Thursday, September 18, 2008

Forever 21 -- Breached and PCI Compliant

I anticipate we will be seeing a lot more instances of merchants suffering payment card breaches while PCI compliant. The question is, will they be held liable for those breaches. An article soon on that. For now, here is an article on Forever 21, which just reported a breach involving over 98,000 card numbers. Forever 21 claims that is has been certified as PCI compliant since 2007. However, all of the incidents happened from March 2004 to August 2007. Therefore it is possible that Forever 21 was not PCI-compliant at the time of the incidents, but became so in after August 2007.

Wednesday, August 27, 2008

Best Western: PCI Compliant and Hacked

While the details are still murky on the number of records impacted (somewhere between 13 and 8 million), it appears that we have a security breach of another high profile corporation claiming PCI compliance at the time of breach. SC Magazine has the story here.

Here is Best Western's statement on the breach:
“We comply with the Payment Card Industry (PCI) Data Security Standards (DSS). To maintain that compliance, Best Western maintains a secure network protected by firewalls and governed by a strong information security policy. We collect credit card information only when it is necessary to process a guest’s reservation; we restrict access to that information to only those requiring access and through the use of unique and individual, password-protected points of entry; we encrypt credit card information in our systems and databases and in any electronic transmission over public networks; and again, we delete credit card information and all other personal information upon guest departure. We regularly test our systems and processes in an effort to protect customer information, and employ the services of industry-leading third-party firms to evaluate our safeguards.”
Obviously, the facts are still murky, but it will be interesting to see what, if any, protection PCI compliance will have from a liability perspective and a "safe harbor" perspective.

Monday, June 9, 2008

FACTA Development: The “Credit and Debit Card Receipt Clarification Act of 2007” Signed into Law.

The FACTA class action litigation saga has taken a new twist. Congress has passed and the President has signed the Credit and Debit Card Receipt Clarification Act of 2007 (the “Act”) into law. The Act will likely provide a large set of FACTA class action defendants with the ability to escape expensive litigation and liability.

As previously reported, plaintiffs have filed FACTA class action lawsuits based not on the printing of the payment card number on an electronically printed receipt, but simply based on the printing of the expiration date on a receipt (see for example the StubHub case referenced in this post). In fact, the relevant FACTA section establishes an “either/or” scenario:

Except as otherwise provided in this subsection, no person that accepts credit cards or debit cards for the transaction of business shall print more than the last 5 digits of the card number or the expiration date upon any receipt provided to the cardholder at the point of the sale or transaction.

15 U.S.C. 1681c(g) (emphasis supplied). If a plaintiff is able to establish a willful violation of FACTA, a court could award statutory damages ranging from $100 to $1,000 without the having to establish that he or she suffered actual harm.

Unfortunately dozens of companies that had made the effort to truncate the payment card numbers nonetheless were sued in FACTA class actions alleging a failure to remove the expiration date from payment card receipts (see e.g. Troy v. Home Run Inn, No. 07CV4331 (N.D. Ill 2008)); Cicilline v. Jewell Food Stores, No. 07CV2333 (N.D. Ill 2007)).

Congress passed the Act in light of these “expiration date only” FACTA lawsuits. The relevant part of the Act states:

(d) Clarification of Willful Noncompliance- For the purposes of this section, any person who printed an expiration date on any receipt provided to a consumer cardholder at a point of sale or transaction between December 4, 2004, and the date of the enactment of this subsection but otherwise complied with the requirements of section 605(g) for such receipt shall not be in willful noncompliance with section 605(g) by reason of printing such expiration date on the receipt.

(emphasis supplied). In essence this language appears to block plaintiffs from going after statutory damages under FACTA. Since those statutory damages are the only reason these cases are attractive to plaintiffs attorneys, it is likely that class actions on this basis will not be pursued.

Significantly, the Act applies retroactively: it would apply to FACTA lawsuits already filed on the basis of printing the expiration date on the receipt.

This is obviously good news for defendants. However, the way Congress went about this raises some questions. Rather than “clarifying” the law by stating that printing just the expiration date is not a violation of FACTA, Congress left the door open for plaintiffs that suffer “actual harm” based on the “non-willful” printing of the expiration date. Admittedly, few if any plaintiffs will be able to establish actual harm in this context.. However, there is a certain logic gap at play here.

