Banks Scramble in Wake of Heartland Breach

Several have begun reporting fraud associated with exposed cards

In the first real indication of the scope of the recently disclosed breach at Heartland Payment Systems, banks and credit unions from Washington to Maine have begun to reissue thousands of credit and debit cards over the past few days.

Several have also begun disclosing fraud associated with payments cards that were reported to them by Visa and MasterCard as having been exposed in the breach.

A Pennsylvania law firm today filed the first class action lawsuit related to the breach. The lawsuit was filed by Chimicles & Tikellis LLP of Haverford, PA on behalf of Alicia Cooper, a resident of Woodbury, MN, and others who might have been affected by the breach.

The complaint, filed in the U.S. District Court for the District of New Jersey in Trenton, alleges that Cooper, whose card was compromised in the breach, and others, were victims of Heartland's negligence in protecting card-holder data. The lawsuit, which calls for a jury trial, charged Heartland with breach of contract, breach of implied contract and breach of fiduciary contract for the breach.

The compromise has pushed the Washington Credit Union League in Federal Way to revive legislation that would mandate specific data protection controls on all merchants and third-parties such as Heartland that process payment card data. The bill (HB 1149) received its first hearing last Thursday in the Washington House Financial Institutions and Insurance Committee, according to a statement released by the association.

Heartland, a Princeton, NJ-based processor of payment card transactions disclosed last Tuesday that its systems had been broken into by unknown intruders sometime last year. The company claimed that the intrusion -- which some are calling the biggest ever -- was discovered only earlier this month following a forensic investigation that began last year when Visa and MasterCard first alerted it of suspicious transaction activity.

The company said that intruders planted sophisticated sniffer software in its network and stolen data as cards were being processed.

Heartland has not yet released any information on the number of cards exposed in the intrusion. But the fact that the company processes more than 100 million transactions per month for over 250,000 customers has sparked speculation that the breach might be even bigger than the one disclosed by TJX Companies Inc. in which more than 45 million payment cards were compromised.

Since its disclosure, a growing number of financial institutions across the country have begun notifying their customers of their cards being potentially compromised as a result of the breach. In most cases, the compromises resultin the cards being blocked and recalled by the financial institutions. A small sample of those making such announcements included the following:

  • Boston-based Sovereign Bank has posted a notice on its Web site alerting account holders of the breach and informing them that the bank's cards had been affected by it as well. The bank said it was still determining the number of compromised cards.
  • The Platte Valley Bank of Scottsbluff, NE issued an alert saying that 433 of its debit and credit card customers had been affected by the breach. The statement stressed that the bank's own systems had not been hacked into, and called out that the compromise was the result of the intrusion at Heartland. First State Bank also of Scottsbluff, NE said 200 of its customers had been impacted. "This could possibly be a bigger breach than TJ Maxx and has affected customers of every bank in the area," the alert noted.
  • The Association of Vermont Credit Unions said that as of last Friday the breach had affected about 6,000 ATM check cards and thousands of credit cards at credit unions across the state. In a statement the association said it had learned of the breach on Friday January 9 or more than 10 days before it was disclosed by Heartland.
  • Jenny Reynolds, vice president of marketing at CU Community Credit Union in Springfield, Mo. said that so far the breach has resulted in about 16 compromised cards belonging to the credit union being used to commit about $11,000 worth of fraudulent transactions. In total the credit union has ended up blocking 350 Visa cards after the breach disclosure Reynolds said. The fraud itself occurred last November even before the breach was disclosed by Heartland, she said. Many of the fraudulent transactions involved purchases at gas stations and small merchandize, she said. "I haven't spoken to one financial institution that hasn't been affected by the breach," she said.
  • The Washington Credit Union League noted that some the state's financial institutions have reported that more than half of their card base as being affected by the breach, Most credit union leaders believe that the effect during the initial days is just the "tip of the iceberg," the association warned.
  • Representatives from the Maine Credit Union League, the California Credit Union League and the Massachusetts Bankers Association told Computerworld they reported their members as having been affected by the breach, though all said it was still too soon to determine the full scope of the compromise.
  • Meanwhile, CUNA Mutual Group, a firm that insures credit unions, said its risk management analysts had noticed an unsual increase in fraudulent payment card activity as early as October last year and had forwarded the information to MasterCard and Visa.
  • On Jan. 21 CUNA sent out an alert to more than 5000 credit unions nationwide on January 21 offering recommendations for credit unions to mitigate losses from the breach. The alert quoted CUNA Mutual product executive Chuck Cashman as saying that while the exact number of affected cards was not known, it was expected to be "many millions."
  • FREE Download: Get the Spring 2019 digital issue of CSO magazine today!