Jump to content
Sign in to follow this  
OLD CS1

Chicago-area parking vendor SP+ compromised

Recommended Posts

If anyone used a parking garage in the Chicago area (Evanston is included) during the Faire, take close looks at your bank statements. (The article does not give a time frame, just that a notification was given on November 3rd.)

 

Hackers Infiltrate Payment Systems of Major Parking Garage Operator | SecurityWeek.Com
http://www.securityweek.com/hackers-infiltrate-payment-systems-major-parking-garage-operator

Share this post


Link to post
Share on other sites

The cash option wasn't working on one of the outside 'meters', so I think I swiped a card at least once while out there. While dropping quarters into the device it became clear that without a meter holding time, person A can pay for 2 hours, leave early, and the next person who pulls in gets none of that time credited to their parking. Quite the ripoff. (end rant)

 

Anyway, thanks for sharing this!

Share this post


Link to post
Share on other sites

I think this was on my Discover... so I'll have to watch it. Probably get a new card and number and then have to change a couple auto pays. Grr.

Share this post


Link to post
Share on other sites

I have had my personal and business cards replaced several times within a couple of months because of breaches. It really aggravates me because I work in the industry and I know that it is NOT difficult to secure your shit! But you get managers (IT and otherwise) who insist on bowing to external vendor demands even if it brings you out of compliance... let alone common sense! Almost like Target, K-Mart, Jimmy Johns, Dairy Queen, TJX, et. al. simply never happened.

 

I have begun bullying and strong-arming vendors into working in compliance, to the point that if I find a remote access program installed, I involve them in an investigation, tying them up for hours while we run down a list of questions until they just do it OUR way. Including expiring passwords and a policy which requires them to call before they can gain access to the system. Pisses them off, but it saves a lot of trouble in the end.

 

Sure, these business are insured against losses and damages, but what about the end customer who has implicitly, if not explicitly, trusted these business with personal and financial data? While it may not be a big deal that a business's POS systems were compromised and any illegitimate charges to my account will be taken care of, no one covers my lost time going through all of the disparate payment systems which have my information on-file because I have to give it to them (another potential weak link,) and if I miss one I get in a metric shit-tonne of trouble when they try to bill an invalid card.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...