Certegy Reaches Data Breach Settlement

Company Pays $850K For AG's Court Costs Florida's Attorney General Bill McCollum has reached a settlement with Certegy Check Services over a data breach that happened three years ago.

The settlement is over allegations the company didn't have adequate data security for consumer records. The St. Petersburg-based company experienced a massive data breach exposing personal data from about 5.9 million consumer files. Under the settlement, the company agrees to ensure that safeguards are in place to protect consumer data.

Certegy Check Services Inc., a related company, Fidelity National Card Services, and subsidiaries of Fidelity National Information Services Inc., reported in July 2007 that customer records were stolen by a former company employee. Certegy notified the attorney general and the Federal Trade Commission and consumers of the data thefts, and cooperated with the attorney general's investigation.

A former Certegy employee, William Gary Sullivan, was later convicted of fraud and is serving a 57-month sentence in federal prison. Certegy and Fidelity also cooperated with investigations into the dissemination of consumer data through data brokers and marketers.

As part of a class action settlement in U.S. District Court in Tampa, consumers were given the opportunity to elect credit monitoring for one year or bank account monitoring for two years and were able to seek reimbursement of certain out-of-pocket costs incurred or identity theft expenses. Consumers also were able to request credit monitoring at the company's expense immediately after the thefts were announced.

The settlement with the attorney general's office ensures that Certegy will maintain a comprehensive information-security program. This program will assess internal and external risks to consumers' personal information, implement safeguards to protect that consumer information, and will regularly monitor and test the effectiveness of those safeguards. Certegy and its related entities also agree to adhere to payment card industry data security standards as those standards continue to evolve.

As part of the settlement, Certegy is donating $125,000 to the attorney general's Seniors vs. Crime Program for educational, investigative and crime prevention programs for the benefit of senior citizens and the community and will pay $850,000 for the state's investigative costs and attorney's fees related to the case.

About the Author

Linda McGlasson

Linda McGlasson

Managing Editor

Linda McGlasson is a seasoned writer and editor with 20 years of experience in writing for corporations, business publications and newspapers. She has worked in the Financial Services industry for more than 12 years. Most recently Linda headed information security awareness and training and the Computer Incident Response Team for Securities Industry Automation Corporation (SIAC), a subsidiary of the NYSE Group (NYX). As part of her role she developed infosec policy, developed new awareness testing and led the company's incident response team. In the last two years she's been involved with the Financial Services Information Sharing Analysis Center (FS-ISAC), editing its quarterly member newsletter and identifying speakers for member meetings.

Around the Network

Our website uses cookies. Cookies enable us to provide the best experience possible and help us understand how visitors use our website. By browsing bankinfosecurity.com, you agree to our use of cookies.