CONSUMER NEWS    RECALLS    COMPLAINT FORM    SCAM ALERTS  


Complain about a product or service

Small Claims Guide | Class Actions | Lemon Law | FAQ | Resources | Newsletters | Spanish
Automotive    Education    Electronics    Family    Finance    Health    Homeowners    Shopping    Travel   
NEWS   Latest |  Archives |  Auto |  Cells, etc. |  Computers |  Financial |  Health |  Homeowners |  Parents |  Privacy |  Scams |  Seniors |  Travel

CardSystems Solutions Settles Federal Charges

Tens of Millions of Consumer Credit and Debit Card Numbers Compromised



February 23, 2006

CardSystems
CardSystems Solutions Settles Federal Charges
CardSystems Sells Out After Massive Data Breach
Visa Gives CardSystems a Reprieve, Pending Sale to CyberSource
Setback for Consumers in CardSystems Class Action
CardSystems May Shut Down
CardSystems Losing Big Customers
Cardsystems Named in Class Action Suit
States Want CardSystems to Provide Details of Data Breach
Washington State Wants CardSystems to Provide Details of Data Breach
Latest Security Breach Exposes 40 Million Credit Card Accounts to Potential Fraud
---
More about Identity Theft ...

CardSystems Solutions has settled federal charges growing out of the largest known compromise of financial data to date.

CardSystems Solutions, Inc. and its successor, Solidus Networks, Inc., doing business as Pay By Touch Solutions, settled Federal Trade Commission charges that CardSystems' failure to take appropriate security measures to protect the sensitive information of tens of millions of consumers was an unfair practice that violated federal law.

According to the FTC, the security breach resulted in millions of dollars in fraudulent purchases. The settlement will require CardSystems and Pay By Touch to implement a comprehensive information security program and obtain audits by an independent third-party security professional every other year for 20 years.

This is the ninth FTC case targeting companies whose security practices compromised consumers' confidential financial information, and the first the Commission has brought against a credit card processor.

"CardSystems kept information it had no reason to keep and then stored it in a way that put consumers' financial information at risk," said Deborah Platt Majoras, Chairman of the FTC. "Any company that keeps sensitive consumer information must take steps to ensure that the data is held in a secure manner."

According to the FTC, CardSystems provided merchants with products and services used in "authorization processing" -- obtaining approval for credit and debit card purchases from the banks that issued the cards. Last year, it processed about 210 million card purchases, totaling more than $15 billion, for more than 119,000 small and mid-size merchants.

In processing these transactions, CardSystems collected personal information from the magnetic strip of the card, including the card number, expiration date, and other data. CardSystems then stored this information on its computer network.

Pay By Touch acquired CardSystems' assets in December 2005, and now processes transactions for the merchants CardSystems served.

The FTC charged that CardSystems engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for sensitive consumer information. Specifically, the agency alleges that CardSystems:

• created unnecessary risks to the information by storing it;

• did not adequately assess the vulnerability of its computer network to commonly known or reasonably foreseeable attacks, including "Structured Query Language" injection attacks;

• did not implement simple, low-cost, and readily available defenses to such attacks;

• did not use strong passwords to prevent a hacker from gaining control over computers on its computer network and access to personal information stored on the network;

• did not use readily available security measures to limit access between computers on its network and between its computers and the Internet; and

• failed to employ sufficient measures to detect unauthorized access to personal information or to conduct security investigations.

According to the FTC's complaint, these practices compromised millions of credit and debit cards, and led to millions of dollars in fraudulent purchases.

In addition, after the fraud was discovered, banks cancelled and re-issued thousands of credit cards, and consumers experienced inconvenience, worry, and time loss dealing with the affected cards.

The proposed settlement requires CardSystems and Pay By Touch to establish and maintain a comprehensive information security program that includes administrative, technical, and physical safeguards.

The settlement also requires them to obtain -- every two years for the next 20 years -- an audit from a qualified, independent, third-party professional that confirms that its security program meets the standards of the order, and to comply with standard bookkeeping and record-keeping provisions.

This case is similar to prior FTC actions involving alleged failures to secure credit and debit card information. As in the prior cases, CardSystems faces potential liability in the millions of dollars under bank procedures and in private litigation for losses related to the breach.



Report Your Experience
If you've had a bad experience -- or a good one -- with a consumer product or service, we'd like to hear about it. All complaints are reviewed by class action attorneys and are considered for publication on our site. Knowledge is power! Help spread the word. File your consumer report now.


Consumer News

May 16 2008

Recent Recalls & Safety Alerts

READER SERVICES

Print, Email & More

Subscribe

Free consumer newsletters
Sign up now!



Back to the top |

Advertisement


Home | Rogues Gallery | Good Guys | Complaint Form | News | Recalls | Search | Video | FAQ |
Consumer Resources | Small Claims Guide | Lemon Law | Newsletter | Contact Us
Advertise With Us | Testimonials | Newsroom | RSS Feeds | Radio | Job Postings




Terms of Use Your use of this site constitutes acceptance of the Terms of Use

Advertisements on this site are placed and controlled by outside advertising networks. ConsumerAffairs.com does not evaluate or endorse the products and services advertised. See the FAQ for more information.

Company Response Welcome If complaints about your company appear on our site, we welcome your response. Please see the Response Form for more information.

For more information, see the FAQ and privacy policy. The information on this Web site is general in nature and is not intended as a substitute for competent legal advice.  ConsumerAffairs.com Inc. makes no representation as to the accuracy of the information herein provided and assumes no liability for any damages or loss arising from the use thereof. 

Copyright © 2003-2008 ConsumerAffairs.com Inc.  All Rights Reserved.