The largest credit card data breach ever?
Malicious software in the network of US payment processor Heartland leads to data on 100 million transactions being compromised.
US-based payments processor Heartland Payment Systems was the victim of a massive security breach, which could have exposed customer information associated with the 100 million transactions it handles each month.
Heartland found evidence of the intrusion last week, and notified law enforcement officials as well as the card brands involved. It said that the incident could have been the result of a widespread global fraud operation.
The only data compromised was names, card numbers and expiration dates as well as the information on the card's magnetic strip which could be used to duplicate cards.
Heartland was alerted by Visa and MasterCard of suspicious activity surrounding processed card transactions. An investigation uncovered malicious software compromising data across Heartland's network.
Avivah Litan, analyst at Gartner, told the Wall Street Journal that this was the largest card-data breach ever, even beating the TJX credit card data theft last year.
Richard Wang, of SophosLabs US, said that it appeared the information stolen was enough to create fake cards.
He said on his company's blog: "Although addresses were not compromised by this breach, making card not present' fraud more difficult, this provides one more piece in the puzzle for anyone trying to assemble stolen identities."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"A name and card number from one breach could be used along with name and address from another source to build a more complete identity."
For anyone affected by the breach, more information is available on a specially-created website run by Heartland.
-
Airbnb CEO Brian Chesky says companies need to start building useful AI productsNews The Airbnb chief called for better consumer AI tools to undercut backlash against the technology
-
Software teams should take a leaf out of manufacturers books when it comes to testing codeNews Software testers are struggling to keep up with the pace of code production. UiPath thinks it has the solution
-
Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effectNews The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft
-
Fake North Korean IT workers are rampant on LinkedIn – security experts warn operatives are stealing profiles to apply for jobs and infiltrate firmsNews The scammers' latest efforts mark a significant escalation in tactics, experts have warned
-
Generative AI attacks are accelerating at an alarming rateNews Two new reports from Gartner highlight the new AI-related pressures companies face, and the tools they are using to counter them
-
Cyber teams are struggling to keep up with a torrent of security alertsNews Fragmented identity security processes are creating blind spots, and the proliferation of tools doesn't help
-
CISO job satisfaction is plummeting, and some are considering quitting altogetherNews CISO job satisfaction is being plagued by mounting demands, poor c-suite collaboration, and stressful working patterns
-
The IT Pro Podcast: The front line of fraud techIT Pro Podcast With tools such as deepfakes, the future of fraud tech relies on cutting edge AI as much as good security practice
-
Podcast transcript: The front line of fraud techIT Pro Podcast Read the full transcript for this episode of the IT Pro Podcast
-
LAPSUS$ breached T-Mobile systems, stole source codeNews T-Mobile has denied that the hackers obtained customer or government information