<?xml version="1.0" encoding="UTF-8"?>
<incident>
  <arrest type="boolean">true</arrest>
  <breach-type-id type="integer" nil="true"></breach-type-id>
  <comments-count type="integer">12</comments-count>
  <data-family-id type="integer">1</data-family-id>
  <data-recovered type="boolean">false</data-recovered>
  <disputed type="boolean">false</disputed>
  <fringe type="boolean">false</fringe>
  <fringe-description nil="true"></fringe-description>
  <id type="integer">1518</id>
  <lawsuit type="boolean">true</lawsuit>
  <records type="integer">130000000</records>
  <submission-id type="integer">471</submission-id>
  <updated-at type="datetime">2012-05-07T23:57:20Z</updated-at>
  <user-id type="integer">190</user-id>
  <breach-types type="array">
    <breach_type>
      <name>Hack</name>
    </breach_type>
  </breach-types>
  <data-types type="array">
    <data_type>
      <short_name>CCN</short_name>
    </data_type>
  </data-types>
  <timeline-items type="array">
    <timeline_item>
      <first_date>2009-01-20 00:00:00 UTC</first_date>
      <type>Organization reports incident</type>
    </timeline_item>
    <timeline_item>
      <first_date>2009-01-27 00:00:00 UTC</first_date>
      <type>Lawsuit filed</type>
    </timeline_item>
    <timeline_item>
      <first_date>2009-01-12 00:00:00 UTC</first_date>
      <type>Incident discovered by organization</type>
    </timeline_item>
    <timeline_item>
      <first_date>2009-08-16 00:00:00 UTC</first_date>
      <type>Arrest made</type>
    </timeline_item>
    <timeline_item>
      <first_date>2008-05-15 00:00:00 UTC</first_date>
      <second_date>2008-11-13 06:20:00 UTC</second_date>
      <type>Incident Occurred</type>
    </timeline_item>
  </timeline-items>
  <vector>
    <name>Outside</name>
  </vector>
  <primary-organization>
    <business-type-id type="integer">1</business-type-id>
    <freebase-cached-data>
      <companies-acquired type="array"/>
      <net-income type="array"/>
      <name>Heartland Payment Systems</name>
      <subsidiary-companies type="array"/>
      <ticker-symbol type="array">
        <ticker-symbol>
          <ticker-symbol>HPY</ticker-symbol>
          <stock-exchange>NYSE</stock-exchange>
        </ticker-symbol>
      </ticker-symbol>
      <market-capitalization type="array">
        <market-capitalization>
          <amount type="float">1000000000.0</amount>
          <currency type="array">
            <currency>
              <name>US$</name>
            </currency>
          </currency>
          <valid-date>2007-12-31</valid-date>
        </market-capitalization>
      </market-capitalization>
      <board-members type="array">
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>Richard Vague</member>
          <to nil="true"></to>
        </board-member>
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>Scott L Bok</member>
          <to nil="true"></to>
        </board-member>
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>Jonathan J Palmer</member>
          <to nil="true"></to>
        </board-member>
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>Mitchell L Hollin</member>
          <to nil="true"></to>
        </board-member>
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>Marc Ostro</member>
          <to nil="true"></to>
        </board-member>
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>George F Raymond</member>
          <to nil="true"></to>
        </board-member>
        <board-member>
          <title nil="true"></title>
          <from nil="true"></from>
          <member>Robert H Niehaus</member>
          <to nil="true"></to>
        </board-member>
      </board-members>
      <type>/business/company</type>
      <operating-income type="array">
        <operating-income>
          <amount type="float">88200000.0</amount>
          <currency type="array">
            <currency>
              <name>US$</name>
            </currency>
          </currency>
          <valid-date>2006-12-31</valid-date>
        </operating-income>
      </operating-income>
      <number-of-employees type="array"/>
      <revenue type="array">
        <revenue>
          <amount type="float">1097000000.0</amount>
          <currency type="array">
            <currency>
              <name>US$</name>
            </currency>
          </currency>
          <valid-date>2006-12-31</valid-date>
        </revenue>
      </revenue>
    </freebase-cached-data>
    <freebase-description>Heartland Payment Systems, Inc. (NYSE:&#160;HPY) provides debit, prepaid, and credit card processing, online payments check processing, payroll services and a growing line of industry solutions for small to mid-sized merchants. Heartland Payment Systems is currently the fifth largest credit card processor in the United States and the 9th in the world. Founded by Robert O. Carr in 1997, Heartland Payment Systems is headquartered in Princeton, New Jersey. There are also offices nationally in Texas, Colorado, Tennessee, Oregon, Indiana, and Ohio.
