<?xml version="1.0" encoding="UTF-8"?>
<incident>
  <arrest type="boolean">true</arrest>
  <breach-type-id type="integer" nil="true"></breach-type-id>
  <comments-count type="integer">12</comments-count>
  <data-recovered type="boolean">false</data-recovered>
  <disputed type="boolean">false</disputed>
  <id type="integer">1518</id>
  <lawsuit type="boolean">true</lawsuit>
  <records type="integer">130000000</records>
  <submission-id type="integer">471</submission-id>
  <updated-at type="datetime">2009-12-10T09:34:05-06:00</updated-at>
  <user-id type="integer">190</user-id>
  <breach-types type="array">
    <breach_type>
      <name>Hack</name>
    </breach_type>
  </breach-types>
  <data-types type="array">
    <data_type>
      <short_name>CCN</short_name>
    </data_type>
  </data-types>
  <timeline-items type="array">
    <timeline_item>
      <first_date>Tue Jan 20 00:00:00 -0600 2009</first_date>
      <type>Organization reports incident</type>
    </timeline_item>
    <timeline_item>
      <first_date>Tue Jan 27 00:00:00 -0600 2009</first_date>
      <type>Lawsuit filed</type>
    </timeline_item>
    <timeline_item>
      <first_date>Mon Jan 12 00:00:00 -0600 2009</first_date>
      <type>Incident discovered by organization</type>
    </timeline_item>
    <timeline_item>
      <first_date>Sun Aug 16 00:00:00 -0500 2009</first_date>
      <type>Arrest made</type>
    </timeline_item>
  </timeline-items>
  <vector>
    <name>Outside</name>
  </vector>
  <primary-organization>
    <business-type-id type="integer">1</business-type-id>
    <freebase-cached-data type="yaml">--- 
companies_acquired: []

net_income: []

name: Heartland Payment Systems
subsidiary_companies: []

ticker_symbol: 
- ticker_symbol: HPY
  stock_exchange: NYSE
market_capitalization: 
- amount: 1000000000.0
  currency: 
  - name: US$
  valid_date: &quot;2007-12-31&quot;
board_members: 
- title: 
  from: 
  member: Richard Vague
  to: 
- title: 
  from: 
  member: Scott L Bok
  to: 
- title: 
  from: 
  member: Jonathan J Palmer
  to: 
- title: 
  from: 
  member: Mitchell L Hollin
  to: 
- title: 
  from: 
  member: Marc Ostro
  to: 
- title: 
  from: 
  member: George F Raymond
  to: 
- title: 
  from: 
  member: Robert H Niehaus
  to: 
type: /business/company
operating_income: 
- amount: 88200000.0
  currency: 
  - name: US$
  valid_date: &quot;2006-12-31&quot;
number_of_employees: []

revenue: 
- amount: 1097000000.0
  currency: 
  - name: US$
  valid_date: &quot;2006-12-31&quot;
</freebase-cached-data>
    <freebase-description>Heartland Payment Systems, Inc. (NYSE:&#160;HPY) is a payroll service provider and the 6th largest credit card processor in the United States specializing in small to mid-sized restaurants and retail merchants. Founded by Robert O. Carr in 1997, HPS is based in Princeton, New Jersey. In processes transactions for more than 250,000 business locations in the United States., totaling about 100 million transactions each month. About forty percent are for small to mid-sized restaurants.
On January 20, 2009, during the inauguration of Barack Obama, HPS announced that it had been &quot;the victim of a security breach within its processing system in 2008&quot;, involving &quot;malicious software that compromised data that crossed Heartland's network&quot;. Robert Baldwin, Heartland's president and chief financial officer,...</freebase-description>
    <freebase-pref-name>Heartland Payment Systems</freebase-pref-name>
    <id type="integer">1459</id>
    <is-private type="boolean" nil="true"></is-private>
    <name>Heartland Payment Systems</name>
    <stock-symbol>HPY</stock-symbol>
    <updated-at type="datetime">2009-02-19T13:53:09-06:00</updated-at>
  </primary-organization>
  <secondary-organizations type="array"/>
  <summary>
    <summary>Malicious Software/Hack compromises unknown number of credit cards at fifth largest credit card processor</summary>
  </summary>
  <comments type="array">
    <comment>
      <content>Washington Post is saying 100,000,000 cards, see the washington post reference.</content>
      <created_at>Tue Jan 20 14:04:39 -0600 2009</created_at>
    </comment>
    <comment>
      <content>This breach is most likely WELL over 100mill.  Heartland does 100mill or more PER MONTH. I would estimate 5-700 mill.</content>
      <created_at>Tue Jan 20 17:07:49 -0600 2009</created_at>
    </comment>
    <comment>
      <content>The PSP in this case is of course PCI compliant? Not! 
If they were Tripwire (or similiar) and malware should have been installed as standard and would have potentially protected against this.......</content>
      <created_at>Wed Jan 21 05:19:35 -0600 2009</created_at>
    </comment>
    <comment>
      <content>Actually, they were PCI compliant as of April 2008.</content>
      <created_at>Thu Jan 22 11:26:01 -0600 2009</created_at>
    </comment>
    <comment>
      <content>
http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf

