<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Backup Technology &#187; Online payments</title>
	<atom:link href="http://www.backup-technology.com/category/online-payments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.backup-technology.com</link>
	<description>Backup Technology Blog featuring online backup, disaster recovery and business continuity news</description>
	<lastBuildDate>Thu, 29 Jul 2010 13:57:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>UK financial data targeted by malware campaign</title>
		<link>http://www.backup-technology.com/uk-financial-data-targeted-by-malware-campaign/</link>
		<comments>http://www.backup-technology.com/uk-financial-data-targeted-by-malware-campaign/#comments</comments>
		<pubDate>Wed, 07 Jul 2010 16:03:49 +0000</pubDate>
		<dc:creator>Ritchie</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online payments]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bank fraud]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Password Security]]></category>

		<guid isPermaLink="false">http://www.backup-technology.com/?p=2875</guid>
		<description><![CDATA[A deviously implemented malware campaign has been detected in the UK. It has been targeting the private financial information of thousands of users whilst simultaneously staying off the radar of most mainstream anti-virus software vendors. Anyone who regularly banks online is at risk from the malware, which has the ability to harvest passwords and customer [...]<p><a href="http://www.backup-technology.com/uk-financial-data-targeted-by-malware-campaign/">UK financial data targeted by malware campaign</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></description>
			<content:encoded><![CDATA[<p>A deviously implemented malware campaign has been detected in the UK. It has been targeting the private financial information of thousands of users whilst simultaneously staying off the radar of most mainstream anti-virus software vendors.</p>
<p>Anyone who regularly banks online is at risk from the malware, which has the ability to harvest passwords and customer numbers which then can be used to make transactions within an individual&#8217;s account which seem legitimate to the bank, but are actually the work of criminals.</p>
<p>One out of every 500 computers in the UK is infected with the Silon.var2 malware, whilst one in 5000 has Agent.DBJP onboard, according to security firm Trusteer. This penetration level is much lower than in the USA, but as a result of the regional, small scale targeting it has been much harder for the large security vendors to react to what seems to be a limited, local issue.</p>
<p>Two botnets based in the UK have also been identified and the specificity of these is equally troubling, as UK banks seem to be the only target, with UK-based computers being harnessed to make the attacks. This tactic is another that aims to circumvent the conventional malware detection process of anti-virus firms and it seems as though the criminals have been able to work around many security systems that would usually guarantee the protection of personal data.</p>
<p>The group behind this malware are targeting UK citizens through spam campaigns which centre around local issues, as well as piggybacking on formerly legitimate websites which have become compromised.</p>
<p>Trusteer&#8217;s Mickey Boodaei said that a small number of UK banks were being targeted by the current campaign, with between three and seven being hit at the same time, as opposed to the hundreds of financial institution which can be targeted by the better known data theft tools which are thus largely defeated by the anti-virus vendors.</p>
<p>The small group of target banks are repeatedly attacked for up to nine months at a time, according to Mr Boodaei, before the focus of the criminals changes and the malicious software evolves.</p>
<p><a href="http://www.backup-technology.com/uk-financial-data-targeted-by-malware-campaign/">UK financial data targeted by malware campaign</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.backup-technology.com/uk-financial-data-targeted-by-malware-campaign/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS compliance heads for UK in July</title>
		<link>http://www.backup-technology.com/pci-dss-compliance-heads-for-uk-in-july/</link>
		<comments>http://www.backup-technology.com/pci-dss-compliance-heads-for-uk-in-july/#comments</comments>
		<pubDate>Mon, 21 Jun 2010 09:46:02 +0000</pubDate>
		<dc:creator>Ritchie</dc:creator>
				<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Online payments]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.backup-technology.com/?p=2851</guid>
		<description><![CDATA[The enforcement of the data security standards that govern the payment card industry is beginning next month and experts believe that many UK businesses could face hefty fines as a result of non-compliance. PCI DSS is being instigated by Visa from the start of July. As a result, the electronic point of sale (EPOS) and [...]<p><a href="http://www.backup-technology.com/pci-dss-compliance-heads-for-uk-in-july/">PCI DSS compliance heads for UK in July</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></description>
			<content:encoded><![CDATA[<p>The enforcement of the <a href="http://www.backup-technology.com/">data security</a> standards that govern the payment card industry is beginning next month and experts believe that many UK businesses could face hefty fines as a result of <a href="http://www.backup-technology.com/regulatory-compliance/">non-compliance</a>.</p>
<p>PCI DSS is being instigated by Visa from the start of July. As a result, the electronic point of sale (EPOS) and online retail sites operated by many of the smaller enterprises in the UK could come under scrutiny and be deemed inadequate under the new rules.</p>
<p>Larger businesses have until the end of September to ensure compliance with PCI DSS as the process of converting outdated systems is perceived to be lengthier and more complex within organisations of significant size.</p>
<p>Regulators have divided businesses into multiple tiers in order to separate out those businesses dealing with the most significant volume of transactions annually from those responsible for the least. The first tier businesses are the largest, with six million or more payment card transactions channelled through them annually, while the fourth tier enterprises experience less than 20,000.</p>
<p>Experts believe that Visa will start issuing fines to firms that have not ensured complete compliance as soon as the rules come into effect for that particular tier. </p>
<p>The acquirer will be fined by the payment card firm and these fines and associated costs will be passed onto the non-compliant business, according to Barclaycard&#8217;s head of security, Neira Jones.</p>
<p>Smaller firms from tiers two to four are encouraged to ensure complete PCI DSS compliance, because any breach will not only result in direct fines, but may also move them up the pile to be considered alongside tier one firms and their associated charges, which could have a long lasting impact according to data security expert Mathieu Gorge.</p>
<p>Some believe that smaller firms are being penalised under the new system, with security advisor John Walker suggesting that the limited understanding and explanation of PCI DSS rules to lower tier UK businesses could result in fines and poor treatment for those who unwittingly break the new regulations.</p>
<p><a href="http://www.backup-technology.com/pci-dss-compliance-heads-for-uk-in-july/">PCI DSS compliance heads for UK in July</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.backup-technology.com/pci-dss-compliance-heads-for-uk-in-july/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Visa online payment system targeted by cyber criminals</title>
		<link>http://www.backup-technology.com/visa-online-payment-system-targeted-by-cyber-criminals/</link>
		<comments>http://www.backup-technology.com/visa-online-payment-system-targeted-by-cyber-criminals/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 08:26:15 +0000</pubDate>
		<dc:creator>Ritchie</dc:creator>
				<category><![CDATA[Online payments]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.backup-technology.com/visa-online-payment-system-targeted-by-cyber-criminals/</guid>
		<description><![CDATA[The personal information of millions of online consumers could be put at risk if the latest phishing enterprise, which targets those paying by Visa, is mistaken as legitimate by innocent customers. Andrew Brant, a malware prevention blogger, explained in a recent post that consumers should be wary of any emails claiming to have originated from [...]<p><a href="http://www.backup-technology.com/visa-online-payment-system-targeted-by-cyber-criminals/">Visa online payment system targeted by cyber criminals</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></description>
			<content:encoded><![CDATA[<p>The personal information of millions of online consumers could be put at risk if the latest phishing enterprise, which targets those paying by Visa, is mistaken as legitimate by innocent customers.</p>
<p>Andrew Brant, a malware prevention blogger, explained in a recent post that consumers should be wary of any emails claiming to have originated from Visa and asking them to follow a link and update their payment card details online.<span id="more-2288"></span></p>
<p>The malicious emails link to the phony but authentically designed site and users are then encouraged to enter a significant number of personal details, including answers to any security questions you may have used when setting up your Visa account.</p>
<p>Brant assured readers that this was the first indication that something was afoot, as no Verified by Visa payment type scheme should ever ask you for extensive personal information. This rule is applicable to site online with which you already hold an account and vigilance is essential if consumers wish to avoid having their personal information harvested with their unknowing complicity.</p>
<p>It is believed that this new phishing scam is being perpetrated by a particularly sophisticated group that has put a lot of effort into making the page look authentic. A casual viewer might be hard pressed to tell the difference between an official Verified by Visa page and the fake site.</p>
