Global Payments working to again validate its PCI compliance

For the first time, breached processor Global Payments disclosed on Tuesday that a number of card brands have removed the company from their approved list of Payment Card Industry (PCI)-compliant service providers.

However, the Atlanta-based firm continues to process transactions for all of the major card brands as it seeks rejoin those lists, it said in an update.

Global Payments stands by its initial estimate that fewer than 1.5 million cards were impacted by the breach. However, it declined to provide any further details or a timeline of the attack.

"We identified and self-reported the incident in early March, and we will continue to provide information to the appropriate parties as revealed by the investigation," the company said.

A Visa spokesman on Wednesday sent SCMagazine.com a statement saying that it has asked Global Payments to re-validate its compliance to PCI by using a qualified security assessor, or QSA. Retailers that use the company's services will not be liable for penalties during that time.

A MasterCard spokesman did not respond to a request for comment.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.