Congress has said unequivocally, regardless of the actual facts of the case, that printing the expiration date shall not be “willful noncompliance.” What if, in an (extreme) hypothetical, a defendant wrote an email stating:

I, President of ABC company, understand that FACTA prohibits the printing of a credit card expiration date on the receipt, but for financial reasons I intend to not follow that legal requirement.
Based on the Act, there would still be no willful violation even though under this hypo there was one in laymen’s terms. Of course in “real life” this email likely does not exist, but there could be lesser evidence establishing “willfulness” that could be in play. In short, Congress took an awkward somewhat Alice-In-Wonderland approach to rectify the situation, and hopefully it does not give plaintiffs a hook to keep these cases in court (clearly more research would be needed as to how legislative intent is factored in these scenarios). Regardless, at the minimum, this gives the FACTA defendants great litigation leverage on this issue.

Another “Victory” on the Issue of “Damages” in a Security Breach Negligence Case

As has been reported on this blog previously (here and here), many courts that have considered the issue of damages in a security breach scenario involving personal information have concluded that taking pre-emptive actions (such as purchasing credit monitoring services) do not amount to “damages” for purposes of a negligence claim. some chinks, however, have begun to develop in the “damages” armor used by defendants in security breach negligence cases. A recent decision sets forth another possible theory of liability to get a plaintiff at least beyond a motion to dismiss.

In Ruiz v. Gap, 07-5739 (N.D. Cal. 2008), a class of plaintiffs sued the Gap alleging that their unencrypted personal information resided on one of two laptops stolen from one of the Gap’s vendor (the personal information of approximately 800,000 Gap job applicants was stored on the laptops). The Gap offered the plaintiffs 12 months of credit monitoring services and fraud assistance without charge, as well as access to $50,000 worth of identity theft insurance.

The Ruiz court analyzed the plaintiffs’ complaint to determine whether the plaintiff properly alleged an “injury in fact” for purposes of standing and the issue of damages with respect to the plaintiffs’ negligence claim. In particular, the court noted that the plaintiffs had merely alleged that they were at “an increased risk of identity theft” and did not allege that their identity had been stolen.

The court noted that the plaintiffs’ allegations seemed “conjectural or hypothetical, rather than actual or imminent,” and that there was nothing else to allow the court to determine that the risk was actual, imminent or credible. Nonetheless, the court presumed that the general allegations embraced the specific facts supporting them and denied the motion to dismiss. The court did, however, issue a warning to the plaintiffs indicating that if it became apparent that their allegation of injury was too speculative or hypothetical the plaintiffs’ case may be dismissed later in the proceeding. In addition, the court noted that the extent of recoverable damages was unclear even if the plaintiffs were to prevail on a negligence claim.

Unfortunately, as with other negligent security cases allowing plaintiffs to proceed past a motion to dismiss, the court did not provide a highly developed legal rationale to support its decision. In this case it appears that the court simply accepted on its face that the alleged “increased risk of identity theft” constituted an injury. It went further and allowed the negligence claim to proceed even though no specific facts were alleged supporting that the plaintiffs were at increased risk. For the time being at least, it appears to be another small chip off the damages security breach defense rationale.

Wednesday, April 16, 2008

"Damages" in a security breach case... er.. maybe kinda...

A recent opinion came out of the U.S. District Court for the District of Columbia that denies defendant's motion to dismiss a case against the Transportation Safety Administration arising out of the loss of hard drive containing the personal information of 100,000 TSA employees (including names, SSNs, DOBs, bank account numbers, etc.).

The plaintiff's alleged a violation of section 522a(3)(10) of the Privacy Act, which provides:
Each agency that maintains a system of records shall . . . establish appropriate administrative, technical, and physical safeguards to insure the security and confidentiality of records and to protect against any anticipated threats or hazards to their security or integrity which could result in substantial harm, embarrassment, inconvenience, or unfairness to any individual on whom information is maintained .
In various contexts, the defendants argued that the plaintiff's had not alleged actual damages, that damages should be construed as only encompassing "out-of-pocket" pecuniary loss, and that plaintiffs' concerns about harm were speculative and dependent on future events (e.g. criminal misuse of the plaintiff's personal information by third parties).

The court analyzed the following injury allegations by plaintiffs:
“embarrassment, inconvenience, mental distress, concern for identity theft, concern for damage to credit report, concern for damage to financial suitability requirements in employment, and future substantial financial harm, [and] mental distress due to the possibility of security breach at airports."
In rejecting the defendant's motion to dismiss on the issue of injury/harm/damages, the Court focused on the "embarrassment... mental distress.... and concern" allegations. It held that those emotional distress allegations were not speculative nor dependent on future events.

The court also noted that the plaintiffs conceded that they were not alleging "current, actual, financial loss" or seeking out-of-pocket expenses. The court cited a case interpreting the Privacy Act that held that actual damages were not limited to "pecuniary losses" and that actions under the Privacy Act could survive the motion to dismiss phase based on pain and suffering and non-pecuniary losses. In this case the allegation of emotional distress was sufficient to surviving a motion for summary judgment.

There are several issues to address in this case:

(1) First off, since the plaintiffs did not appear to allege "out-of-pocket" expenses related to the security breach, it does not appear that the logic of this case would apply to situations where a plaintiff incurs costs (e.g. credit monitoring) to head off potential future harm that could arise out of identity theft (e.g. bad credit, cleaning up credit reports, credit monitoring, etc.). Rather, this case focused on whether "emotional distress" or "concern" was itself actual damages or an adverse impact under the Privacy Act. So I am not sure it helps support the theory that out-of-pocket expenses post breach, pre-Identity Theft are actionable.

(2) This case arose in the context of the Privacy Act, and in particular an alleged violation of a section intended to prevent "substantial harm, embarrassment, inconvenience." Since the intended harm includes "intangibles" such as embarrassment and inconvenience it seems that emotional distress can easily fall into that type of "injury."

(3) Another contextual matter: the reason the plaintiffs have to establish actual damages is to satisfy a U.S. Supreme Court case that ruled that "actual damages" were necessary for a plaintiff to recover the $1,000 statutory penalty available under the Privacy Act. More research needs to be done to determine whether "damages" in a negligence context is the same as "actual damages" in the Privacy Act coverage.

(4) It seems to me the logic employed here was a little loose. Most of the "emotional distress" and "concern" clearly ties to what might happen to the plaintiffs' personal information (e.g. concern for identity theft, concerning for damage to credit report, concern for damage to employment suitability, etc.). I suppose its possible that somebody could suffer emotional distress simply knowing their information was breached. However, its how that information might be used in the future after the breach that is actually of concern. It seems to me without some alleged facts (e.g. evidence of visits to a psychiatrist, starting anti-anxiety medication, evidence of depression) that this is fairly weak tea. I suppose courts are more lenient at the motion to dismiss phase (all you need to do is state a claim) and are likely to be more demanding on the evidentiary front if/when a motion for summary judgment is filed.

(5) In my view, since the ruling was fairly conclusory and did not dive deep into the details concerning how to define "damages," I am not sure how persuasive this reasoning will be in other contexts.

Thursday, April 10, 2008

PCI: "Follow the Standards to the Letter"

An interesting quote from Bob Russo on how the PCI standard should be followed:

Bob Russo, the general manager for the PCI Security Standards, a group that devises data security measures for the five major credit card companies, said almost all data breaches are the fault of the merchant.

"Everybody that has been breached has been noncompliant with the standard," he said, noting that the circumstances of the Hannaford breach are still too murky for him to render a judgment about. "If you follow the standards to the letter, it puts enough of a hard shell around the data that it is hard to get to."

Full story here.

My question, what about all those emails from the PCI Council, the card brands, acquiring banks and payment processors that purport to resolve ambiguities and which may not be "to the letter" of the PCI Standard? And that question reveals the potential problem from a legal standpoint.

Thursday, April 3, 2008

More Evidence of Hannaford-like Exploits?

While I will have to defer to my tech/security-oriented friends, we have reports of exploits that may be similar to the one suffered in Hannaford: Vermont ski area reports Hannaford-like theft of payment card data.

This exploit may be more common than just Hannaford:

And Hannaford and Okemo may not be the only businesses disclosing breaches involving payment card data in transit between systems. According to McPherson, law enforcement authorities who are investigating the breach at Okemo told resort officials that they currently are looking into about 50 reported incidents of the same sort in the Northeast alone.


So what does this all mean? Do the controls required under the PCI Standard address this issue? What about encryption under 4.1 and the language concerning "networks that are easy and common for a hacker to exploit." In general, has the security community anticipated this sort of attack? Is it reasonably foreseeable that hackers would exploit the point-of-sale systems? Legally, is failure to address this type of exploit "unreasonable" for purposes of negligence claim?