FierceFinanceFierceFinanceITFierceComplianceIT   FierceCIO

Fallout from a hacking incident

The problem with breaches is that there is so much blame that has to go around. If there are big losses, you can't just sit back and do nothing. You've got to sue! So it goes with Merrick Bank, which has sued Savvis, claiming $16 million in damages after hackers compromised up to 40 million credit card accounts.

Merrick Bank argues that it hired Savvis to check if vendor CardSystems was compliant with MasterCard and Visa anti-breach standards. Savvis gave CardSystems a clean bill of health. Less than a year after Merrick hired CardSystems, the processors' computer systems were breached, and millions of credit card account numbers were stolen. The banks say the info was lost because CardSystems kept unencrypted card information on its servers, violating security regulations for which Savvis had certified it. The complaint was filed in May 2008, but it is just now coming to light. 

For more:
- here's a summary
- here's a copy of the complaint

Related Articles:
Sarbox an issue for Google apps adoption?
The compliance dangers of Web 2.0
Hacking compliance-related concerns on the rise

SHARE WITH:
Email Twitter Facebook LinkedIn StumbleUpon
Get Your FREE FierceComplianceIT Email Newsletter:
Be the first to comment

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.