Reply to post:

TalkTalk offers customer £30.20 'final settlement' after crims nick £3,500

ekky

I couldn't help but notice that they insisted that the credit card information had been tokenized, but gave no mention of ACH information. Considering the article mentioned that the money had vanished from the victim's personal bank account, I'd suspect that they were storing bank account:routing numbers in plain text.

Which, as everyone knows, is not PCI compliant.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon