You are here: silicon.com > Software > Security Strategy

Security Strategy

Hacker publishes credit card numbers on the Web

By Sally Watson

Published: 11 January 2000 00:25 GMT

Online retailers are still reeling this morning after a hacker broke into music store www.CDuniverse.com and stole 25,000 credit card numbers.

In what could be the largest recorded credit card fraud on the Internet, the hacker, simply known as 'Maxus', obtained entry to the US company's 300,000 strong sales database and demanded over £60,000 in blackmail money.

After CD Universe refused to pay, Maxus published 25,000 numbers, expiry dates and addresses on his Web site, and advertised their availability on hacker news groups.

Some reports suggest the credit card details were available from 25 December until last Sunday, when Internet service provider Lightrealm shut down the hacker's site.

The incident could have serious ramifications for online retailers who have repeatedly assured consumers the Internet is a safe place to shop.

This morning, CD Universe's Web site still carried the message: "CD Universe has successfully processed over one hundred thousand credit-card transactions, without a single credit card number being compromised. In February 1997 we were named one of the 10 best commerce sites in the world by PC Week magazine."

According to Michael Walton, CEO of Internet consultancy, Nvision, it was an accident waiting to happen. "It was inevitable. Any hacker worth their salt likes the challenge," he said.

"It certainly says that credit card suppliers and retailers need to be working ever more diligently to improve security online. Bad publicity is worse than any financial loss," he added.

Most of CD Universe's customers will be covered for any losses - at least after the first $50 - by their credit card supplier.

A spokesman for American Express confirmed its customers were covered for fraudulent purchases made over the Internet, and added that the company would work with any affected online retailer to help tighten up security procedures.

The retailer and its software partner CyberCash are so far keeping quiet about the incident.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Business Analyst (Credit Card transactions)

Ideally you will have come from a credit card/ banking background. Business Analyst. You will have recent experience of working within Bank that ...

Risk Analyst - Credit Card Analytics - London WC

A leading retail banking organisation, based in London (WC) currently has a vacancy for a Risk Analyst to join the Credit Card Risk Analytics team. ...

Project Manager - Financial Services

Project Manager, Financial Services, Finance, Store Card, Insurance - 60k-65k One the Europe's most successful retailers is looking for an ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: