Sorry for the confusion – by ‘on site’ I mean, they get passed through CRC’s IT infrastructure, even if it’s only a temporary stop over. This still allows an angle of attack.
Who knows, CRC might completely outsource their payment to a 3rd party landing page, so no CC details are actually going through their infrastructure…
Recently, Play.com emailed customers to say their 3rd party email system (Silverpop) had been compromised. They were quick to state it was a 3rd party issue, not their own infrastructure.