SHARE
Facebook X Pinterest WhatsApp

CardSystems Settles Data Breach Charges

Written By
thumbnail
Roy Mark
Roy Mark
Feb 24, 2006


A credit card processor settled charges with the Federal Trade Commission
(FTC) Thursday over what the FTC characterizes as the largest known compromise of financial data to date.


Last June, CardSystems revealed
it exposed personal information on more than 40 million credit cards after
hackers cracked into the firm’s computer system.


The FTC said CardSytems’s lax security practices, taken together, constituted
an unfair trade practice.


To settle the charges, CardSystems agreed to implement an information
security program and to obtain audits from an independent third-party
security professional every other year for 20 years.


“CardSystems kept information it had no reason to keep and then stored it in
a way that put consumers’ financial information at risk,” FTC Chairman
Deborah Platt Majoras said in a statement. “Any company that keeps sensitive
information must take steps to ensure that the data is held in a secure
manner.”


There was no fine included in the settlement since the statute under which
CardSystems was charged prohibits civil penalties.

In a similar case charged
under a different law, data broker ChoicePoint paid a record $10 million fine for inadequately protecting consumer data.


CardSytems does, however, face potential financial liability under banking
laws and private litigation for losses related to the breach.


According to the FTC, CardSystems, as a credit card processor, provided
merchants with hardware and software used in obtaining approval for credit
and debit card purchases from the banks that issued the cards.


CardSystems collected the personal information, including card numbers and
expiration dates, from the magnetic strip on the cards. In 2005, CardSystems
processed more than 210 million card purchases totaling more than $15
billion.


The company then stored the information on its own system where it
eventually became exposed to data theft.


The FTC charged CardSystems with creating unnecessary risks to the
information by storing it, including not using readily available security
measures.

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.