Visa and MasterCard are investigating a major breach of credit card numbers at a US payment processor, the size of which may exceed anything seen in at least three years.
Global Payments confirmed a breach which occurred in early March, but it did not reveal how many card numbers were involved..
"[The company] determined card data may have been accessed," said a statement. "It immediately engaged external experts in information technology forensics and contacted federal law enforcement. The company promptly notified appropriate industry parties to allow them to minimise potential cardholder impact."
The company's stock price dropped sharply following the news and a spokesperson did not respond to a request for comment.
The amount of victims was unknown. The Wall Street Journal reported some 50,000 cards were impacted, but security blogger Brian Krebs claimed the number could reach 10 million.
Avivah Litan, vice president and distinguished analyst at Gartner, told SCMagazine.com that her sources within the payment industry tell her the breach was sustained by a New York City-based taxi cab/parking garage company, and was the work of a Central American gang.
"The taxi cabs generate millions of transactions over months," she said.
A city Taxi and Limousine Commission spokesman, Allan Fromberg said he wasn't aware of any breach, but said there are 65 so-called "medallion agents" who lease taxi cabs to drivers.
They serve as merchants, as well, and contract with third-parties to process cab fares that are paid with credit card.
Visa, in its statement, said it was contacting "payment card issuers" with information about card numbers that may have been compromised.
PSCU, which provides financial services, such as bill payment solutions, to 680 credit unions, issued a security alert this week to its members after it was contacted by Visa.
The alert obtained by SCMagazine.com reported that 46,194 of the compromised Visa card numbers belonged to PSCU customers, and that the breach lasted from 21 January and 25 February. (The 46,194 number dropped to 26,094 when accounting for duplicate, expired or invalid cards).
No matter the size of the breach, this appears to be the first massive incident involving stolen credit card data since Heartland Payment Systems was hit it to the tune of 100 million card numbers.
"Just when we thought it was safe to go back shopping," Litan joked.
Global Payments is planning an 8 a.m. EST conference call on Monday with investors.