Symantec investigates call-centre credit card scam

NEWS

Symantec said on Tuesday that it is looking into allegations that a call centre in India leaked credit-card numbers of its customers to someone who then sold them to BBC News reporters in an undercover investigation.

The company has informed UK privacy authorities, plus attorneys general and officials in eight US states and Puerto Rico, of the allegations that three UK customers had credit-card information leaked and that about 200 US customers may have been affected because of interactions with the call centre, said Symantec spokesman Cris Paden.

"We nailed it down to one agent at the call centre [who handled the Symantec customers]", he said. That agent was put on administrative leave pending the investigation, he added.

In addition to Puerto Rico, the states contacted were: New Hampshire, Maryland, New Jersey, Maine, Massachusetts, New York, Virginia and North Carolina, Paden said.

It was unclear how the data of the three UK customers went from the call centre into the hands of the man whom the BBC News said sold the credit-card numbers. Nor was it clear whether any data from the US customers had been leaked. Paden said there was no evidence any US data was exposed.

In a letter to New Hampshire attorney general Kelly Ayotte, dated 24 March, the security vendor said it was "investigating a potential security incident involving a small number of customers' credit-card information".

The letter said Symantec was sending a notice to an unnamed customer in New Hampshire who may have been affected by the alleged incident, even though the company does not believe a security breach as defined by New Hampshire statue had occurred.

The company said even though it has no evidence that the credit-card information of any US residents was compromised, it was offering its customers one year of identity-protection services through Debix as a precautionary measure, and reviewing its "security processes and third-party vendor protocols".

BBC News reported on 19 March that undercover reporters posing as fraudsters had gone to Delhi to buy 50 credit-card numbers, at $10 a card, from a man who claimed to have obtained them from a call centre. They filmed the interaction. The man denied any wrongdoing, the BBC said.

When the reporters contacted some of the card owners, three of them said they had bought Norton software from Symantec over the phone using their cards. The purchases were found to have been made within hours of each other and the numbers were sent to the BBC shortly thereafter, the report said.

Symantec has set up an email address for customers to contact to get more information at global_purchase_query@symantec.com.

The BBC was criticised recently for purchasing a botnet and using it in some tests to show the dangers web surfers face.

The Wall Street Journal was first to report on the Symantec letters to officials on Tuesday.

Talkback

While economically sound on costings, to put such information in the hands of comparatively poor 3rd world operators is somewhat irresponsible.
The information available to such call centre operators, regardless of location, should be limited to make it unusable on it's own.
There must always be one level of access information that is not available to call centre operators.

1000215420 1 Apr 09 14:03 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

dava4444

this spam bot is exasperating

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

:D I think the server exchange does slow down a bit round 5 to 7/8 pm but I find I mostly get 3 to 4 MBps on downloads and by that time there...

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

night before last

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

5MBps, I saw 5.8

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

honestly I do get

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

thank you for the support. ..but in

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

if you download a BIG file from the MS site then THAT is your *true* speed.

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

Hi Fat Pop Do Wop!

2 hours ago by dava4444 on I'd Rather Have a Bigger Byte Than a Little bit...Broadband
dava4444

it filters the word 'aittude' mis spelled intentionally

2 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

but with a fair amount of work, possibly. God Bless Dava

2 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

But I think Googles idea could be developed into an able paradigm. right now, no.

2 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

took there repos down for Ubuntu (I think there back now but they took a few months). I don't think there is a perfect answer,

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

but the community coding and ideas would be gratis, maybe that's why OEM's can be 'slackers' when it comes to Linux. they just sit back and let...

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

continued the bad point about that is hardware, a rival OEM can take your development and use it themselves and to retaliate you would have to go...

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

continued Okay how about something like Google's approach 'semi-open source'? . the OEM pours cash in to development and code, whilst opening it...

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

Hi Adrian em, interesting, yeah okay I can get this vibe, if I wanted VRec on my Tele I would need an embedded and tiny OS and you're totally...

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

Hi Adrian been trying to post for three days .this spam bot is a nightmare. Dava

4 hours ago by dava4444 on How to build a GUI for a toaster
dava4444

Hi James I totally agree. The new site makes me want to come and post, but the spam bot refers me at every turn. I even at one point, thought I...

5 hours ago by dava4444 on Spam? Filter Changed?
sameerhere

the future of mobile will be location and context aware. This means, you will have apps that will suggest you depending where you are right...

6 hours ago by sameerhere on Symbian^3 will do resistive multitouch, says Nokia
kenye2009

hello i would like to have some form of a answer to this question as it concerns the goverment i want to know why if your on state benefits as a...

7 hours ago by kenye2009 on ITN to launch ITV online news service

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now