August 03, 2005

Court orders CardSystems to retain breach information

Lawsuit says company and others were negligent in maintaining consumer credit data

SAN FRANCISCO - A California state court has ordered CardSystems Solutions and three other defendants in a class-action lawsuit to preserve evidence relating to a major breach of the Atlanta, Ga., credit-card processor's computer systems.

The court also has set a date for CardSystems, along with MasterCard International, Visa USA and Merrick Bank Corp., to argue over who bears ultimate responsibility for informing customers of the breach.

The court order, issued on Tuesday by the Superior Court of the State of Calif. in San Francisco, is the latest development in what may prove to be a long-running class-action lawsuit over the highly publicized theft of credit-card information at CardSystems' Tucson, Ariz., operations center, which was first disclosed in June.

The suit, filed shortly after the theft was revealed, claims that CardSystems was negligent in the way it maintained consumer credit data. In addition to monetary damages, the suit seeks to force CardSystems and the credit-card companies to notify California consumers whose data has been compromised.

Tuesday's order will make it more likely that the defendants are able to inform consumers, should the court side with the plaintiffs, according to Ira Rothken, managing partner of San Rafael, California-based The Rothken Law Firm, which filed the suit.

"We don't want any Enron shredding going on," said Rothken, referring to the much-publicized fraud case at the Texas oil giant. "Any documents arising out of the security vulnerability and breach investigation at CardSystems, we want preserved."

A second court order, also issued Tuesday, requires that the defendants prove that they are not responsible for notifying California residents whose information was exposed in the attack, Rothken said. CardSystems and the other companies in the case have argued that their member banks bear this responsibility, he said.

Representatives for CardSystems, MasterCard and Visa did not immediately return calls seeking comment.

Arguments will be heard on this matter on Aug. 17, and should the court rule in Rothken's favor, the four companies will "have to work together to ensure to get proper notice (to California consumers) about whether their credit card data was hacked."

CardSystems, a major credit-card transaction processor, has been roiled by revelations of the attack, which exposed as many as 40 million credit card accounts. Last month, two of its major customers, Visa and American Express Co. announced they were terminating their CardSystems contracts because of the security lapse.

REFERENCES:
Lawsuit filed over CardSystems data breach, Jun. 28, 2005
Visa, Amex cut ties with CardSystems due to breach, Computerworld (US), Jul. 22, 2005
Stolen records in latest breach were improperly kept, Jun. 20, 2005




Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.