Account Data Compromise is every organisation’s worst nightmare, whether they know it or not. A single incident can damage your reputation and erode customer trust. That’s not to mention the potential legal and financial impact.
What is an Account Data Compromise?
Account Data Compromise (ADC) is a type of data breach where unauthorised parties gain access to user account data, typically through stolen credentials.
In a PCI DSS context, ADC specifically refers to the exposure or theft of cardholder data (CHD) and/or sensitive authentication data (SAD). This includes full card numbers (Primary Account Numbers or PAN), cardholder names, expiry dates, and security codes, expiry dates, and cardholder names. If your systems store, process, or transmit payment card data, you’re at risk of a PCI DSS reportable compromise if account data ends up in the wrong hands.
How does Account Data Compromise Happen?
Attackers often exploit organisations through:
- Outdated software or unpatched systems: These create openings attackers can easily exploit to gain access.
- Poorly secured remote access: Remote desktop or vendor access without proper security can act as an open door to your systems.
- Cracking weak passwords that aren’t secured by multi-factor authentication: Simple or reused passwords make it easy for attackers to break in.
- Installing malware: Malicious software can quietly collect card data over time without being detected.
- Phishing attacks: Tricking employees into giving away credentials or clicking harmful links.
- Skimming or eSkimming: Criminals attach devices to point-of-sale terminals or inject malicious code into your website to steal card data at the point of entry.
- Physical theft of paper records: Printed receipts or documents containing card data can be stolen or improperly discarded.
Once inside, they can remain undetected for months, extracting valuable cardholder data and selling it on the dark web.
The Impact of Account Data Compromise
Recent data breaches across Australia show how damaging ADCs can be. Beyond direct costs like forensic investigations and fines, businesses face long-term damage to customer trust.
For instance, if card data from your environment ends up being used fraudulently, the card schemes (like Visa or Mastercard) will often trace it back to your systems. If you’re found responsible, you could be liable for:
- Reimbursement of fraud losses.
- Card reissuance costs.
- Mandatory audits and assessments.
- Possible suspension of your ability to accept card payments.
What Happens if My Organisation Experiences Account Data Compromise
Account Data Compromise is a serious matter. So, if it happens through your systems, expect severe consequences – especially if you’re found to not be PCI DSS compliant.
When you discover an account data compromise (ADC), you must immediately take steps to contain the incident and notify your acquiring bank. In parallel, begin preliminary investigation activities to identify the cause of the breach and preserve evidence. You may be asked to temporarily disable your payment acceptance method to ensure no further cards make it into your compromised system.
This is often a high-pressure situation, with some acquiring banks requiring you to complete these initial remediation actions within 24 hours of discovery. Having a retained PFI on standby helps streamline the chaos. They’ll be available immediately and move fast, providing the necessary reporting documentation and mitigating the impact of the compromise.
Then, your acquiring bank or the card schemes may require a PCI DSS investigation conducted by an approved third party, such as a QSA or PFI.
5 Practical Steps to Protect Your Business from ADC
Step 1: Know where your card data is stored and transmitted Start with a clear inventory of systems, software, and third parties involved in processing payments. If you don’t know where the data is, you can’t secure it.
Step 2: Lock down your payment environment Apply the principle of least privilege. Only give cardholder data access to people and systems that genuinely need it. To protect that data, mandate strong passwords and enable multi-factor authentication wherever possible.
Step 3: Patch and update regularly Unpatched systems are a common entry point for attackers. Have a schedule for applying updates to software, firewalls, and point-of-sale systems.
Step 4: Monitor for suspicious activity Invest in logging and alerting tools that help you detect unusual access or data movement. Early detection can prevent long-term damage.
Step 5: Get PCI DSS compliant There’s a reason acquiring banks mandate PCI DSS investigations for every ADC. PCI DSS is a proven framework for protecting cardholder data. Achieving and maintaining PCI DSS compliance will help you avoid a breach altogether.
What To Do If You’ve Suffered a Breach
If you suspect an ADC, time is of the essence. That’s why we strongly recommend engaging a retained Payments Forensic Investigator (PFI) immediately. A PFI will:
- Investigate the breach.
- Contain and remediate the issue.
- Report findings to card schemes and acquiring banks.
- Help you meet compliance obligations.
Having a PFI on standby ensures you can act quickly when every hour counts.
Find out more about our PFI services.
Account Data Compromises are a serious risk for any organisation handling card data. This includes organisations that engage third party payment service providers. But with proactive steps, you can greatly reduce your exposure.
If you’d like a comprehensive review of your organisation’s cyber security practices against PCI DSS, contact us today for a security review.
