ARLINGTON, Va.—As data breaches continue—the latest possibly at Sally Beauty Supply and another at the Hard Rock Hotel and Casino in Las Vegas—NAFCU is again emphasizing the need for national data breach standards for retailers.
The Hard Rock Hotel and Casino recently alerted customers of a data breach involving customer credit and debit card data. According to a statement on the company's website, the data breach involves customer names, card numbers and CVV codes, but doesn't include PIN information. The hack was limited to card transactions between Sept. 3, 2014 and April 2, 2015 at restaurant, bar and retail locations at the Hard Rock Las Vegas property.
Also, for the second time in a year, Sally Beauty Holdings Inc. says it is investigating reports of unusual credit and debit card activity at some of its U.S. stores. KrebsOnSecurity reported hearing from multiple financial institutions about a pattern of fraudulent charges on cards that were all recently used at Sally Beauty locations in various states.
In a statement, the company said it is currently investigating reports of “unusual activity” involving payment cards used at some of its U.S. Sally Beauty stores.
“The latest data breaches, with a repeat offense at Sally’s Beauty stores, underscores the urgency with which Congress needs to act to pass legislation that would establish strong national data security standards for retailers such as the Data Security Act of 2015, which has bipartisan support in both the House and Senate,” said NAFCU President and CEO Dan Berger. “Cybercriminals continue to be left unchecked and prey on the vulnerabilities in retailers’ payments systems to capture consumers’ sensitive personal financial information. As long as there are no national data security standards for retailers, the safety of our entire payments system is at risk.”
Two data security bills were introduced in the House and the Senate last month.
H.R. 2205 was introduced by Reps. Randy Neugebauer (R-TX), and John Carney (D-DE). S. 961 was introduced by Sens. Tom Carper (D-DE) and Roy Blunt (R-MO), both members of the Senate Banking Committee.
The two bills, both titled the Data Security Act of 2015, would set national data security standards for merchants, outline a process for breach notifications and recognize financial institutions’ compliance with the Gramm-Leach-Bliley Act’s information security requirements.
