EP4: Redemption after data disaster: Heartland Payments breach spurs card data innovation
Manage episode 372326995 series 3479156
In October 2008 Heartland Payment Systems discovered it had been breached. Albert Gonzalez and several other individuals hacked their way through an external company website using SQL injection — an attack that too often still works — to the core of Heartland’s systems. They were able to copy credit and debit card numbers and other data used in payment authorization.
At the time, that data enabled those who bought it to create new magstripe cards.
Some stats about the hack:
- Heartland’s stock price fell by 77% in the months following the attack.
- Some 130 million card numbers were exposed.
- Heartland paid $60 million in fines to Visa, over $40M to Mastercard, $5M to Discover, and $3.6M to AMEX.
- The business of signing up merchants to accept cards using Heartland’s services took a big hit.
To me, this is also something of a hero story. Because Heartland’s leadership, led by CEO Bob Carr, got angry. Yes, at the hackers. But more important they took that anger and frustration and used it to fill a gaping hole in card system security, way out in front of what the card systems themselves required.
I was fortunate enough to play a minor part in Heartland’s response. As an analyst, I got to know some key players who will tell their part of the story in this episode.
Chapters
1. EP4: Redemption after data disaster: Heartland Payments breach spurs card data innovation (00:00:00)
2. Payment Data Breach (00:00:22)
3. Development of Secure Payment Terminals (00:15:24)
4. Voltage's Encryption Solution for Heartland Breach (00:28:00)
5. Advancements in Encryption and Data Security (00:34:24)
16 episodes