03-18-13 | Blog Post
On March 7th, the sportswear company Genesco filed a lawsuit against Visa. The issue? In 2010 Genesco’s computer system was breached, potentially allowing customer credit card information to be accessible to attackers. Due to this data breach, Visa charged Genesco with over $13 million in fines for noncompliance with the Payment Card Industry Data Security Standards (PCI-DSS).
Now, Genesco is claiming that the attackers did not access any stored payment card data from their systems, but was trying to get the data as it was being transmitted to credit card processors using packet-sniffing malware on the company’s network. Coming straight from the Genesco complaint:
The feature of the payment card system that the criminals sought to exploit in the Intrusion is that, according to PCI DSS security protocols and consistent with longstanding and pervasive industry practice, the payment card account data required for approval of a mag-stripe-swipe transaction is permitted to be transmitted in unencrypted form during the transaction approval process.
The fines imposed on merchants after a data breach are supposed to be for their failure to meet PCI standards, resulting in noncompliance, but Genesco attests in their complaint that they were compliant at the time of the breach.
Also, Visa stated at the time of the breach that every Visa card processed by Genesco from December 2009 through December 2010 had been compromised, which is another assertion Genesco disagrees with, stating that when their servers reboot any cardholder data that may have been temporarily stored in log files would have been overwritten. This would mean a slim chance of a whole year’s worth of data being stored within their system. Genesco also claims that Visa has no forensic evidence that the aforementioned accounts had, in fact, been compromised.
This lawsuit is the first recorded in which a merchant has challenged the PCI noncompliance fines after a data breach. Mastercard also imposed fines, but currently Genesco has not filed a lawsuit against them for them.
Looking for more information on PCI hosting requirements, recommendations, and the foundation of a secure PCI compliant data center?
Download our PCI Compliant Hosting white paper now for a complete guide to PCI hosting with IT vendors.