# Suspect you’ve been compromised?

We'll help you respond.

[Security guidelines](https://bd.visa.com/dam/VCOM/download/merchants/cisp-what-to-do-if-compromised.pdf)

## Overview

In the event of a data breach, respond quickly. Contact your acquiring bank immediately.

* * *

## Response checklist

Follow these steps if you believe you have been compromised

To help protect and aid the investigation

- Stay alert and monitor all systems that have cardholder data or may have connections to the cardholder data environment.
- Do not log in or change passwords on the at-risk systems. Do not log in as ROOT.
- Detach the at-risk system from the network by unplugging the cable. Do not turn it off.
- Change secure service identification on the access point and all systems using a wireless connection, except the at-risk systems.
- Save all logs and electronic evidence.
- Keep a record of all actions taken.

Alert all necessary parties immediately

- Notify your internal information security group and incident response team.
- Notify your acquirer.

Deliver an Incident Report to your acquirer

- This should be done within 3 working days of the incident. See Appendix A of the [What to Do If Compromised guidelines](https://bd.visa.com/content/dam/VCOM/download/merchants/cisp-what-to-do-if-compromised.pdf) for the report template.

Deliver account numbers to your acquirer

Deliver all potentially compromised Visa, Interlink and Plus account numbers within 10 working days. Visa will distribute the numbers to issuers and safeguard confidentiality.

Note: Visa and your acquirer will determine whether to conduct an independent forensic investigation.

## Visa response team

Visa has two support groups to help you respond to a payment card breach.

### Visa Fraud Investigations

- Works to obtain all potentially compromised account numbers
- Shares at-risk account information with issuers
- Works with the appropriate law enforcement on your behalf
- Facilitates a timely forensic investigation
- [USFraudControl@visa.com](mailto:USFraudControl@visa.com)

### Data Security Team

- Provides guidelines to assist your response to the incident
- Supports you in identifying security deficiencies
- Makes sure you take action to minimize future risk to account information
- Helps you quickly verify PCI DSS compliance
- [cisp@visa.com](mailto:cisp@visa.com)

* * *

## More resources

### Find more information on protecting your business

[Minimising Payment Risks for Merchants Using Integrators/Resellers](https://bd.visa.com/content/dam/VCOM/download/merchants/webinar-merchants-using-integrators.pdf)

[Cybercriminals Targeting Point of Sale Integrators](https://bd.visa.com/content/dam/VCOM/download/merchants/webinar-managing-data-breaches.pdf)

[Effectively Managing Data Breaches](https://bd.visa.com/content/dam/VCOM/download/merchants/webinar-managing-data-breaches.pdf)

[Data Breach Communication Guidelines](https://bd.visa.com/content/dam/VCOM/global/support-legal/documents/responding-to-a-data-breach.pdf)

[Identifying and Mitigating Threats to E-Commerce Payment Processing](https://bd.visa.com/content/dam/VCOM/download/merchants/webinar-ecommerce-threats-public.pdf)

## Has your data been compromised?

Contact your acquirer immediately.

[View data breach guidelines](https://bd.visa.com/content/dam/VCOM/download/merchants/cisp-what-to-do-if-compromised.pdf)
