Why Does Account Testing Persist?
Account testing exploits vulnerabilities that exist in a part of the payments system not directly related to the storage, processing or transmission of cardholder data. In companies that segregate their data networks, these systems may be outside the scope of security measures required by the Payment Card Industry Data Security Standard (PCI DSS) and the Cardholder Data Environment.
These vulnerabilities allow virtual and physical merchant terminals to be compromised or copied and used to submit fraudulent authorizations, credits or other malicious messages into an acquiring processor’s merchant administration system. These terminals may be copied without the merchant’s knowledge, making it impractical to simply delete the terminals without detailed planning and communication.