Heartland Payment Systems processes transactions for more than 250,000 business locations in the United States. Heartland Payment Systems currently processes more than 11 million transactions a day and more than $120 billion in transactions a year....</freebase-description>
    <freebase-pref-name>Heartland Payment Systems</freebase-pref-name>
    <id type="integer">1459</id>
    <is-private type="boolean">false</is-private>
    <name>Heartland Payment Systems</name>
    <stock-symbol>HPY</stock-symbol>
    <updated-at type="datetime">2011-07-16T15:30:15Z</updated-at>
  </primary-organization>
  <secondary-organizations type="array">
    <secondary-organization type="Organization">
      <business-type-id type="integer">1</business-type-id>
      <freebase-cached-data>
        <net-income type="array">
          <net-income>
            <amount type="float">14980000000.0</amount>
            <valid-date>2007</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </net-income>
          <net-income>
            <amount type="float">14982000000.0</amount>
            <valid-date>2007-12-31</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </net-income>
          <net-income>
            <amount type="float">21133000000.0</amount>
            <valid-date>2007</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </net-income>
          <net-income>
            <amount type="float">7882000000.0</amount>
            <valid-date>2000</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </net-income>
        </net-income>
        <name>Bank of America</name>
        <companies-acquired type="array">
          <companies-acquired>
            <date>2005</date>
            <company-acquired>MBNA</company-acquired>
          </companies-acquired>
          <companies-acquired>
            <date>2004</date>
            <company-acquired>FleetBoston Financial</company-acquired>
          </companies-acquired>
          <companies-acquired>
            <date>2007-10</date>
            <company-acquired>LaSalle Bank</company-acquired>
          </companies-acquired>
          <companies-acquired>
            <date>2008-07</date>
            <company-acquired>Countrywide Financial</company-acquired>
          </companies-acquired>
          <companies-acquired>
            <date>2006-11-20</date>
            <company-acquired>U.S. Trust Company</company-acquired>
          </companies-acquired>
          <companies-acquired>
            <date>2004</date>
            <company-acquired>National Processing Company</company-acquired>
          </companies-acquired>
          <companies-acquired>
            <date>2009-01-01</date>
            <company-acquired>Merrill Lynch</company-acquired>
          </companies-acquired>
        </companies-acquired>
        <ticker-symbol type="array">
          <ticker-symbol>
            <ticker-symbol>BAC</ticker-symbol>
            <stock-exchange>NYSE</stock-exchange>
          </ticker-symbol>
          <ticker-symbol>
            <ticker-symbol>8648</ticker-symbol>
            <stock-exchange>TYO</stock-exchange>
          </ticker-symbol>
        </ticker-symbol>
        <subsidiary-companies type="array">
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>LaSalle Bank Midwest</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>LaSalle Bank</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>Bank of America Capital Investors</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>BA Merchant Services</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>FIA Card Services</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>Bank of America Securities</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from nil="true"></from>
            <subsidiary>Countrywide Financial</subsidiary>
          </subsidiary-company>
          <subsidiary-company>
            <from>2009-01-01</from>
            <subsidiary>Merrill Lynch</subsidiary>
          </subsidiary-company>
        </subsidiary-companies>
        <market-capitalization type="array">
          <market-capitalization>
            <amount type="float">155730000000.0</amount>
            <valid-date>2008</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </market-capitalization>
        </market-capitalization>
        <type>/business/company</type>
        <board-members type="array">
          <board-member>
            <title>Vice Chair</title>
            <from>1988</from>
            <member>Robert W. Frick</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2001</from>
            <member>Patricia E. Mitchell</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2006-01</from>
            <member>Frank P. Bramble</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2004-04</from>
            <member>Gary L. Countryman</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>W Steven Jones</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>Thomas M. Ryan</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2004</from>
            <member>William Barnet III</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2004-04</from>
            <member>John T. Collins</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>1988</from>
            <member>Meredith R. Spangler</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>Robert L. Tillman</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>Walter E. Massey</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2006</from>
            <member>Monica C. Lozano</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>Thomas J.  May</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title>Chair</title>
            <from>2001-04</from>
            <member>Ken Lewis</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>1994</from>
            <member>Jackie M. Ward</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>Solomon Trujillo</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>1999</from>
            <member>James H. Hance Jr.</member>
            <to>2005</to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>2005-12</from>
