Commentary
New Credit Card Breach Will Test PCI
The latest exposure of more than 4 million credit and debit card numbers may strain the validity and stability of the credit card industry's controversial security rules.The latest exposure of more than 4 million credit and debit card numbers may strain the validity and stability of the credit card industry's controversial security rules.Yesterday the Hannaford Bros. grocery chain announced that more than 4 million customer credit and debit card account numbers were exposed. Hannaford Bros. also happens to be in compliance with the credit card industry's security rules. (Scroll to the bottom to read the PCI compliance statement.)
The Payment Card Industry Data Security Standards (PCI DSS) were put in place by the major card brands -- including Visa and MasterCard -- to ensure that retailers take sufficient steps to protect customer card data.
More Software Insights
White Papers
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- Red Alert: Why Tablet Security Matters - by BlackBerry
Reports
More >>Webcasts
- Maximize ROI with Database Consolidation onto Private Clouds
- The ABC's of Cloud Computing in the Midmarket
The card brands, particularly Visa, have a vested interest in demonstrating that PCI makes customer card data more secure. If a PCI-compliant retailer still gets breached, that's a lot of egg on Visa's face.
So what happens next?
First, the card brands will likely conduct an investigation to determine if the retailer was compliant at the time of the breach. As I wrote in a recent cover story, the PCI standards are vague enough that the card brands can probably find enough cause to determine that Hannaford Bros. was, in fact, noncompliant at the time of the breach.
The penalties for noncompliance are significant. The card brands can fine the retailer, and raise the transaction fees levied for each credit or debit card transaction.
A finding of noncompliance also will be potent ammunition for the inevitable lawsuits that will likely emerge.
One plaintiff is likely to be the banks that issued the cards to consumers. These banks eat any fraudulent charges made on the cards, and may have to cancel existing accounts and reissue new cards. So far, 1,800 fraud cases have been reported in connection with the breach.
This wouldn't be the first time banks sued a retailer. It's exactly what happened in the TJX case: a group of banks in the Northeast sued TJX and then settled. TJX also has settled separate class-action suits brought on behalf of consumers -- and promised to have a one-day sale as part of the settlement.
And here's another wrinkle. If Hannaford Bros. is a Level-1 merchant, it had to undergo an assessment by a third party to determine PCI compliance. If the card brands rule that Hannaford is noncompliant, will Hannaford sue its assessor? If so, that could have a chilling effect on other assessors and throw a monkey wrench into the PCI compliance process.
We'll follow the story as it develops. Stay tuned.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- Red Alert: Why Tablet Security Matters - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Broadcast
This white paper explains how to create a manageable, scalable environment suited to answer real-time business needs by building out a data center on a standards-based, virtualization-aware, energy-efficient and affordable platform. Plus, learn how virtualization is making the jump from the server realm into the application, mobile and database worlds in the additional resources section.
Learn More












