SCARBOROUGH, Me. – As many as 58 credit unions throughout Maine–one of seven states hit by the data security breach at Hannaford Bros.– expected to reissue more than 150,000 Visa and MasterCard debit and credit cards to ensure against further risk to members, the Maine CU League said Friday.
That means the latest cards security breach could cost Maine credit unions upwards of $2 million to resolve, and countless millions for credit unions in the other affected states–Massachusetts, Vermont, New Hampshire, Connecticut, Rhode Island, New York and Florida–with little of it expected to be covered by insurance, according to observers.
Hannaford Bros. acknowledged Friday that the cause of the breach was malicious software–known as malware–installed in almost all of the company’s 271 store servers which allowed the hackers to access card numbers while transactions were being authorized. The malware was detected in the company’s stores in New England and New York and at its Sweetbay stores in Florida, the company said.
The determination was revealed in a letter from the company to the Massachusetts Attorney General explaining the breach.
The Hannaford breach has caused widespread concern in the industry because it appears to be the first time that customer data was stolen in transit, rather than from stored records.
The malware apparently began as a single message sent to one location then was sent to multiple locations.
The company disclosed that as many as 4.2 million customer accounts may have been compromised by one or more hackers who accessed the company’s database during the authorization process.
Hannaford said about 1,800 cases of fraudulent transactions have been detected so far, with unauthorized charges coming for as far afield as Brazil, Mexico, Italy and Bulgaria.
Three Maine credit unions have reported fraudulent transactions, so far.
Four separate suits have been filed by consumers against Hannaford Bros. asking for class action status.









