Feeds

Retailer challenges Visa penalty fees in data security dust-up

Claims it was charged despite 'no evidence' of breach

Secure remote control for conventional and virtual desktops

In a payment industry first, a sporting-goods retailer has filed a multimillion-dollar lawsuit against Visa, arguing that the penalties the credit card company charges its members for data security breaches are unfair.

As reported by Wired, retailer Genesco alleges that Visa seized some $13m in funds from its merchant bank accounts following an incident in which packet-sniffing software was discovered on its network, despite there being no evidence that any credit card data was stolen.

At the time of the security breach, which took place in 2010, Genesco said it believed the intrusion had been successfully contained, though it was still possible that "certain details" of payment cards might have been compromised.

But in court documents filed on March 7, Genesco's attorneys argued that although the company had been "the victim of a sophisticated cybercrime attack," Visa failed to prove that any accounts had actually been breached – and that in fact, in many instances the forensic evidence proved that specific data was not leaked.

Nonetheless, the suit alleges, Visa concluded that Genesco had experienced a "data compromise event" and an "account compromise event" as defined by the Payment Card Industry Data Security Standards (PCI DSS), and proceeded to charge the company's banks non-compliance fines and fees to cover fraud-recovery expenses.

All told, Visa collected $13,298,900.16 in the incident, the court documents show – and all of that ultimately came out of Genesco's pocket, because its contracts with its banks indemnified the banks against any Visa fees or penalties.

Genesco now alleges that Visa's imposition of the fines was a breach of contract under the Visa International Operating Regulations, and it wants all $13m back.

The company also claims that Visa knew there was no basis for the fines, and that its actions amounted to "unlawful, unfair or fraudulent business practices" under the California Unfair Business Practices Act, for which it says additional damages should be determined at trial.

Tennessee-based Genesco is the parent company of a variety of footwear and sports-apparel store chains, including Journeys, Lids, Schuh, and Johnston & Murphy, among others, which together operate some 2,440 retail stores across Canada, the UK, Ireland, and many US states – including California, where Visa is headquartered.

This is the first time a retailer has filed suit against a credit card company over PCI DSS fines related to a data security breach. As Wired points out, a restaurant and nightclub disputed similar fees in one earlier case, but in that incident the suit was brought against the banks that collected the fees, rather than the credit card company that imposed them.

According to Genesco, however, it is Visa that is clearly in the wrong in its case, and that to allow Visa to keep the $13m it collected from Genesco would be "against principles of right, justice, and morality" – strong words, indeed.

If the court finds in Genesco's favor, it could potentially set legal precedent that changes the ways in which credit card companies are allowed to levy fees for PCI DSS violations.

Visa has issued no statement on the matter. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
'Cowardly, venomous trolls' threatened with TWO-YEAR sentences for menacing posts
UK government: 'Taking a stand against a baying cyber-mob'
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Don't bother telling people if you lose their data, say Euro bods
You read that right – with the proviso that it's encrypted
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.