            <member>Tommy Franks</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title>Chair</title>
            <from>2004-04</from>
            <member>Charles K. Gifford</member>
            <to>2005-01</to>
          </board-member>
          <board-member>
            <title>Lead Director</title>
            <from>2006-05</from>
            <member>O.Temple Sloan Jr.</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title>Vice Chair</title>
            <from>1993</from>
            <member>James H. Hance Jr.</member>
            <to>2005-01-31</to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from nil="true"></from>
            <member>Samuel H. Armacost</member>
            <to nil="true"></to>
          </board-member>
          <board-member>
            <title nil="true"></title>
            <from>1996</from>
            <member>O.Temple Sloan Jr.</member>
            <to nil="true"></to>
          </board-member>
        </board-members>
        <operating-income type="array">
          <operating-income>
            <amount type="float">23010000000.0</amount>
            <valid-date>2007-12</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </operating-income>
          <operating-income>
            <amount type="float">14982000000.0</amount>
            <valid-date>2008</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </operating-income>
        </operating-income>
        <number-of-employees type="array">
          <number-of-employee>
            <number type="integer">206587</number>
            <year>2007</year>
          </number-of-employee>
          <number-of-employee>
            <number type="integer">209718</number>
            <year>2008-02-28</year>
          </number-of-employee>
        </number-of-employees>
        <revenue type="array">
          <revenue>
            <amount type="float">119190000000.0</amount>
            <valid-date>2007</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </revenue>
          <revenue>
            <amount type="float">117017000000.0</amount>
            <valid-date>2007</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </revenue>
          <revenue>
            <amount type="float">51392000000.0</amount>
            <valid-date>2000</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </revenue>
          <revenue>
            <amount type="float">119190000000.0</amount>
            <valid-date>2008</valid-date>
            <currency type="array">
              <currency>
                <name>US$</name>
              </currency>
            </currency>
          </revenue>
        </revenue>
      </freebase-cached-data>
      <freebase-description type="Organization">Washington University in St. Louis is a nonsectarian, private research university located in suburban St. Louis, Missouri. Founded in 1853, and named for George Washington, the university has students and faculty from all fifty U.S. states and more than one hundred and ten nations. Twenty-two Nobel laureates have been affiliated with Washington University, nine doing the major part of their pioneering research at the university. The university has an endowment of $4.07 billion, the 18th largest in the country. In FY 2006 the National Science Foundation reported that the university received $434 million in Federal research funds, ranking sixth among private universities receiving federal research and development support, and in the top four in funding from the National Institutes of...</freebase-description>
      <freebase-pref-name type="Organization">Bank of America</freebase-pref-name>
      <id type="integer">2749</id>
      <is-private type="boolean" nil="true"></is-private>
      <name type="Organization">Tower Federal Credit Union</name>
      <stock-symbol type="Organization" nil="true"></stock-symbol>
      <updated-at type="datetime">2010-06-08T06:17:34Z</updated-at>
    </secondary-organization>
    <secondary-organization type="Organization">
      <business-type-id type="integer">1</business-type-id>
      <freebase-cached-data type="yaml" nil="true"></freebase-cached-data>
      <freebase-description type="Organization">Washington University in St. Louis is a nonsectarian, private research university located in suburban St. Louis, Missouri. Founded in 1853, and named for George Washington, the university has students and faculty from all fifty U.S. states and more than one hundred and ten nations. Twenty-two Nobel laureates have been affiliated with Washington University, nine doing the major part of their pioneering research at the university. The university has an endowment of $4.07 billion, the 18th largest in the country. In FY 2006 the National Science Foundation reported that the university received $434 million in Federal research funds, ranking sixth among private universities receiving federal research and development support, and in the top four in funding from the National Institutes of...</freebase-description>
      <freebase-pref-name type="Organization">Beverly National Bank</freebase-pref-name>
      <id type="integer">2750</id>
      <is-private type="boolean" nil="true"></is-private>
      <name type="Organization">Beverly National Bank</name>
      <stock-symbol type="Organization" nil="true"></stock-symbol>
      <updated-at type="datetime">2010-06-08T06:23:14Z</updated-at>
    </secondary-organization>
  </secondary-organizations>
  <summary>
    <summary>Malicious Software/Hack compromises unknown number of credit cards at fifth largest credit card processor</summary>
  </summary>
  <comments type="array">
    <comment>
      <content>Washington Post is saying 100,000,000 cards, see the washington post reference.</content>
      <created_at>2009-01-20 14:04:39 UTC</created_at>
    </comment>
    <comment>
      <content>This breach is most likely WELL over 100mill.  Heartland does 100mill or more PER MONTH. I would estimate 5-700 mill.</content>
      <created_at>2009-01-20 17:07:49 UTC</created_at>
    </comment>
    <comment>
      <content>The PSP in this case is of course PCI compliant? Not! 