Service Provider: Heartland Payment Systems
Validation Date: April 30, 2008
Services Covered by Review: Payment Processing
Assessor: Trustwave</content>
      <created_at>Fri Jan 23 04:35:43 -0600 2009</created_at>
    </comment>
    <comment>
      <content>&quot;No confidential merchant data, Social Security numbers, unencrypted personal identification numbers (PIN), addresses or telephone numbers were retrieved in what is believed to be a global cyber-fraud operation. Heartland does not yet know how many card numbers were obtained.&quot; 

http://www.snl.com/irweblinkx/file.aspx?IID=4094417&amp;FID=7249269
</content>
      <created_at>Fri Jan 23 12:42:47 -0600 2009</created_at>
    </comment>
    <comment>
      <content>
An OSF staff member mailed the PCI-DSS contact for Trustwave asking for public comment.</content>
      <created_at>Sat Jan 24 04:32:21 -0600 2009</created_at>
    </comment>
    <comment>
      <content>Suspect supposedly pinpointed per http://www.storefrontbacktalk.com/securityfraud/feds-identify-overseas-suspect-in-heartland-case/</content>
      <created_at>Sat Jan 24 13:13:55 -0600 2009</created_at>
    </comment>
    <comment>
      <content>Lawsuit filed : http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1346268,00.html </content>
      <created_at>Wed Jan 28 14:06:25 -0600 2009</created_at>
    </comment>
    <comment>
      <content>I received a new discover card this week.  The account number did not change, but the expiration and validation code on the back changed.  When I called Discover to activate the card I ask why the change and he acknowledge it was due to the Heartland compromise.</content>
      <created_at>Fri Jan 30 17:01:10 -0600 2009</created_at>
    </comment>
    <comment>
      <content>I've been watching this one since it happened in January.  I just now (May 11th) got notified by Suntrust that my card may have been compromised in this breach.  4 months to notify me?  They've got to be kidding.</content>
      <created_at>Mon May 11 18:17:18 -0500 2009</created_at>
    </comment>
    <comment>
      <content>In a recent update Heartland Payment Systems announced today (January 8, 2010) that it will pay Visa-branded credit and debit card issuers up to $60 million to cover losses incurred from the Heartland data breach.
http://www.bankinfosecurity.com/articles.php?art_id=2054&amp;rf=010910eb
</content>
      <created_at>Mon Jan 11 04:16:10 -0600 2010</created_at>
    </comment>
  </comments>
  <location>
    <address>90 Nassau St, Princeton, NJ 08542, USA</address>
    <thoroughfare_name>90 Nassau St</thoroughfare_name>
    <dependent_locality_name></dependent_locality_name>
    <locality_name>Princeton</locality_name>
    <sub_administrative_area_name>Mercer</sub_administrative_area_name>
    <administrative_area_name>NJ</administrative_area_name>
    <postal_code_number>08542</postal_code_number>
    <country_name_code>US</country_name_code>
    <longitude>40.3499</longitude>
    <latitude>-74.66</latitude>
    <accuracy>8</accuracy>
  </location>
</incident>
