Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Prevent the Top Five Types of Credit-Card Data Breaches

With the 1.1 revision to the Payment Card Industry Data Security Standard (PCI DSS) in September 2006, the weaknesses of the current credit- and debit-card data security system have been made extremely clear. However, shortly after issuance of the revised PCI DSS, Visa completed a detailed study of the card-security environment and released its comprehensive findings* of the five leading causes of card-related data breaches:

  1. Storage of magnetic stripe data—the most common cause of data breaches occurs when a merchant or service provider stores sensitive information encoded on the card’s magnetic stripe in violation of the PCI Data Security Standard. This can occur because a number of point-of-sale systems improperly store this data, and the merchant may not be aware of it
  2. Missing or outdated security patches—in this scenario, hackers are able penetrate a merchant or service provider’s systems because they have not installed up-to-date security patches, leaving their systems vulnerable to intrusion
  3. Use of vendor-supplied default settings and passwords—in many cases, merchants receive POS hardware or software from outside vendors who install them using default settings and passwords that are often widely known to hackers and easy to guess
  4. SQL injection—criminals use this technique to exploit Web-based applications for coding vulnerabilities and to attack a merchant’s Internet applications (e.g. shopping carts)
  5. Unnecessary and vulnerable services on servers—servers are often shipped by vendors with unnecessary services and applications that are enabled, although the user may not be aware of it. Because the services may not be required, security patches and upgrades may be ignored and the merchant system exposed to attack

For complete details on these vulnerabilities and risk-mitigation strategies, please see Visa’s official CISP Bulletin [PDF] on this issue.

*Source: Top Five Data Security Vulnerabilities Identified to Promote Merchant Awareness, Cardholder Information Security Program, Visa U.S.A. Inc., August 2006.