On CHOW: Can girls use the guys' bathroom?
BNET Business Network:
BNET
TechRepublic
ZDNet

May 8th, 2009

Heartland says malware breach cost $12.6 million

Posted by Ryan Naraine @ 7:26 am

Categories: Anti Virus, Arbitrary Code Execution, Data theft, Exploit code, Malware, PCI, Responsible disclosure, Spyware and Adware, Zero-day attacks

Tags: Bank, Payment, Malware, Intrusion, MasterCard International, Heartland, Financial Services, Viruses And Worms, Security, Ryan Naraine

The data breach at Heartland Payment Systems cost the company a whopping $12.6 million in legal costs and fines from Mastercard and Visa.

Heartland, a publicly traded company that provides bank card payment processing services to merchants in the U.S., made the disclosure less than four months after confirming a malware intrusion that compromised data that crossed its network.

[ SEE: Heartland finds malware in bank card payment system ]

On a conference call with investors yesterday (see transcript), Heartland CEO Robert Carr explained the financial damage from the breach:

This quarter we have taken a $12.6 million charge in expenses and accruals attributable to the processing system intrusion announced in the first quarter. The smaller part of these intrusion related expenses represents legal and other expenses related to the intrusion and less then $1 million related to fines assessed by Visa against our sponsor banks, which fines our sponsor banks are contesting.

More then 50% of this expense however relates to a fine that MasterCard assessed against our sponsor banks ostensibly because of an alleged failure by Heartland to take appropriate action upon having learned that its computer system may have been breached and upon thereafter having discovered the intrusion.

[ SEE: It's a good day to disclose the largest credit card data breach ever ]

Carr said the company is challenging the MasterCard fine:

Heartland therefore considers the MasterCard fine to be in direct violation of both the MasterCard rules and applicable law and it intends and is prepared to vigorously contest and it has recommended to its sponsor banks that they vigorously contest, through all means available including litigation if necessary any liability that may be asserted or imposed upon Heartland or its sponsor banks by reason of this fine.

Following the breach, Carr said Heartland is on schedule to introduce a fully encrypted end-to-end terminal solution in the third quarter.

* Hat tip: Dan Goodin/The Register.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 12 Talkback(s)
Correct.
Many companies have good looking locks on the door but negligent the dog door that is left open. I seen the reformations and measures that PCI industry groups have created awhile back since the start ... (Read the rest)
Posted by: phatkat Posted on: 05/11/09 You are currently: a Guest | | Terms of Use
I don't think ...  n0neXn0ne | 05/08/09
But of course  GuidingLight | 05/08/09
Thank you.....  daMan25 | 05/08/09
Correct.  phatkat | 05/11/09
You just lost an excellent opportunity...  InAction Man | 05/08/09
Could be that he sees people like n0neXn0ne  John Zern | 05/08/09
Can you support that claim or is it a product of your wild imagination?  InAction Man | 05/09/09
Why was the server not patched? Simple: IT laziness  Lerianis | 05/09/09
Please provide some CREDIBLE support for your claims.  InAction Man | 05/09/09
Yes, you do NOT think, why isn't anybody surprised ?  markbn | 05/11/09
Take the fine, critisize the IT department, and don't slack off.  Grayson Peddie | 05/10/09
delete this ...  markbn | 05/11/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here