Courts and data breach fines: We’re talking real money now
June 8, 2010 by Sam NarisiPosted in: Security, Special Report

If you need one more reason for instituting an improved data security system, the chance of serious liability (we’re talking over $100 million) has just gotten more real.
Federal courts are getting far more aggressive in penalizing companies that fail to protect confidential client data. That’s the case with a recent court settlement of a class action suit brought for data breaches at a company called Heartland Payment Systems.
Heartland is one of the biggest processors of credit and debit card transactions in the country. In 2009, it revealed that hackers had managed to break into its systems and stole critical information on as many as 130 million customer credit and debt card accounts. The breach, orchestrated by an organized gang of US-based cyberthieves, was the largest of its kind and resulted in a flurry of false charges made on consumer card accounts.
Many of the members of the gang were caught, tried and sentenced, but the affected customers and their banks joined in a large class action suit for the costs and inconvenience of sorting out the false charges. The settlement of the suit required Heartland to pay:
- $60 million to reimburse banks issuing Visa cards for costs related to the breach
- $41 million for settling with MasterCard-issuing banks
- $3.6 million just to settle claims from American Express, and
- $4 million to settle consumer claims.
The agreement may be indicating a new era of liability for data breaches. According to a BusinessWeek story about the settlement:
“Typically, courts have tended to dismiss consumer class action lawsuits in data breach cases involving payment card data. By that measure, Heartland’s settlement offer is unusual even though it might appear small considering the number of cards that were compromised.”
DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.
Click here to sign up and start your FREE subscription to DocuCrunch!
Tags: data breach, Heartland Payment Systems, lawsuit, settlement
