On Heartland V
Sorry, but I cannot resist – here comes “On Heartland V.” Why did I break my promise?
This is why:
Source: DatalossDB
And this is why: “Class Action Lawsuit on behalf of certain investor in Heartland Payment Systems over alleged violations of Federal Securities Laws” (here)
And this is why: “Visa withdraws Heartland PCI compliance” (here) And “a little bird” (tm) brought this missing piece of info: their merchants are contractually obligated to do business with a PCI-compliant processor (please confirm or deny this rumor, if you have more info)
Overall, in light of the above I now think that Heartland might well end up being “CardSystems 2.0” and actually die. That will make “security doesn’t really matter” crowd … well… not matter :-) At least for a while.
Case closed? Security breaches actually … gasp! … matter for business.
Possibly Related Posts:
Comments
Now - it's entirely possible that this is simply a case of hackers vs. white-hats and hackers win... that happens; but I want an investigation that is *public* to determine cause... and IF the cause is determined to be anything other than "they did the best they could, but still got nailed" then management, from the CISO up, goes to the Federal Pen.... period.
My guess is both will re-certify and get back in Visa's good graces soon. I also note that none of the other brands has taken any action. Therefore, I don't see any wholesale defection of merchants. Visa didn't go nuclear on them; they could have if the situation warranted, and it doesn't seem like it did.
Look at past breaches, the fines normally flow to the processor first and then the merchant. The question is who's in the front in the line of (legal) fire.