides a number of unique benefits.

Detect credit card list washing: If the credit card details are stolen, ThreatMetrix will detect multiple credit card details linked to the same computer even if fraudsters attempt to spoof their location and IP Address with Proxies, even if transactions are conducted across multiple sites.

Stop first time fraud attempts: Even if a device in the transaction is not recognized, ThreatMetrix provides real-time anomaly detection such as if the transaction is being conducted through a botnet proxy or compromised PC that is infected and under the control of a fraud ring.

Accept more orders and registrations: ThreatMetrix enables merchants and websites to verify whether the combination of the user’s credit card and the device in the transaction has previously been successfully transacted before, allowing the confident acceptance of orders and registrations that might otherwise be rejected.

  •  
  •  
  •  
  •  
  •  
  •  
  •  
  •  

Posted by Alisdair Faulkner Categories: Account Compromise. Botnets. Device Identification. Identity Theft. Online Credit Card Transactions. Online Fraud. Proxies

Leave a Comment

Click here to cancel reply.

  • < Previous Article
  • Next Article >
  • Translator

  • Subscribe

    Subscribe Via Email
    Subscribe to our RSS Feed
    Follow us on Twitter
  • Top Posts

    • Casual Disconnect: Fraudsters Take Fun & Profit Out Of Social Games
    • Catch Me If You Can – Mining Data to Spot Cybercrime Patterns
    • Boys Will Be Boys—And Fraudsters
    • IRCE 2010 Report: What Internet Retailers Really Want for Christmas This Year
    • Marketing & Fraud Detection: Friction or Faction?
  • Additional Resources

    Ponemon Study Ponemon Study:
    Consumer Attitudes on
    Privacy & Fraud Prevention

    download now

    Executive Primer Executive Primer:
    Using Device ID for
    Fraud Prevention

    download now

    Free White Paper Technical White Paper:
    Device Intelligence In-depth

    download now

  • Categories

  • Blog Archives

ThreatMetrix Comics

threatmetrix comics

Episode 10: Global Money Transfer Scam Caught, Find out how ThreatMetrix thwarts Gromyko's money transfer scam plans

View this episode and more >

Blogroll

  • Dark Reading
  • Inside Social Games
  • Javelin Strategy
  • Online Personals Watch
  • Scam Detectives Blog
  • Shop.org
  • The Fraud Blog
  • Virtual Goods

Join Us

  • Twitter
  • Facebook
  • SlideShare
  • LinkedIn
  • Vimeo
  • YouTube
  • News RSS Feed

Become Our Customer | Contact Support | Schedule a Demo | Call us at 1.650.625.1451
© 2010 Threatmetrix All Rights Reserved. Privacy Policy | Site Map | Terms of Service