Ask HN: Crap, I just downloaded over 10000 Credit Card Numbers - Now What?
https://news.ycombinator.com/item?id=1339743I'm a developer in the freelancing/early startup phase, and had a client ask me to look at their current CMS/Online Store. I found out that the service they're using is storing credit card numbers, names, addresses, phone numbers, and cvv - probably in plaintext too. Obviously this is NOT PCI Compliant!
I poked around a bit to see wtf is going on and unintentionally dumped the entire db of 10,000+ credit card numbers, cvv, etc. For ALL of the system's users!
I'm a good person, and I really would rather not use this information incorrectly, so what's the right thing to do that won't land me in jail?
If anyone is wondering the shopping cart service is apparently based in PHP.
Edit: I didn't make it clear enough, this is a service - like shopify - but definitely NOT shopify :) Appears to be locally operated, and has a good number of local clients.