- Posts: 109
- Thank you received: 2
Important Security Notice from Authorize.Net
- fullfusion
-
Topic Author
- Offline
Less
More
10 years 5 months ago #237470
by fullfusion
Important Security Notice from Authorize.Net was created by fullfusion
-- HikaShop version -- : 2.6.2
-- Joomla version -- : 3.5.1
A client received this from Authorize.net. Does HikaShop store partially masked CC numbers in the database? See below.
________________________________
Dear Authorize.Net Merchant:
On the evening of March 21, 2016, between 4:13 PM and 11:49 PM Pacific time, an error occurred following an Authorize.Net system update that resulted in some merchants receiving transaction responses that contained their customers' full, unmasked card number associated with the transaction, rather than the masked, last four digits (Ex. XXXX1234) normally included in the response. Our internal team identified and resolved the issue.
Based on our follow-on investigation, it appears some of your transactions may have been affected. As with all your transaction processing, these responses were returned via a secure, encrypted connection. However, we urge you to ensure you are not storing this unmasked data in your systems.
It is recommended that you promptly contact your e-commerce/shopping cart provider or web developer to determine whether you typically store the card number field from the transaction response data you receive from Authorize.Net. Please refer to the FAQs below for further details regarding the card number field and its location in the transaction response.
If you determine that any transaction responses from the timeframe above were stored in your systems and contain a full, unmasked card number (rather than just the last four digits), it's recommended you delete the full card number or take appropriate steps to securely store or mask the data to maintain your level of Payment Card Industry Data Security Standard (PCI DSS) compliance. Please contact your Merchant Service Provider or PCI DSS assessor for further information on PCI compliance or refer to the PCI DSS website.
If you have any questions regarding this notice, please review the FAQs below or contact Customer Support.
We apologize for any disruption this may have caused and thank you for being an Authorize.Net merchant.
Sincerely,
Authorize.Net
-- Joomla version -- : 3.5.1
A client received this from Authorize.net. Does HikaShop store partially masked CC numbers in the database? See below.
________________________________
Dear Authorize.Net Merchant:
On the evening of March 21, 2016, between 4:13 PM and 11:49 PM Pacific time, an error occurred following an Authorize.Net system update that resulted in some merchants receiving transaction responses that contained their customers' full, unmasked card number associated with the transaction, rather than the masked, last four digits (Ex. XXXX1234) normally included in the response. Our internal team identified and resolved the issue.
Based on our follow-on investigation, it appears some of your transactions may have been affected. As with all your transaction processing, these responses were returned via a secure, encrypted connection. However, we urge you to ensure you are not storing this unmasked data in your systems.
It is recommended that you promptly contact your e-commerce/shopping cart provider or web developer to determine whether you typically store the card number field from the transaction response data you receive from Authorize.Net. Please refer to the FAQs below for further details regarding the card number field and its location in the transaction response.
If you determine that any transaction responses from the timeframe above were stored in your systems and contain a full, unmasked card number (rather than just the last four digits), it's recommended you delete the full card number or take appropriate steps to securely store or mask the data to maintain your level of Payment Card Industry Data Security Standard (PCI DSS) compliance. Please contact your Merchant Service Provider or PCI DSS assessor for further information on PCI compliance or refer to the PCI DSS website.
If you have any questions regarding this notice, please review the FAQs below or contact Customer Support.
We apologize for any disruption this may have caused and thank you for being an Authorize.Net merchant.
Sincerely,
Authorize.Net
Please Log in or Create an account to join the conversation.
10 years 5 months ago #237480
by nicolas
Replied by nicolas on topic Important Security Notice from Authorize.Net
Hi,
HikaShop doesn't store credit cards data in the database so no problem.
HikaShop doesn't store credit cards data in the database so no problem.
Please Log in or Create an account to join the conversation.
- fullfusion
-
Topic Author
- Offline
Less
More
- Posts: 109
- Thank you received: 2
10 years 5 months ago #237582
by fullfusion
Replied by fullfusion on topic Important Security Notice from Authorize.Net
Glad to hear it. Thank you!
Please Log in or Create an account to join the conversation.
Time to create page: 0.201 seconds