New Credit Card Breach Will Test PCI

The latest exposure of more than 4 million credit and debit card numbers may strain the validity and stability of the credit card industry's controversial security rules....

Andrew Conry-Murray

March 18, 2008

2 Min Read
Network Computing logo

The latest exposure of more than 4 million credit and debit card numbers may strain the validity and stability of the credit card industry's controversial security rules. Yesterday the Hannaford Bros. grocery chain announced that more than 4 million customer credit and debit card account numbers were exposed. Hannaford Bros. also happens to be in compliance with the credit card industry's security rules. (Scroll to the bottom to read the PCI compliance statement.)

The Payment Card Industry Data Security Standards (PCI DSS) were put in place by the major card brands -- including Visa and MasterCard -- to ensure that retailers take sufficient steps to protect customer card data.

The card brands, particularly Visa, have a vested interest in demonstrating that PCI makes customer card data more secure. If a PCI-compliant retailer still gets breached, that's a lot of egg on Visa's face.

So what happens next?

First, the card brands will likely conduct an investigation to determine if the retailer was compliant at the time of the breach. As I wrote in a recent cover story, the PCI standards are vague enough that the card brands can probably find enough cause to determine that Hannaford Bros. was, in fact, noncompliant at the time of the breach.The penalties for noncompliance are significant. The card brands can fine the retailer, and raise the transaction fees levied for each credit or debit card transaction.

A finding of noncompliance also will be potent ammunition for the inevitable lawsuits that will likely emerge.

One plaintiff is likely to be the banks that issued the cards to consumers. These banks eat any fraudulent charges made on the cards, and may have to cancel existing accounts and reissue new cards. So far, 1,800 fraud cases have been reported in connection with the breach.

This wouldn't be the first time banks sued a retailer. It's exactly what happened in the TJX case: a group of banks in the Northeast sued TJX and then settled. TJX also has settled separate class-action suits brought on behalf of consumers -- and promised to have a one-day sale as part of the settlement.

And here's another wrinkle. If Hannaford Bros. is a Level-1 merchant, it had to undergo an assessment by a third party to determine PCI compliance. If the card brands rule that Hannaford is noncompliant, will Hannaford sue its assessor? If so, that could have a chilling effect on other assessors and throw a monkey wrench into the PCI compliance process.We'll follow the story as it develops. Stay tuned.

About the Author(s)

Andrew Conry-Murray

Former Director of Content & Community

SUBSCRIBE TO OUR NEWSLETTER
Stay informed! Sign up to get expert advice and insight delivered direct to your inbox
More Insights