<p>Online security expert Nigel Hawthorn urged worried consumers to invest in a URL filter for their computers so that they would never accidentally enter information on phishing sites. Because data harvesting via phishing does not utilise virus or malware techniques, but is instead a con based on misleading online shoppers, standard antivirus software will not be an adequate defence.</p>
<p>Hawthorn emphasised the need for additional security tools which do more than just filter spam and remove viruses. He also pointed out that the new Visa phishing campaign could have a widespread effect because Visa itself has been associated with watertight online security in the past, so consumer trust is intrinsically assured by the brand.</p>
<p><a href="http://www.backup-technology.com/visa-online-payment-system-targeted-by-cyber-criminals/">Visa online payment system targeted by cyber criminals</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.backup-technology.com/visa-online-payment-system-targeted-by-cyber-criminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Congestion charging online payments fail during hand-over</title>
		<link>http://www.backup-technology.com/congestion-charging-online-payments-fail-during-hand-over/</link>
		<comments>http://www.backup-technology.com/congestion-charging-online-payments-fail-during-hand-over/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 16:54:44 +0000</pubDate>
		<dc:creator>Ritchie</dc:creator>
				<category><![CDATA[Online payments]]></category>

		<guid isPermaLink="false">http://www.backup-technology.com/?p=2275</guid>
		<description><![CDATA[IBM suffered major setbacks in the nation&#8217;s capital last week after it botched a systems switchover and was taken to court by a local council over a data management matter. On Monday 2nd November IBM was set to take control of the Congestion Charging system from previous operators Capita. However, whilst the transfer of the [...]<p><a href="http://www.backup-technology.com/congestion-charging-online-payments-fail-during-hand-over/">Congestion charging online payments fail during hand-over</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></description>
			<content:encoded><![CDATA[<p>IBM suffered major setbacks in the nation&#8217;s capital last week after it botched a systems switchover and was taken to court by a local council over a data management matter. On Monday 2nd November IBM was set to take control of the Congestion Charging system from previous operators Capita. However, whilst the transfer of the payment system was in process, a catastrophic crash occurred. This prevented customers from making payments via the online system for 9 hours, causing considerable frustration for those affected.</p>
<p>IBM has called the lengthy breakdown an &#8216;interruption&#8217; which it says was caused by a major upgrade to the payment system which occurred in unison with the switch-over. Customers who could not make the Congestion Charge payments online were forced to use either the mobile payment service or to make their payments at one of the many retail outlets in and around London.<span id="more-2275"></span></p>
<p>Transport for London was forced to apologise on behalf of IBM and assured its customers that no one would be improperly penalised as a result of the recent crash. Sources inside TfL claimed that some customers could be issued with incorrect penalty notices. It was also claimed that IBM had not undertaken the necessary planning in order to ensure a smooth changeover, though these allegations have yet to be substantiated.</p>
<p>The downtime further detracted from the reputation of the IT giant after Southwark Council began the process of claiming £700,000 in damages from IBM just three days earlier. The allegations levelled at IBM include claims that they failed to provide the council with a satisfactory Master Data Management system. It was also alleged that IBM failed to act on the findings of a review which identified the key areas of failure within the MDM system.</p>
<p>In response to the lawsuit, IBM stated that it regards the allegations as founded on false evidence and that it will be refuting any limitations to its services during the ensuing legal proceedings. Whether these events will tarnish the reputation of a trusted brand within the capital remains to be seen, but IBM has certainly had its data management skills brought under the glare of the media spotlight.</p>
<p><a href="http://www.backup-technology.com/congestion-charging-online-payments-fail-during-hand-over/">Congestion charging online payments fail during hand-over</a> is a post from our <a href="http://www.backup-technology.com">Online Backup</a> blog. Contact us today for <a href="http://www.backup-technology.com/business-continuity/">business continuity</a> consulting.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.backup-technology.com/congestion-charging-online-payments-fail-during-hand-over/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
