Search      Advanced Search | Browse By Topic
Magazine Content
Home
Features
Columnists
Industry Risk Reports
In-Depth Series
Special Reports
Point/Counterpoint
R&I One® Content
News & Analysis
Editor's Choice Stories
Resources and Tools
Power Broker® Directory
Risk InnovatorTM
Emerging Risks
Top Employee Benefits Consultant
Executives To Watch
Insights
Industry Events
WorkersComp Forum
Award Nominations
Webinars
RSS
R&I Information
Subscription Center
Advertiser Information
About Us
Contact Us
 

Newsletter Sign-up

Click on the name of the free newsletter below to preview:

R&I One®
WORKERSCOMP Forum TM Update
HTML Text
E-Mail Address:


Click here to unsubscribe
Privacy Policy
Preferences

 

Hacked: 1.5 Million Credit Card Numbers

Will the Global Payments data breach push more companies to purchase cyberliability coverage?

Print Email Add to Facebook Add to Twitter Add to LinkedIn Write to the Editor Reprints

By JARED SHELLY, senior editor/web editor of Risk & Insurance®

In yet another high-profile cyberdata breach, a large credit and debit card breach was discovered on March 30 by a third-party payment processor.

Global Payments, which processes card transactions, reported that 1.5 million credit card numbers have been exported by hackers, however early reports indicate the villains did not get names, addresses or Social Security numbers.

As a result, Visa removed Global Payments from its list of compliant service providers but the company can reapply after showing it addressed the problem. Meanwhile, Mastercard said it has alerted payment card issuers, while Discover and American Express have released statements saying that they're monitoring the situation.

In a conference call Monday, Global Payments Chairman and Chief Executive Paul R. Garcia said the incident was "absolutely contained," and said there were no fraudulent transactions.

In just the past year, there have been data breaches at Sony's PlayStation Network, Citigroup, the International Monetary Fund, Google and National Public Radio.

One of the largest attacks in recent memory happened in 2008, when Heartland Payment Systems saw 130 million customer accounts compromised in a cyberattack. The company eventually agreed to a $110 million settlement with American Express, and Visa, MasterCard and other card associations.

Although risk managers say cyberrisks are top-of-mind, purchasing such coverage still lags. A 2011 survey of risk managers by Towers Watson found that 73 percent of respondents had not purchased network liability policies.

The recent Global Payments case is just the type of breach to get the attention of risk managers and push them to buy coverage, said Robert Parisi, senior vice president at Marsh, who called the breach "a wake-up call for retailers and how they deal with payment processors."

In fact, clients are already calling Willis' FINEX North America to make sure their risk management plans are sound and that their insurance policies would cover such a breach, said Thomas Srail, senior vice president of the company's Cyber and Errors & Omissions team.

"I expect more retailers, payment processers and tech companies to look at this breach, examine the fines, penalties and regulatory actions, and examine at their approaches to cyber risk," Srail said.

When data losses capture headlines, there tends to be a spike in the number of companies purchasing cyberliability policies.

Before approximately 2004, the only companies that seemed to buy cyberpolicies were in the telecom industry, said Parisi. Now, he estimates that between 10 percent to 20 percent of all companies have such policies. That number jumps to about 40 percent to 50 percent, he said, in industries that routinely handle personal and financial data like retail, credit card companies, banks, higher education and health care.

It remains to be seen if the Global Payments data breach will bring those numbers even higher.

April 3, 2012

Copyright 2012© LRP Publications

 
 
 
 
 
 
 
 
 
 
 
RISK logo
 

Back to top

Entire contents copyright © 2013 Risk and Insurance® All rights reserved. May not be reproduced in any form without written permission.