HEARTLAND PAYMENT SYSTEMS▊
The PCI-certified processor that lost ~130 million card numbers while the certificate was still warm — then spent the next decade as compliance theater's loudest reformed witness.
- ENTITY
- Heartland Payment Systems, Princeton, New Jersey — at the time the fifth-largest U.S. payment processor, ~11 million transactions a day FACT
- EVENT
- BREACHED — SQL injection into an eight-year-old web form (late 2007), sniffer malware on the processing network (2008), ~130 million card numbers exposed FACT
- THE TWIST
- Heartland was certified PCI DSS compliant at the time of the breach — and had been certified repeatedly during the years the vulnerability sat in its code FACT
- ATTACKER
- Albert Gonzalez and co-conspirators — convicted; 20 years and a day ADJUDICATED
- DISPOSITION
- Up to $100M paid into a settlement fund for Visa, Mastercard and AmEx claims; total breach costs reported well above that; company later sold to Global Payments FACT
First party. Heartland's disclosure, from its own January 20, 2009 press release ("Heartland Payment Systems Uncovers Malicious Software in Its Processing System," preserved at its breach-disclosure site, archived). And CEO Bob Carr, to CSO magazine, August 2009:
"The audits done by our QSAs (Qualified Security Assessors) were of no value whatsoever. To the extent that they were telling us we were secure beforehand, that we were PCI compliant, was a major problem." No verified corporate X handle exists for the Heartland brand today (it operates under Global Payments; heartland.us links no X account), so the receipts stand in.
-->
Observe the animal in two postures. Before: a processor holding six years of compliance certificates while sniffers drink from its payment stream. After: the industry's most vocal witness against the very audit regime that certified it. Few specimens molt this completely, or this publicly.
Heartland is the load-bearing exhibit in the PCI argument — the reason "we were certified compliant" stopped working as a sentence. A Federal Reserve bank wrote the case study; the CEO gave the quotes; the court supplied the conviction. Nothing in this file is contested attribution.
What makes the file worth keeping is the second act. Most breached institutions issue the apology and rebuild the same wall. This one turned state's evidence against its own audit regime and spent its money building the thing the standard didn't require. Both facts stay in the drawer together.
the drama timeline
ACT I — THE CERTIFICATE AND THE SNIFFER (2007–2008)
The vulnerability is old enough to attend third grade. The certificate is renewed annually. The intruders are patient.
-
LATE 2007
SQL injection, through an eight-year-old form
Intruders exploit a SQL-injection vulnerability in web-form code written eight years earlier — a flaw that annual internal and external audits and continuous monitoring had never flagged — and gain access to Heartland's corporate network. They spend almost six months hiding, defeating multiple antivirus packages, working toward the separately segmented processing network.
-
2008
Sniffers on the payment stream — under a current certificate
Inside the processing network, the intruders install sniffer software that captures card numbers, expiration dates, and in some cases cardholder names as the data move through Heartland's systems — data in transit, which the PCI standard of the day did not require to be encrypted. Heartland is PCI-certified during this period, as it had been repeatedly while the vulnerability existed.
The standard's blind spot and the attacker's harvest are the same field. The certificate, meanwhile, renews on schedule.
-
OCT 2008
The card brands notice first
Visa and Mastercard alert Heartland to suspicious activity tied to cards it processed. Forensic investigation follows; the sniffer malware is eventually uncovered in January 2009. As with most entries in this drawer, the institution did not catch its own breach.
ACT II — INAUGURATION DAY (JAN 2009)
The disclosure lands on the one news morning in four years guaranteed to be about something else.
-
JAN 20 2009
Disclosure
Heartland announces it "uncovered malicious software in its processing system" — the same morning Washington is otherwise occupied swearing in a president. The exposure is eventually reckoned at roughly 130 million card numbers, the largest card breach then on record. Critics call the timing burial; the company maintained the sequence followed the forensics. Both readings are preserved here.
ACT III — THE BILL AND THE SENTENCE (2009–2010)
The criminal case ends cleanly. The institutional argument is just getting started.
-
AUG 2009
Gonzalez charged
Albert Gonzalez — already indicted over TJX, and a sometime U.S. Secret Service informant — is charged in New Jersey with masterminding the Heartland intrusion along with attacks on other processors and retailers. The indictment's headline number across the ring's victims: 130 million card numbers.
-
MAR 26 2010
Twenty years and a day
Gonzalez is sentenced in Boston to 20 years and a day for the Heartland, 7-Eleven and related intrusions, concurrent with the 20-year TJX sentence handed down the day before — then the longest U.S. sentence for computer crime. "I understand the road to redemption will be long," he tells the court.
-
2009–2010
The settlements
Heartland agrees to pay up to $100 million into a fund reimbursing Visa, Mastercard and AmEx issuers; with forensics, legal fees and remediation, contemporaneous case studies put the total north of $140 million. The stock, briefly, loses most of its value; it recovers as the company survives.
ACT IV — THE CONVERT (2009–2016)
The rarest post-breach behavior in the archive: the victim turns witness — against the audit regime, and against its own pre-breach architecture.
-
AUG 2009
Carr indicts the QSAs; the profession objects
Carr, to CSO magazine: the audits done by Heartland's QSAs "were of no value whatsoever." Securosis analyst Rich Mogull publishes an open letter in reply: a QSA's role "is to assure your compliance with the standard, not secure your organization from attack" — compliance is a point in time, and an experienced executive should know the difference. The exchange becomes the canonical statement of both positions.
-
2009–2010
The E3 push — building past the standard
Heartland launches an end-to-end encryption program (E3) to encrypt card data in transit — the exact gap the sniffers had exploited and the PCI standard hadn't closed — and Carr becomes the industry's most prominent advocate for encryption and tokenization beyond the PCI baseline. A Federal Reserve Bank of Philadelphia workshop paper documents the strategy, and Carr's point that PCI is "a minimum standard."
The defense's best exhibit is behavioral: the company that got burned did not buy a thicker certificate. It bought cryptography.
-
2016
Absorbed
Global Payments acquires Heartland; the brand survives as a Global Payments company. The breach becomes a business-school case, a Federal Reserve paper, and the first name anyone says in an argument about PCI.
both sides, on the record
Certified while compromised. PCI-compliant at the time of the breach, certified repeatedly across the years the vulnerability existed — the compliance regime's most damning single exhibit, documented by a Federal Reserve bank [1].
Didn't catch it, wasn't first to know. The card brands flagged the fraud in October 2008; disclosure came in January, on a morning famously hostile to news [2] [3].
The blame-shift drew fire from its own side. When Carr pinned it on the QSAs, working security professionals answered publicly that a point-in-time compliance assessment was never a security guarantee — and that executives know this [6].
The crime was adjudicated — and it wasn't an inside job. A federal court convicted Albert Gonzalez and his ring; the same actor had hit TJX, Hannaford, 7-Eleven and others. Heartland was one victim of a professional criminal enterprise that beat many defenses, certified and otherwise [4] [5].
It paid, publicly, and told the story straight. Up to $100M in issuer settlements, a CEO who gave interviews and Federal Reserve workshops instead of no-comments, and a breach site that published the details [1] [2] [3].
Then it built the fix the standard never required. The E3 end-to-end encryption program attacked the exact data-in-transit gap the intruders used; Carr's post-breach career was spent arguing the industry should exceed PCI, not worship it. The reformed witness is real, not PR [1] [7].
YOU DECIDE
Scoped to the claims. The breach, the certificates, the $100M fund, and the conviction are all on the public record; none is disputed. The open question is what the certificate was worth — Heartland's CEO said "no value whatsoever," the profession answered that he'd bought an assessment and expected a guarantee, and eighteen years of Verizon data (see the PCI Council file) suggest both can be true at once.
Weigh the costly signal: after the breach, Heartland's money went into encryption hardware, not additional certificates. Institutions tell you what they actually believe with their remediation budgets.
The archive does not judge. It keeps the certificates, and the dates.
evidence locker
PRIMARY RECORD
Federal Reserve Bank of Philadelphia — "Heartland Payment Systems: Lessons Learned from a Data Breach" (Julia S. Cheney, Jan 2010) FACT — the breach mechanics, the compliant-at-the-time-of-breach finding, the QSA-process criticism, and the E3 strategy, from a Fed workshop with Carr.
philadelphiafed.org/…/d-2010-january-heartland-payment-systems.pdf
PRESS & ANALYSIS
The standard. The breach mechanics and compliance history are sourced to a Federal Reserve bank's case study and the company's own disclosure; the conviction is a federal court's; the settlements are contemporaneously reported. The "news burial" reading of the disclosure date is presented as the critics' characterization, not asserted. Carr's criticism of his QSAs and the profession's rebuttal are both quoted, both attributed, both at full strength — and nothing on this page alleges wrongdoing by any named assessor or by Carr personally. If it couldn't survive a defamation challenge, it wouldn't be on this page.