NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

Security


2004 Data Breach Prompts Game Changing Lawsuit

Will decide if security auditors can be held liable for their reports

By Lucian Constantin, Web News Editor

4th of June 2009, 09:44 GMT

Adjust text size:


CardSystems data breach brings lawsuit against auditor four years later
Enlarge picture
Four years after a major data breach occurred at CardSystems Solutions, the auditing company that certified the payment processor is taken to court by the bank that contracted with CardSystems based on its report. Experts say that the lawsuit could set an important precedent for auditor accountability.

Utah-based Merrick Bank sued Savvis Inc. last year for negligence in the process of auditing the security solutions and policies implemented by CardSystems, an action that ended up costing the bank $16 million in fraud-related losses. The trial is set to commence in Arizona in the near future, according to Wired.

In June 2004, Savvis certified CardSystems Solutions as being compliant with the Cardholder Information Security Program (CISP), the precursor of today's Payment Card Industry Data Security Standard (PCI DSS). As a result Merrick Bank signed a contract with CardSystems to process credit card transactions for its customers.

However, after only three months, hackers obtained unauthorized access to the processor's network, from where they stole the details of 263,000 credit cards, which were stored in unencrypted form. Another 40 million cards, which were never confirmed stolen, were nevertheless considered compromised because of the incident.

Even though Visa added CardSystems Solutions to its list of certified payment processors based on the Savvis report, after the breach was investigated it concluded that the company was not actually compliant. Visa also noted that CardSystems did not pass an audit in 2003, which was performed by a company acquired by Savvis shortly before the 2004 audit.

Merrick Bank alleges that Savvis failed to "competently and professionally assess CardSystems’ compliance," since it was later discovered that the processor was storing credit card data unencrypted for at least five years before the incident and its firewall did not meet the Visa requirements. None of these security lapses were mentioned in the Savvis audit report sent to Visa in order to get certification.

Andrea Matwyshyn, a law and business ethics professor at the University of Pennsylvania’s Wharton School, told Wired that in her opinion "it’s not clear as a matter of law to what extent a certification authority has liability in this particular context for a negligent misrepresentation of the security level of an enterprise."

This trial might clear that up and set the scene for future ones. RBS WorldPay and Heartland Payment Systems, two large U.S.-based payment processors, suffered major data breaches that already resulted in millions of dollars being lost to fraud a few months back. Both companies were compliant with PCI DSS when the incidents occurred, but were later removed from Visa's list of certified service providers.

TAGS:

CardSystems Solutions | Savvis lawsuit | Merrick Bank | auditor liability | data breach
Read by 1,188 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Online Merchant's Server Hacking Results in Data Breach

Data Breach Costs Heartland $12.6 Million So Far

PCI-DSS Non-Compliant Payment Processor Wins IRS Contract

285 Million Records Compromised in 2008 During 90 Breaches

$10 Million Stolen by Notorious Israeli hacker

Heartland and RBS WorldPay No Longer PCI Compliant

New Payment Processor Data Breach on the Horizon

RBS WorldPay Security Breach Earns Fraudsters $9 Million

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM