from Hacker News

Someone just lost 324k payment records, complete with CVVs

by just_observing on 9/13/16, 10:07 AM with 12 comments

  • by just_observing on 9/13/16, 10:12 AM

    "Let's talk about that CVV for a moment. ... PCI DSS is very clear about how the CVV (or CVV2 as it is these days) should be stored ... It shouldn't be stored and that's what makes this breach such a big issue. Violation of PCI DSS guidelines can lead to pretty serious fines and even loss of merchant facilities; the card providers take this very seriously.

    It checked out - this is the CVV."

  • by admiralhack_ on 9/13/16, 8:37 PM

    The author doesn't explicitly mention it, but the CVVs were saved as a part of debug logging. That mistake should serve as a warning to others implementing PCI DSS systems.
  • by oneloop on 9/14/16, 3:07 PM

    Oh man this Troy guy is the hero we need, fighting the good fight.