So you’re saying that the merchant data has not been accessed?
> It hasn’t. If you see, apache 2.2.14 – we’ve been live with apache 2.2.17 for last five months.
You’re also saying that merchant account passwords have not been stored as plain text?
> They are encrypted, and not stored as plain text.
Have you ever been told that there is a security hole of some sort?
> We are looking into this, and this is the intial report. From time to time what we get, I am sharing with you. As more information comes out as we investigate, we will share it.
Yep. Typically passwords are hashed and salted. However, I have seen non-technical folks use the terms hashing and encryption exchangeably. Hopefully thats the case here.
Anyways, since CCAvenue didn't store the full CC number (and they definitely didn't store the passcode - for that it redirected to the issuing bank/organization), this doesn't seem to be a very serious issue, even if true.