Show me the money

If you noticed something big missing from last week's settlement between breach extraordinaire TJX and the Federal Trade Commission - that being dollar signs - you weren't alone.

But before you go criticizing the FTC for going soft on a retailer that exposed some 45 million credit card numbers - or double that if you go by court filings - keep this factual tidbit in mind: The agency isn't allowed to impose fines.

The rule has been a thorn in the FTC's side for years, especially as it goes after more and more companies with lax data security practices in place.

Right now, the FTC can force companies to fork up ill-gotten gains and force them to pay for customer redress. That may work fine for spam and spyware purveyors who make a pretty good chunk of change preying on innocent web users, but the agency typically can't apply that to legitimate companies such as TJX.

The FTC is lobbying Congress for additional power. In the meantime, the fines for breaches will come from the credit card brands (for violating Payment Card Industry standards) and countless lawsuits.

Although one must wonder how much fining power Visa and MasterCard can have if the merchant was PCI-compliant, as was the case with the recent Hannaford Bros. breach, at the time of the data loss.
close

Next Article in The News Team Blog

Sign up for our newsletters

POLL

More in The News Team Blog

Here are eight cyber crooks who got less prison time than Andrew Auernheimer

Here are eight cyber crooks who got less ...

The security researcher and self-proclaimed internet troll earned 41 months behind bars Monday for his role in using a script to retrieve data on roughly 120,000 Apple iPad users from ...

The White House thinks Julian Assange and Jeremy Hammond are no different ...

Whistleblowing organizations like WikiLeaks and accused hacktivists like Hammond are not foreign spies lusting to plunder intellectual property from U.S. corporations and government agencies in order to profit and gain a competitive advantage.

Obama would prefer to prosecute leakers than discuss Stuxnet

The FBI and DoJ are targeting high-level U.S. officials in hopes of learning who released classified information about Stuxnet to the press. What the government is not doing is publicly explaining why it launched Stuxnet.