PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

SecurityMetrics Finds Unencrypted Card Data in Two-Thirds of Merchants Scanned

By Mercator Advisory Group
March 15, 2011
in Analysts Coverage
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Digital Transactions has an item today about PCI scanning vendor SecurityMetrics’ PANScan tool, which has detected unencrypted card data in nearly two-thirds of merchants that participated in a recent test. The version of PANScan used in the test is available for free download at the SecurityMetrics PANScan Web site. The article pointed to merchants’ use of payment applications that are not compliant with the Payment Application Data Security Standard (PA-DSS), failure to erase old data when new payment applications are installed, and lack of training in proper data storage techniques as the main reasons for the proliferation of unencrypted card data in merchant systems.

The merchants participating in the test ranged in size from small Level 4 merchants to the largest Level 1 merchants.

Of 478 card data scans conducted during the beta test, 303, or 63.4%, uncovered unencrypted card data, SecurityMetrics says. The tests found about 18 million cards in a scan of 67.5 million files. The maximum number of cards uncovered in a single scan totaled 1.9 million.

SecurityMetrics says it’s impossible to identify the PCI status of the merchants storing unencrypted card data since the PANscan tool is available to anyone for free download and use. Merchants weren’t asked whether they were in compliance with PCI.

Many merchants are unaware that their systems are storing the unencrypted data, says Brad Caldwell, chief executive of SecurityMetrics. “One of the biggest things we hear from merchants is ‘I had no idea I had this data. I talked to my developer and he didn’t say he was storing card data,’” Caldwell says.

Click here to read more.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    gift card strategy

    The Gift Card Shift: From Convenience to Core Shopping Strategy

    February 18, 2026
    Tina Shirley

    From Cross-Border Payments to Community Banks: The Future of Zelle®

    February 17, 2026
    Startups: Fintechs Data Streaming Technology in Banking, corporates Enriched Data vs Faster Payments

    Fighting Fraud in the Era of Faster Payments

    February 13, 2026
    cross-border payments

    Solving for Fraud in Cross-Border Payments Requires Better Counterparty Verification

    February 12, 2026
    agentic commerce

    Demystifying the Agentic Commerce Enigma

    February 11, 2026
    payment gateways

    How Payment Gateways for Businesses Can Help You Offer Your Customers More Options

    February 10, 2026
    Reserve Bank of India (RBI) Extends Mandate for Tokenization to June '22

    Late Payments? Governments Are Taking Action

    February 9, 2026
    ai phishing

    The Fraud Epidemic Is Testing the Limits of Cybersecurity

    February 6, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result