
Following record breaking card scandal
By Joris Evers
Published: 28 September 2005 08:10 BST
A judge has asked MasterCard and Visa to disclose details about their relationship with CardSystems Solutions, the payment processor that was the subject of a high-profile data security breach.
The information, such as contracts between the companies, should help determine whether the credit card companies have responsibility under California law to notify consumers whose personal details were exposed in the CardSystems breach, San Francisco Superior Court Judge Richard Kramer said on Tuesday during a court hearing.
CardSystems, MasterCard, Merrick Bank and Visa were sued in June on behalf of California credit card holders and card-accepting merchants. The suit seeks to test a state law that requires consumer notification after personal information stored on computers is lost, stolen or breached.
On Friday, Kramer denied a request for a preliminary injunction that would have required the credit card companies to tell individual California credit card holders that their account information was exposed in the CardSystems breach.
The digital break-in at CardSystems was publicly disclosed by MasterCard on 17 June. Intruders got access to details on about 40 million credit cards. Records of more than 200,000 cards are thought to have been transferred out of CardSystems' network. MasterCard and Visa maintain that notification responsibility falls with the banks that issue credit cards because they have direct relationships with the affected customers.
Kramer said he wants to be clear on which defendants fall under California civil code section 1798.82, the notification statute. While it is clear that the breach was at CardSystems, the law applies to entities that "own or license" personal information about Californians. Plaintiffs in the case say that includes MasterCard, Merrick and Visa.
Kramer said: "I believe we have to figure out whether indeed Visa, MasterCard and Merrick are covered by the statute. They don't seem to own the data but the plaintiffs' view is that they are operating with a licence." He ordered all parties to prepare for a trial on that matter and to exchange information.
Plaintiff attorney Ira Rothken said he was pleased with the outcome of Tuesday's hearing. "We're going to get to do some discovery and tee up the most important question in this case," he said. Rothken believes all defendants fall under the California law. "We believe they are all intimately intertwined," he said.
MasterCard, Merrick and Visa have argued that the statute does not apply to them.
Another hearing in the case has been scheduled for 24 October.
Joris Evers writes for CNET News.com
MasterCard launches pay-as-you-go plastic
One million HSBC customers getting contactless cards
MasterCard data breach: Lawsuit demands damages
Customer churn threat to data-clumsy banks
MasterCard scandal: More details emerge
Will MasterCard breach breed new wave of phishing?
MasterCard scandal: Worst data theft ever?
Experience of the processes required to implement software solutions in a consumer finance (credit card; loans; store card; mortgage) environment. A ...
To be considered for this role you must have: - Knowledge in business change, the credit card business & ideally wider retail banking environment - ...
This will require ensuring security reminders are put in unit communications, security awareness sessions are presented to communication events on a ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...