In addition to complying with any applicable laws and regulations, you and your agents must take immediate action to contain the incident, notify payment system partners including Visa, and investigate the incident, which may include retaining an independent PCI Forensic Investigator (PFI).
Overview
In the event of a data breach, respond quickly.
Failure to immediately notify Visa Inc. Fraud Control of the suspected or confirmed loss or theft of any Visa transaction information at: (650) 432-2978 or usfraudcontrol@visa.com may result in a penalty of up to US$100,000 per incident to the client bank.
Response checklist
Follow these steps if you believe you’ve been compromised
-
- Stay alert and monitor all systems that have cardholder data or may have connections to the cardholder data environment.
- Don’t log in or change passwords on the at-risk systems. Don’t log in as ROOT.
- Detach the at-risk system from the network by unplugging the cable. Do not turn it off.
- Change secure service identification on the access point and all systems using a wireless connection, except the at-risk systems.
- Save all logs and electronic evidence.
- Keep a record of all actions taken.
-
- Notify your internal information security group and incident response team.
- Notify your acquirer. If you don’t know the name or contact information for your acquirer, notify the Visa Fraud Investigations group immediately at (650) 432-2978 or usfraudcontrol@visa.com
- Notify your local office of the United States Secret Service.
- Data Breach Communication Guidelines
-
- This should be done within 3 working days of the incident. See Appendix A of the What to Do If Compromised guidelines for the report template.
-
Deliver all potentially compromised Visa, Interlink and Plus account numbers within 10 working days. Visa will distribute the numbers to issuers and safeguard confidentiality.
Note: Visa and your acquirer will determine whether to conduct an independent forensic investigation.
Visa response team
Visa has two support groups to help you respond to a payment card breach.
Visa Fraud Investigations
- Works to obtain all potentially compromised account numbers
- Shares at risk account information with issuers
- Works with the appropriate law enforcement on your behalf
- Facilitates a timely forensic investigation
- USFraudControl@visa.com
Data Security Team
- Provides guidelines to assist your response to the incident
- Supports you in identifying security deficiencies
- Makes sure you take action to minimise future risk to account information
- Helps you quickly verify PCI DSS compliance
- cisp@visa.com
More resources
Find more information on protecting your business
Identifying and Mitigating Threats to E-Commerce Payment Processing
You may also be interested in
Securing the future of payments
80% of US payment fraud is caused by electronic cardholder data theft. What are we doing about it?