The bank hasn't said anything because they haven't found out yet... or you haven't experienced a fraud yet.
I can't recall the case exactly, but a few years ago a webshop owner here in the UK was processing cards in this fashion and a fraudster hacked into their site, got a stack of card numbers, and the CVV numbers AND the customers' addresses... and then had a field day! With all that "required" info to hand, there was no stopping the rapid carnage that followed.
Within 72 hours, the crooks had done over £100,000 "damage".
The affected banks sued the shop owner for the loss, AND the costs of administering the problem.
The chap lost his business, his house and I think he's still trying to pay everything off.
You need to configure a payment gateway (like PayPal) so that card transactions take place AWAY from your server...




