Data Breach Overview Mike Schenk, VP Research and Policy Analysis Credit Union National Association
MERCHANT DATA BREACHES Merchants do not follow strong data security requirements like credit unions Financial institutions, including credit unions, are subject to strict data security standards under the Graham-Leach-Bliley Act (GLBA). Retailers are not. All who hold personal data should be subject to strong federal security requirements. Congress should pass legislation that would impose data security standards on merchants to protect consumers and reduce criminal access to financial information. Nearly 60% of consumers expect to be a victim of data breach at some point
AMERICAN CONSUMERS NEED PROTECTION STRONG NATIONAL DATA PROTECTION STRONG NATIONAL DATA PROTECTION and consumer notification standards with effective enforcement provisions are needed to ensure sensitive data is protected. RECOGNITION OF ROBUST PROTECTION and notification standards that credit unions and banks are already subject to. PREEMPTION OF INCONSISTENT STATE LAWS and regulations in favor of strong federal data protection and notification standards. ABILITY OF CREDIT UNIONS AND BANKS TO INFORM members and customers about a breach, including where it occurred. SHARED RESPONSIBILITY for all those involved in the payments system for protecting consumer data. The costs of a data breach should ultimately be borne by the entity that incurs the breach.
Data exposed in 2017 breaches: 53% exposed SSNs 19% exposed Debit card/Credit card 37% exposed unknown records
CREDIT UNIONS HIT HARD: TWO EXAMPLES Target Data Breach 12/19/13: Target data breach announced (~41 million cardholders) CUNA survey: 1,112 responding credit unions by 2/5/14 Estimated 5.4 million CU debit and credit cards affected $30.6 million total costs in first 2.5 months Primarily card reissuance & administrative expenses Call volumes up by 25%+ at 37% of credit unions Nearly 40% report increasing staffing as a result Excludes any fraud losses after initial 2/5/14 Home Depot Data Breach 9/18/14: Home Depot data breach announced (~50 million cardholders) CUNA survey: 544 responding credit unions by 10/29/14 Estimated 7.2 million CU debit and credit cards affected $57.4 million total costs in first 1.5 months Primarily fraud and card reissuance expenses Call volumes up by 25%+ at 21% of credit unions Excludes any fraud losses after initial 10/29/14