by admin
August 6, 2010 11:13AM
A Starbucks employee in Jakarta recently took it upon himself to stock up on iPods purchased with the credit card numbers of customers. According to police sources in Jakarta, the suspect, reprinted daily receipts that included the credit card verification value.
While the fraudster will be prosecuted and serve time, the Starbucks franchise was storing credit card verification codes (presumably after authorization), which is one of the biggest “no nos” in the Payment Card Industry Data Security Standard. The storage of the card verification code is prohibited, along with track data and PIN/PIN block. The franchise should and will be held accountable for storing the information post authorization.
Franchise owners must know what data their point-of-sale system has; it is tough to safeguard or put security and operational measures in place if you are unaware of the data. If you are a franchise owner, take the initiative and do discovery on what data you have. If you are unaware of how to do this, contact your point-of-sale vendor for discovery assistance within the POS or terminal.
Security consultants can also be of assistance and search for data beyond the POS system.
I’ll take a grande latte with that 64GB iPod touch.
Contact us today!