An open and unprotected database with 9,098,506 records of credit card transactions was discovered recently by security researcher Jeremiah Fowler and the Website Planet research team.
There were a number of essential pieces of information like Personally Identifiable Information (PII) contained in this data. Moreover, it has been found that the majority of these transactions are donations or recurring payments to:-
Cornerstone Payment Systems, a California-based credit card processing company, was identified as the owner of the database we were able to acquire. Following the researchers’ notification, they immediately restricted public access to the information, giving a strong thank you to them for reporting this mistake.
A particular danger associated with cybercrimes involving credit and financial information is the ability of threat actors to establish a target profile by using the following data:-
Phishing attacks and social engineering attacks can then be launched by these criminals. Cyber attacks involving social engineering account for 98% of all attacks.
Here below we have mentioned all the key information that this exposed database contains:-
It is important to note that the processing of credit cards involves transmitting sensitive information about credit cardholders in connection with the approval or denial of transactions.
Credit industry compliance standards such as PCI DSS, which covers the protection of credit card information, are strict.
Criminals could reach out to customers and pretend to be legitimate merchants or organizations in order to defraud them and cause a loss of money.
Considering that only the group that the victim had donated to or the merchant from whom the victim purchased their goods would have known the information, the victim would have little reason to doubt that the call.
As a matter of fact, it is not uncommon for hackers to adopt vigilante tactics and target specific individuals in an attempt to gain an advantage.
For this reason, it is imperative that any organization that collects and stores personally identifiable information should use robust encryption methods and also implement other security measures to ensure that their sensitive information is protected.
Secure Web Gateway – Web Filter Rules, Activity Tracking & Malware Protection – Download Free E-Book
A recent security vulnerability in a widely used airline integration service has exposed millions of…
In a groundbreaking cybersecurity investigation, researchers identified several critical vulnerabilities in a target system, eventually…
A critical vulnerability in the Cacti performance monitoring framework tracked as CVE-2025-22604, has been disclosed,…
Cisco Talos researchers have identified an ongoing cyber campaign, active since mid-2024, deploying a previously…
A groundbreaking technique for exploiting Windows systems has emerged, combining the "Bring Your Own Vulnerable…
Microsoft has taken a significant step toward enhancing cybersecurity by introducing a new phishing attack…