The encyclopedia · Software & IT · Operational decision · 2008
Heartland's breach stole 130M card numbers — the largest payment card theft ever
In 2008, hackers stole 130M payment card numbers from Heartland via SQL injection. It was the largest payment card breach in history at the time.
Heartland Payment Systems · 2008-12
What happened
In December 2008, Heartland Payment Systems, one of the largest payment processors in the US, disclosed that hackers had stolen approximately 130 million payment card numbers from its systems. The breach, carried out by hacker Albert Gonzalez and accomplices, used SQL injection to install malware on Heartland's payment processing servers.
The stolen card numbers were used for fraudulent transactions, and the breach affected millions of consumers. Heartland paid over $145 million in settlements, legal costs and security upgrades. The breach was the largest payment card theft in history at the time.
The case illustrated how a single vulnerability (SQL injection) in a payment processor can compromise data at a massive scale, and how the payment processing industry's centralized architecture creates a single point of failure that affects every merchant and consumer that uses the processor.
Why it happened
- Hackers used SQL injection to install malware on Heartland's payment processing servers.
- 130M payment card numbers were stolen — the largest payment card breach at the time.
- Heartland paid $145M+ in settlements and security upgrades.
- The breach affected millions of consumers across the US.
The lesson
A payment processor is a single point of failure for every merchant it serves. Heartland's SQL injection compromised 130M cards because the architecture centralized the data.
Aftermath
Heartland overhauled its security and became an advocate for payment card security standards. Albert Gonzalez was sentenced to 20 years in prison. The case accelerated the adoption of EMV chip cards and tokenization in the US payment industry.
Sources
- Heartland Payment Systems — Wikipedia (2008 breach)
- Lessons Learned from the 2008 Heartland Breach — Proofpoint
spotted an error? The club wants to know.
More like this
Allianz Life's CRM vendor door exposed most of its 1.4M customers
Allianz Life exposed most of 1.4M customers through a third-party CRM
A former AWS engineer stole 100M Capital One records via a misconfigured firewall
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.