If they were Tripwire (or similiar) and malware should have been installed as standard and would have potentially protected against this.......</content>
      <created_at>2009-01-21 05:19:35 UTC</created_at>
    </comment>
    <comment>
      <content>Actually, they were PCI compliant as of April 2008.</content>
      <created_at>2009-01-22 11:26:01 UTC</created_at>
    </comment>
    <comment>
      <content>
http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf

Service Provider: Heartland Payment Systems
Validation Date: April 30, 2008
Services Covered by Review: Payment Processing
Assessor: Trustwave</content>
      <created_at>2009-01-23 04:35:43 UTC</created_at>
    </comment>
    <comment>
      <content>&quot;No confidential merchant data, Social Security numbers, unencrypted personal identification numbers (PIN), addresses or telephone numbers were retrieved in what is believed to be a global cyber-fraud operation. Heartland does not yet know how many card numbers were obtained.&quot; 

http://www.snl.com/irweblinkx/file.aspx?IID=4094417&amp;FID=7249269
</content>
      <created_at>2009-01-23 12:42:47 UTC</created_at>
    </comment>
    <comment>
      <content>
An OSF staff member mailed the PCI-DSS contact for Trustwave asking for public comment.</content>
      <created_at>2009-01-24 04:32:21 UTC</created_at>
    </comment>
    <comment>
      <content>Suspect supposedly pinpointed per http://www.storefrontbacktalk.com/securityfraud/feds-identify-overseas-suspect-in-heartland-case/</content>
      <created_at>2009-01-24 13:13:55 UTC</created_at>
    </comment>
    <comment>
      <content>Lawsuit filed : http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1346268,00.html </content>
      <created_at>2009-01-28 14:06:25 UTC</created_at>
    </comment>
    <comment>
      <content>I received a new discover card this week.  The account number did not change, but the expiration and validation code on the back changed.  When I called Discover to activate the card I ask why the change and he acknowledge it was due to the Heartland compromise.</content>
      <created_at>2009-01-30 17:01:10 UTC</created_at>
    </comment>
    <comment>
      <content>I've been watching this one since it happened in January.  I just now (May 11th) got notified by Suntrust that my card may have been compromised in this breach.  4 months to notify me?  They've got to be kidding.</content>
      <created_at>2009-05-11 18:17:18 UTC</created_at>
    </comment>
    <comment>
      <content>In a recent update Heartland Payment Systems announced today (January 8, 2010) that it will pay Visa-branded credit and debit card issuers up to $60 million to cover losses incurred from the Heartland data breach.
http://www.bankinfosecurity.com/articles.php?art_id=2054&amp;rf=010910eb
</content>
      <created_at>2010-01-11 04:16:10 UTC</created_at>
    </comment>
  </comments>
  <location>
    <address>90 Nassau St, Princeton, NJ 08542, USA</address>
    <thoroughfare_name>90 Nassau St</thoroughfare_name>
    <dependent_locality_name>Borough of Princeton</dependent_locality_name>
    <locality_name>Princeton</locality_name>
    <sub_administrative_area_name>Mercer</sub_administrative_area_name>
    <administrative_area_name>NJ</administrative_area_name>
    <postal_code_number>08542</postal_code_number>
    <country_name_code>US</country_name_code>
    <longitude>40.3497</longitude>
    <latitude>-74.66</latitude>
    <accuracy>8</accuracy>
  </location>
</incident>

