Court orders CardSystems to retain breach information
Evidence needed in case of 40M exposed credit card numbers
IDG News Service - A California state court has ordered CardSystems Solutions Inc. and three other defendants in a class-action lawsuit to preserve evidence related to a major breach of the Atlanta credit-card processor's computer systems.
The court also has set a date for CardSystems, along with MasterCard International Inc., Visa U.S.A. Inc. and Merrick Bank Corp., to argue over who bears ultimate responsibility for informing customers of the breach (see "Security breach may have exposed 40M credit cards").
The court order, issued on Tuesday by the Superior Court in San Francisco, is the latest development in what may prove to be a long-running class-action lawsuit over the highly publicized theft of credit card information at CardSystems' Tucson, Ariz., operations center. The breach was first disclosed in June.
The suit, filed shortly after the theft was revealed, claims that CardSystems was negligent in the way it maintained consumer credit data. In addition to monetary damages, the suit seeks to force CardSystems and the credit card companies to notify the California consumers whose data was compromised.
The order will make it more likely that the defendants are able to inform consumers, should the court side with the plaintiffs, according to Ira Rothken, managing partner of San Rafael, Calif.-based The Rothken Law Firm, which filed the suit.
"We don't want any Enron shredding going on," said Rothken, referring to the much-publicized fraud case at the Texas energy giant. "Any documents arising out of the security vulnerability and breach investigation at CardSystems we want preserved."
A second court order, also issued Tuesday, requires that the defendants prove that they are not responsible for notifying California residents whose information was exposed in the attack, Rothken said. CardSystems and the other companies in the case have argued that their member banks bear this responsibility, he said.
Representatives for CardSystems, MasterCard and Visa did not immediately return calls seeking comment.
Arguments will be heard on the matter on Aug. 17, and should the court rule in Rothken's favor, the four companies will "have to work together to ensure to get proper notice [to California consumers] about whether their credit card data was hacked."
CardSystems, a major credit-card transaction processor, has been roiled by revelations of the attack, which exposed as many as 40 million credit card accounts. Last month, two of its major customers, Visa and American Express Co., announced that they were terminating their CardSystems contracts because of the security lapse (see "Visa, Amex cut ties with processing firm hit by security breach").



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts