What is an account data compromise (ADC)?

An ADC happens when an unauthorised person accesses card payment data in your business environment with the intention to commit fraud. Card payment data is any information about a credit or debit card such as the card number, cardholder PIN, expiry date, card verification code (three numbers on the back of the card) or cardholder name.

How criminals can gain access to your business.

Unauthorised parties look for weaknesses in your systems or processes to access sensitive information, such as card payment data. Common tactics include:

  • Terminal skimming. A device is placed on your payment terminal that reads the magnetic stripe on the back of the card and records the information
  • Installing malware. This is software that can be used by fraudsters to lock you out of your systems and give them access and control over your information
  • Phishing. You may receive an email from a compromised or legitimate-looking address that tricks you into sharing information or clicking on a link that installs malware
  • Physical theft of paper-based information. This could include card numbers that have been written down while taking payments over the phone or any other sensitive information about your customers or business.

What can unauthorised parties do with card payment data?

Once card payment data is accessed, it is often sold through underground online marketplaces. It can then be used to make purchases online or in store using cloned or fake cards. These purchases may be resold for cash, making them harder to trace. Stolen data can continue to circulate for months or even years.

What types of businesses are likely to be targeted?

Every type and size of business that handles card payment data is at risk of an account data compromise. The less secure your systems and processes are, the more likely you are to be targeted.

What will happen if my business suffers an ADC?

If Westpac suspects or confirms that your business has experienced an ADC, we will contact you as soon as possible. The incident will need to be contained and investigated, and we will advise if you need to engage a Payment Card Industry (PCI) Forensic Investigator or a Qualified Security Assessor (QSA).

An ADC can lead to financial penalties, the suspension or termination of your merchant facility, reputational damage for not protecting your customers' data, and the cost of additional audits and remediation.

How to help prevent an ADC.

Here are some resources to help you protect your payment environment when you're accepting payments in-store, online and over the phone.

What should I do if my business has been compromised?

If you notice anything out of the ordinary about your payment environment that could indicate an ADC has taken place, follow these instructions.

Contact Westpac immediately using the following channels

  • Call your Relationship Manager
  • Call the Westpac Merchant Assist team on 0800 888 066, option 4 weekdays between 8:30am - 5pm
  • Email PCI.DSS.Compliance@westpac.co.nz

Immediately secure your systems

  • Stop taking payments through the compromised systems (for example your website).
  • Isolate the compromised systems by disconnecting them from the internet and your internal network (for example unplug network cables or disable connections).
  • Don't access or make changes to compromised systems.
  • Don't turn off, restart or reboot the compromised systems.

Collect and preserve evidence

  • Identify and document all potentially compromised components, including PCs, servers, payment terminals, databases and websites.
  • Preserve all logs and evidence, such as security events, login and remote access logs, web and database logs, firewall activity, system images or malware (if available)
  • Record all actions taken, including dates, times, people involved, and steps performed.

Understand what happened

The Westpac team will need to understand how the compromise occurred. Be prepared to provide answers to the following questions:

  • When was the compromise first identified?
  • How did you become aware of the issue?
  • What was the likely cause? (for example malware, phishing, service provider breach or terminal tampering)
  • Which systems were affected?
  • What information may have been exposed? (for example card numbers, expiry dates or customer details)
  • Did the incident affect more than one location?
  • Who have you contacted for support? (for example: IT provider, or Police)
  • What steps have you already taken to isolate and secure your systems?

Contain the incident and prevent further impact

We’re here to help with ADC prevention and response.

Reach out to your Westpac Relationship Manager or email the PCI DSS compliance team at PCI.DSS.Compliance@westpac.co.nz.

You can also call the Westpac Merchant Assist team on 0800 888 066, option 4 weekdays 8:30am to 5pm.

Things you should know.

The information on this page is intended as a guide only. We make no warranty or representation, express or implied, regarding the accuracy of any information, statement or advice contained on this page. We recommend you seek independent advice before acting or relying on any of the information on this page. All opinions, statements and analysis expressed are based on information current at the time of writing from sources which Westpac believes to be authentic and reliable. Westpac issues no invitation to anyone to rely on this material.

Links to other sites are provided for convenience only and Westpac accepts no responsibility for the availability or content of such websites.