Commentary
The Inevitable Has Occurred: Heartland Payment Sued
The payment processor Heartland Payment Systems just got served with a lawsuit over the allegedly massive data breach.The payment processor Heartland Payment Systems just got served with a lawsuit over the allegedly massive data breach.According to this news story by Robert Westervelt at SearchSecurity.com, a lawsuit was filed in the U.S. District Court for the District of New Jersey:
It was filed on behalf of Alicia Cooper, a resident of Woodbury, Minn. The law firm says Heartland does not appear to be offering any credit-monitoring services or other relief to credit card holders affected by the breach.This was inevitable. The suit seeks to become a class action. It seems Cooper also wants to know the names of the affected merchants. The story also mentioned that the suit claims that Heartland Payment Systems wasn't compliant to the Payment Card Industry Data Security Standard.
More Security Insights
White Papers
More >>
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
Reports
More >>Webcasts
More >>
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
"In addition to the questionable timing of this disclosure, there are materially misleading statements and omissions contained in Heartland's public description of the breach and its consequences," according to the complaint filed by the law firm.
The funny thing is, I'm not sure what the relevance would be of releasing the names of the affected merchants: they may not have been breached at all. Also, it's not clear to me if Heartland was negligent when it actually learned of the breach, and the company claims to have been PCI compliant at the time of the breach. If this makes it to court, we just may find out.
The strange thing about these events is that a company that tries to do everything right, and takes reasonable approaches to security, can be breached. Perhaps that is what happened in this case.
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- Red Alert: Why Tablet Security Matters - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More












