Critical ResourceVisa CEDP: Major Payments Disruption
Back to Glossary

Data Breach

An incident where sensitive cardholder data is accessed, stolen, or exposed by unauthorized parties, potentially compromising payment card information and leading to fraud, identity theft, regulatory penalties, and significant financial liability for affected merchants.

A data breach occurs when cybercriminals, unauthorized insiders, or security vulnerabilities allow access to protected payment card data stored or transmitted by merchants, processors, or other entities handling cardholder information. Breaches can result from various attack vectors including malware installed on point-of-sale systems, hacking of e-commerce platforms or payment gateways, phishing attacks compromising employee credentials, physical theft of devices containing cardholder data, insider threats from employees with system access, and vulnerabilities in third-party vendors or service providers.

The consequences of payment card data breaches are severe and multifaceted. Merchants face immediate costs including forensic investigation expenses (typically $50,000-$500,000+), notification requirements to affected customers and card brands, credit monitoring services for affected individuals, legal fees and potential lawsuits, and public relations and brand damage control. Card networks impose substantial fines and penalties, often including per-card compromise fees ($5-$100 per card depending on the breach scope and merchant's PCI compliance status), card reissuance costs charged back to the merchant, and non-compliance fees that can reach millions of dollars for large breaches. Merchants may also face increased processing rates, loss of card acceptance privileges, mandatory PCI compliance audits, and requirement to implement specific security measures as conditions of continued processing.

Preventing data breaches requires comprehensive security measures mandated by PCI DSS compliance including encryption of cardholder data in transit and at rest, network segmentation isolating cardholder data environments, regular security testing and vulnerability assessments, strong access controls and authentication requirements, and regular security training for employees. Merchants should never store full card numbers, CVV codes, or magnetic stripe data after authorization. Point-to-point encryption (P2PE) and tokenization technologies reduce breach risk by ensuring sensitive card data never reaches merchant systems in readable form. Despite best efforts, breaches still occur, so merchants should maintain cyber liability insurance covering breach response costs, regulatory penalties, and potential lawsuits. Cyber insurance policies typically cost 0.05-0.10% of annual revenue but can save businesses from bankruptcy in breach scenarios.

Related Content

Optimize Your Payment Processing

Let Verisave analyze your merchant statement to identify hidden fees and misconfigurations related to data breach.

Get a Free Audit

Related Terms