iTnews

8000 CBA credit card details unleashed in breach

By Darren Pauli, SC Magazine on May 27, 2011 1:08PM
8000 CBA credit card details unleashed in breach

Penalties considered after Mastercard, Visa investigation.

The Commonwealth Bank has cancelled some 8000 credit cards after it detected a data breach at a merchant.

CommBank noticed fraudulent transactions over its network and alerted card issuers Visa and MasterCard, the breached merchant and its acquiring bank, and affected customers.

The bank did not release the name of the affected merchant and its acquiring bank, or when the breach occurred.

“[CommBank] continuously monitors all credit card transactions to protect our customers from fraud and during this process we became aware of a potential credit card compromise through an Australian merchant acquired by another bank,” a spokesperson said.

“Customer cards are being reissued as a matter of priority.”

Mastercard and Visa may issue penalties including fines to the acquiring bank, not CommBank, under the payment industry’s PCI-DSS compliance rules.

The rules impose minimum security standards on merchants according to their size. It demands, among other requirements, that credit card data be encrypted so it could not be read in the event of a data breach.

The severity of the penalties will depend on the merchant’s standard of PCI-DSS compliance at the time of the breach.

The acquiring bank may pass on the penalties to the merchant, but it is common practice in Australia for the banks to absorb the costs.

Australia's Privacy Commissioner is aware of the breach, but did not say if it is investigating the incident.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:
bank cba data breach pcidss security

Partner Content

Beat the DDoS blackmails in 2021
Partner Content Beat the DDoS blackmails in 2021
Why companies fail at picking cloud modernisation partners
Partner Content Why companies fail at picking cloud modernisation partners
Shut the door on ransomware
Partner Content Shut the door on ransomware
MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
Partner Content MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics

Sponsored Whitepapers

Five questions to ask before you upgrade to a SIEM solution
Five questions to ask before you upgrade to a SIEM solution
Effectively addressing advanced threats
Effectively addressing advanced threats
The risky business of open source
The risky business of open source
Ensure your e-signatures are legally binding
Ensure your e-signatures are legally binding
Mitigating open source risk in your organisation
Mitigating open source risk in your organisation

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • Beat the DDoS blackmailers in 2021
By Darren Pauli, SC Magazine
May 27 2011
1:08PM
0 Comments

Related Articles

  • CBA lands an ex-RBA CISO
  • Aussie banks warn customers after fresh PayID data breach
  • New Zealand central bank postpones statistics releases after data breach
  • ADHA sees 'inconsequential' My Health Record data breach notices eroding trust
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Australia Post is building a digital twin of its delivery network

Australia Post is building a digital twin of its delivery network

Google threatens to withdraw search engine in Australia

Google threatens to withdraw search engine in Australia

Trump pardons former Google self-driving car engineer

Trump pardons former Google self-driving car engineer

NBN Co runs fixed wireless tower on diesel generator for over two years

NBN Co runs fixed wireless tower on diesel generator for over two years

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.