Millions of credit card records left exposed by payments startup


San Francisco, Apr 23 (IANS): A New York-based payments startup left millions of credit card transaction records exposed for anyone to see on the Internet for nearly three weeks before securing it, a media report said on Thursday.

Security researcher Anurag Sen found the database belonging to card payments processor Paay, TechCrunch reported after alerting the company about the finding.

The database was pulled offline by Paay after it became aware of the issue.

"On April 3, we spun up a new instance on a service we are currently in the process of deprecating," Paay co-founder Yitz Mendlowitz was quoted as saying.

"An error was made that left that database exposed without a password," Mendlowitz said.

To prevent fraudulent transactions, Paay verifies payments on behalf of selling merchants, but anyone could access the data inside because there was no password on the server.

A review of a portion of the data base by TechCrunch revealed that each transaction contained credit card number and expiry date besides the amount spent, but as the data did not include names of the cardholder as well as card verification values, the exposure did not make it any easier for fraudsters to misuse it.

Mendlowitz, however, said that his company does not store card numbers.

 

  

Top Stories


Leave a Comment

Title: Millions of credit card records left exposed by payments startup



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.