WASHINGTON -
Rep. Barney Frank, the new chairman of the House Financial Services Committee, told attendees to CUNA's GAC he has been pursuaded to act by CUs in Massachusetts, particularly Brockton's HarborOne CU, which is paying hundreds of thousands of dollars to reissue cards, even with little or no fraud reported on them. The $1.4-billion CU has paid hundreds of thousands of dollars in uninsured costs to reissue cards 12 times in 2004, 35 times in 2005, and 44 times again in 2006, and has already reissued more than 100,000 cards to protect against the latest data breach at TJ Maxx.
HarborOne CEO Jim Blake, who is also chairman of the Massachusetts CU League, has written TJ Maxx, which is based in the nearby Boston suburb of Framingham, to pay the costs to replace his members' cards. With dozens of institutions around the country replacing their cards, the costs will run into the millions. Dan Egan, president of the Massachusetts League, said they are still considering litigation to recover CU costs from TX Maxx.
CUs in that area were facing a new data breach last week when Stop & Shop, New England's largest supermarket chain, said point-of-sale machines in at least six of its Rhode Island and Massachusetts stores had been tampered with, enabling crooks to steal credit and debit card numbers and PINs. Four suspects were arrested at one of the chain's 385 supermarkets last week, allegedly rigging a POS machine. Police said the crooks worked in teams, with one diverting the store attendant, while his accomplices quickly removed the POS keypad and replaced it with a skimmer that would record cards information. Later, the gang would replace the old keypad in the same way.
Local credit unions and banks were tallying the damages last week. At least two credit unions reported fraud, with Coventry CU reporting $10,000 in losses. Citizens Bank reported $100,000 in fraud on its cards. In all, at least 1,100 victims were reported.
Frank said last week his committee is drafting a bill that will protect credit unions and banks by requiring responsible parties, like a Stop & Shop or TJ Maxx, to pay for reissuing of cards, communicating with members and other costs for such data breaches. "The entity that caused the breach is the entity that bears responsibility," said Frank, who said he was impressed by his discussions with the Brockton credit union.
The nation's merchants object to this approach because they believe companies will end up litigating with each other and the credit unions and banks over who is responsible for the breach.
Credit unions are generally insured for card fraud, but not for the much more expensive process of containing a fraud by shutting down accounts. Credit unions made $100 million in cards fraud claims last year, according to CUNA Mutual Group. They are believed to have spent even more in reissuing cards and trying to limit the damage of each incident.
In one case alone, the breach at BJ Wholesale three years ago, credit union costs rose above $10 million. CUNA Mutual and more than 100 credit unions are still in litigation over that case.
Credit unions are also keying on other potential parts of a data security bill. CUNA Mutual, which insures the vast majority of credit union cards programs, wants to see Congress mandate Visa and MasterCard's PCI rules, the Payment Card Industry standards that bar retention of a customer's account information. Larry Blanchard, chief lobbyist for CUNA Mutual, says they believe the theft of data is proliferating because the majority of merchants do not destroy the consumer records, making the data readily available to crooks. Visa and MasterCard, which have acknowledged this, have both become more vigilant in enforcing the PCI rules, even raising fines for non-compliance. CUNA Mutual wants the PCI rules, which also require encryption of data and regular security audits, to become law.
The merchants fear this would prevent them from mining that customer data for marketing and sales purposes.
Congressional lobbyists expect a major fight over data security, as they did in the last Congress, given their opposition. Some see the best strategy as allowing the merchants to include provisions in a data security bill that would, in some way, restrict interchange fees, a rapidly rising cost for all businesses. The credit union lobby is against this because it would further complicate the issue.
Even without that complication, the issue will have rough sledding in this Congress, with as many as six congressional committees introducing its own version of a bill.









