Visa Europe Alert on Hosted Payment Pages
Visa Europe have recently released an alert concerning the targeting of merchants using a redirect model for processing payments, where the customer is redirect to a third party payment page where the payment transaction is handled. These attacks involve compromising the merchant website and manipulating the redirect in such a way as to compromise the customers credit card details.
This is the first time this particular risk has been identified as an active target for hackers. Under the current system of categorising small merchants, this method of processing credit card payments is viewed as low risk as the merchant does not have 'store, process or transmit' credit card data. However it seems that even though this is the case, the risk is not fully transfered to the third party payment provider if the attacker can directly manipulate the page that the customer is redirected to.
The full details of the alert can be found here.
Email to a Friend
Fill in the form below to send this news item to a friend:
Latest News
- Payment Security Forum 2010 Cairo August 27, 2010
- London PCI DSS Training for Merchants August 24, 2010
- PCI DSS Training Seminar Dubai August 12, 2010
- Visa Europe Alert on Hosted Payment Pages June 21, 2010
- Visa PCI Training - Moscow April 27, 2010
- PCI DSS Merchant Training Nottingham UK April 27, 2010
- Visa PCI Training - Zagreb April 6, 2010
- Enterprise Ireland HPSU Class of 2009 March 4, 2010
- VISA PCI Training - Dubai 2010 March 1, 2010
- Visa PCI Training - Johannesburg 2010 March 1, 2010
