advertisement
advertisement

CyberSource to Take Over CardSystems

Written by Evan Schuman
September 23rd, 2005

With the nation’s worst credit card security disaster on its resume and AmericanExpress and Visa cutting its contract, payment processor CardSystems has few long-term options.

In what might signal the closing chapter in the CardSystem credit-card security breach saga, CyberSource Friday announced its intent to acquire all of CardSystem’s assets for an undisclosed amount.

In May, CardSystems Inc. reported its role in the nation’s largest known data security breach, when it revealed that someone had broken into its systems and stolen the details of as many as 40 million payment cards, including names, account numbers and expiration dates.

CardSystems might have been considered the victim in the incident had it not admitted to having violated its contracts with Visa, American Express and others by failing to encrypt credit card transaction data and by keeping on file card verification numbers that are never supposed to be stored.

The day before testifying before a U.S. House subcommittee, both Visa and American Express announced they were terminating their relationships with CardSystems. MasterCard said it would continue if CardSystems met various criteria.

Friday’s statement from CyberSource confirmed that it had signed on Sept. 20 a non-binding letter of intent to acquire the assets of CardSystems.

Those assets, the statement said, include “CardSystems advanced payment processing platform with direct connections to major credit card association networks and banks, contracts to process credit card transactions on behalf of more than 120,000 merchants representing more than $18 billion in annual processing volume and a network of Independent Sales Organizations (ISOs).”

The distinction between wanting to purchase the assets of CardSystems and purchasing the company itself is significant, said Colin Gillis, the equity research analyst who tracks CyberSource for the Adams Harkness Inc. investment firm.

Given the substantial liability from various potential lawsuits and government investigations, purchasing the company would bring those liabilities to CyberSource.

By purchasing just the assets, CyberSource would, in theory, not be accepting those liabilities, Gillis said.

When both American Express and Visa announced they were terminating their CardSystems contracts, many industry observers questioned whether the processing firm could survive.

During testimony before a Congressional investigative committee, even CardSystems CEO John Perry raised the issue of whether his company could survive without those credit card giants’ support.

That background suggests that CyberSource could be picking up CardSystems’ assets at a substantial discount.

“For CardSystems, this seems like it was something they had to do because of the tremendous bad publicity and security problems,” said IHL Services President Greg Buzek said. “That’s a shame because people spend so much time building something and because of this mistake and criminals, they are basically forced to sell.”

As for the pricing, he added: “I’m sure CyberSource will get the assets at a greatly discounted rate compared with what it would have been a year ago.”

Bruce Frymire, the director of corporate communications and investor relations for CyberSource, wouldn’t comment on the price his company has offered to pay, but he did challenge the premise that it would be a huge discount.

“We do not feel like we paid anything like a fire sale price,” Frymire said.

Another financial analyst that tracks CyberSource?Franco Turrinelli at William Blair & Co.?said there are too many unknowns to determine if the price would be heavily discounted.

CyberSource CEO Bill McKiernan’s team “are pretty smart people. I don’t think Bill and his team are going to overpay.”

Gillis also questioned whether the discounting here would be that substantial.

The $18 billion in processing volume probably amounts to only about 10 cents or 11 cents per transaction, which Gillis estimates would give the privately held CardSystems about $17 million to $20 million in annual revenue.

“So I would expect, at the end of the day, to see this going for between $20 million and $30 million,” he said. “It’s an interesting transaction but it’s a lot smaller than people think.”

But for CyberSource?which Gillis projects will have about $50 million in annual revenue this year, growing to about $63 million next year?that’s not a trivial purchase.

Financial analyst Turrinelli said he sees this deal as a very preliminary work in progress.

“My initial reaction is that it’s a non-binding letter of intent,” Turrinelli said. “There are clearly still a lot of negotiations left.”

The big question hanging over the deal is whether Visa and/or American Express will reverse themselves and welcome what had been the CardSystems team back into its operations.

“If Visa or American Express do not flip, it will be a very different deal,” Turrinelli said, adding that the technology assets wouldn’t change either way.

For CyberSource, the asset acquisition has some nice side benefits, such as improving its small business channel and the ability to take processing business away from a direct competitor?Authorize.net?which had been working with CardSystems on E-Commerce transactions.

About 20 percent of CardSystems revenue is in E-Commerce, Gillis said.

“They’ll immediately be able to boot those (Authorize.net) guys out and take that business,” Gillis said.

But this deal isn’t final, and the big wildcard is how the credit card companies will react.

If American Express and Visa?and, for that matter, MasterCard?do not agree to resume business because of the change in management, the deal could die, Gillis said.

The CyberSource statement also stressed that the deal is far from final. “The transaction is subject to further due diligence, execution of a purchase agreement, satisfaction of closing conditions and may also be subject to governmental or other regulatory approvals,” it said.

“The transaction is expected to close in the fourth quarter of 2005. The letter of intent provides for an exclusivity period during which CardSystems is not permitted to engage any other entity regarding the sale of its business.”

Many of the issues surrounding CardSystems are more perception than strict security. Given that the company violated key provisions of contracts and has announced no punitive measures such as resignations or firings, some have criticized CardSystems senior management for not having taken sufficient responsibility.

Typically, in this kind of a purchase, the acquiring company provides assurances to customers that key management players and the company’s brand would be preserved. In this instance, though, Gillis said, the opposite is more likely.

“I would expect the management team at CardSystems will not be needed,” Gillis said. “You can show that what CardSystems did won’t be tolerated by the industry and that these people will be unemployed.”

CyberSource’s Frymire wouldn’t say whether any members of top management would be offered jobs. “We do expect to extend (jobs) to most of the current CardSystems employees,” he said, adding that he couldn’t discuss individual personnel.

As for the overall reputation of the company whose assets are being acquired, Frymire said that he hoped the good brand attributes of CyberSource would overcome the negatives from CardSystems.

“My belief at this moment is that we would not keep the (CardSystems) name,” he said.

Frymire described CardSystems as “a solid company that experienced an unfortunate breach. We do hope that CyberSource’s strong reputation hopefully prevails and that the reputation of CyberSource will have the mindshare of customers and observers rather than the reputation of the CardSystems incident. Over time, CyberSource’s reputation for security and integrity will win out.”

IHL’s Buzek said the technology assets of CardSystems?coupled with its extensive infrastructure?is not trivial.

“They have some excellent technology. With a new home and heavier security from CyberSource, the service should be much stronger,” Buzek said.


advertisement

Comments are closed.

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.