PCI-DSS – placeholder
note to DG:
the crim needed the CVV. The CVV was only available from the magstripe itself, so a swipe or skimmer attack, or the interception of an authorisation message as the track 2 data is passed in full.
The data should not have been available from merchant databases as the CVV should not be stored. (this is defo true of the CVV2 but check it’s also true of the CVV – I think it is)
Follow the Conversation with Grok
Whilst I was putting this page together, I asked Grok to try an find the DHS minutes, and then I asked Grok to consider and make judgements in response to the arguments I was presenting. Click the button for the complete Grok conversation.

Explore the Future of Payments
The global payment ecosystems continues to evolve with technologies like AI, tokenisation, and real-time payments.
Stay ahead of the game by diving deeper into the world of payment processing.
Have questions or need expert insights? Contact us.