Sunday, April 27, 2025
HomeData BreachOver 9 Million Credit Card Data Exposed from Leading Payment Systems

Over 9 Million Credit Card Data Exposed from Leading Payment Systems

Published on

SIEM as a Service

Follow Us on Google News

An open and unprotected database with 9,098,506 records of credit card transactions was discovered recently by security researcher Jeremiah Fowler and the Website Planet research team.

There were a number of essential pieces of information like Personally Identifiable Information (PII) contained in this data. Moreover, it has been found that the majority of these transactions are donations or recurring payments to:-

  • Religious organizations
  • Charity campaigns
  • Nonprofit groups

Cornerstone Payment Systems, a California-based credit card processing company, was identified as the owner of the database we were able to acquire. Following the researchers’ notification, they immediately restricted public access to the information, giving a strong thank you to them for reporting this mistake. 

- Advertisement - Google News

A particular danger associated with cybercrimes involving credit and financial information is the ability of threat actors to establish a target profile by using the following data:-

  • Credit card numbers
  • Account information
  • Transaction information
  • Names
  • Contacts
  • Donation comments

Phishing attacks and social engineering attacks can then be launched by these criminals. Cyber attacks involving social engineering account for 98% of all attacks.

Exposed Database Contents

Here below we have mentioned all the key information that this exposed database contains:-

  • 9,098,506 Number of Records Exposed
  • Merchants
  • Users
  • Customer names
  • Physical addresses
  • Email addresses
  • Phone numbers
  • 3,641 Gmail addresses
  • 1,194 Yahoo addresses
  • Small numbers of MSN
  • Comcast
  • Other providers or private email servers
  • Partial card numbers
  • Type of card
  • Valid dates
  • Donation details
  • Recurring payments
  • Comments
  • Dollar amount
  • Donation cause
  • Electronic check payment data
  • Bank names
  • Check numbers
  • Authorization tokens
  • Anonymous donors

It is important to note that the processing of credit cards involves transmitting sensitive information about credit cardholders in connection with the approval or denial of transactions.

Credit industry compliance standards such as PCI DSS, which covers the protection of credit card information, are strict.

Criminals could reach out to customers and pretend to be legitimate merchants or organizations in order to defraud them and cause a loss of money.

Considering that only the group that the victim had donated to or the merchant from whom the victim purchased their goods would have known the information, the victim would have little reason to doubt that the call.

As a matter of fact, it is not uncommon for hackers to adopt vigilante tactics and target specific individuals in an attempt to gain an advantage.

For this reason, it is imperative that any organization that collects and stores personally identifiable information should use robust encryption methods and also implement other security measures to ensure that their sensitive information is protected.

Secure Web Gateway – Web Filter Rules, Activity Tracking & Malware Protection – Download Free E-Book

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Claim TikTok Breach, Leak Over 900,000 Usernames and Passwords

A hacker collective known as R00TK1T claims to have breached TikTok's user database, allegedly...

Blue Shield Exposed Health Data of 4.7 Million via Google Ads

Blue Shield of California has disclosed a significant data privacy incident affecting up to...

Hackers Exploit Stolen Certificates and Private Keys to Breach Organizations

Recent research has unveiled a concerning vulnerability within the realm of containerized applications, where...