home news blogs forums events research newsletter whitepapers careers


Network Computing Network Computing Network Computing
HOT PICKS

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network Computing Blog
Lead Analyst:
Jordan Wiens
Jordan Wiens


More analysis, strategies and news at our
Data Privacy
Immersion Center


Subcribe to This Blog's
RSS Feed
SPECIAL EVENT BLOGS:
BrainShare 2008

IMMERSION CENTER BLOGS:
Network Access Control
Virtualization
Application Performance Optimization
Data Center
Data Privacy
802.11n
SOA/Web Services

MORE TOPCS:
Security
Wireless
Application Infrastructure
Collaboration
Network and Systems Management
Network Infrastructure
Storage and Servers
Enterprise Applications
Business Strategy
Personal Technology
Podcasts
NWC Inc
NWC Labs
Techno-Oddities

MORE GREAT BLOGS
Ars Technica
bMighty
Boing Boing
Geek.com
InformationWeek
IT Toolbox
TechCrunch



The Daily Spin Blog
Data Privacy Immersion Center Blog

March 18, 2008
New Credit Card Breach Will Test PCI
By Andrew Conry-Murray

The latest exposure of more than 4 million credit and debit card numbers may strain the validity and stability of the credit card industry's controversial security rules.

Yesterday the Hannaford Bros. grocery chain announced that more than 4 million customer credit and debit card account numbers were exposed. Hannaford Bros. also happens to be in compliance with the credit card industry's security rules. (Scroll to the bottom to read the PCI compliance statement.)

The Payment Card Industry Data Security Standards (PCI DSS) were put in place by the major card brands -- including Visa and MasterCard -- to ensure that retailers take sufficient steps to protect customer card data.

The card brands, particularly Visa, have a vested interest in demonstrating that PCI makes customer card data more secure. If a PCI-compliant retailer still gets breached, that's a lot of egg on Visa's face.

So what happens next?

First, the card brands will likely conduct an investigation to determine if the retailer was compliant at the time of the breach. As I wrote in a recent cover story, the PCI standards are vague enough that the card brands can probably find enough cause to determine that Hannaford Bros. was, in fact, noncompliant at the time of the breach.

The penalties for noncompliance are significant. The card brands can fine the retailer, and raise the transaction fees levied for each credit or debit card transaction.

A finding of noncompliance also will be potent ammunition for the inevitable lawsuits that will likely emerge.

One plaintiff is likely to be the banks that issued the cards to consumers. These banks eat any fraudulent charges made on the cards, and may have to cancel existing accounts and reissue new cards. So far, 1,800 fraud cases have been reported in connection with the breach.

This wouldn't be the first time banks sued a retailer. It's exactly what happened in the TJX case: a group of banks in the Northeast sued TJX and then settled. TJX also has settled separate class-action suits brought on behalf of consumers -- and promised to have a one-day sale as part of the settlement.

And here's another wrinkle. If Hannaford Bros. is a Level-1 merchant, it had to undergo an assessment by a third party to determine PCI compliance. If the card brands rule that Hannaford is noncompliant, will Hannaford sue its assessor? If so, that could have a chilling effect on other assessors and throw a monkey wrench into the PCI compliance process.

We'll follow the story as it develops. Stay tuned.

-- Posted at 11:07 AM in Daily Spin | Data Privacy Immersion Center





This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.








Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights