advertisement
advertisement

This is page 2 of:

Heartland Lawsuit Dismissed, “Insufficient Evidence” Of Weak Security

December 10th, 2009

But Thompson reviewed the full audio of that conference call and sided with Heartland. “Careful attention to context demonstrates that Defendants’ statements and omissions on this conference call are not fraudulent. The analysts’ questions concerned certain expenditures that Heartland made during the fourth quarter of 2007. Obviously, any incident that prompted those expenditures would have occurred before the expenditures were made. The SQL attack occurred on December 26, far too late in the quarter to have been the cause for the million-plus dollar expenditure that was the subject of the analysts’ questions,” she said in her decision. “If the analysts had simply asked ‘Did you suffer a security lapse in fourth quarter 2007?’ then Defendants’ answers might very well have been misleading. But the analyst was specifically asking whether Heartland suffered a security incident that caused the large fourth quarter IT expenditure. Since the SQL attack did not cause the fourth quarter security expenditure, Defendants answered truthfully when they answered in the negative.”

Thompson also discussed another exchange on that call, one where the CFO compared Heartland to the infamous TJX data breach. “Plaintiffs allege that Defendant Baldwin made one other misrepresentation on the February 13 conference call—the following statement: ‘With IT security, you’re either pregnant or you’re not. And I think it would be irresponsible for us to know that we have vulnerabilities in our system where we could have something really bad happen that would put the Company in a TJ Maxx position. Now, fortunately, we’ve never had anything close to that happen, but we could see a scenario where that could have happened. We don’t see that anymore.'”

The judge said that the plaintiff “argues that this statement is untrue because Heartland had in fact suffered a significant security breach—the SQL attack. However, this Court does not read the above paragraph as concealing that fact. A ‘TJ Maxx position’ presumably refers to an incident in 2005 when hackers breached the (TJX) computer network and gained information on 45 million credit and debit card accounts. As of February 2008, hackers had not stolen any credit card information from Heartland. So at the time the above statement was made, Heartland had not suffered the sort of security problem to which Baldwin was alluding. In other words, in the above-quoted passage, Baldwin was talking about security breaches that resulted in major financial problems. There are no allegations to the effect that, as of February 2008, Heartland had suffered any major headline-making problems of the sort T.J. Maxx experienced in 2005. Furthermore, Baldwin did not categorically assert that Heartland had never suffered any security problems. He merely stated that Heartland had not suffered anything ‘close to’ what (TJX) had suffered. His statement was therefore truthful.”


advertisement

5 Comments | Read Heartland Lawsuit Dismissed, “Insufficient Evidence” Of Weak Security

  1. Anthony M. Freed Says:

    As far as I know, the SEC investigation is still underway, and an indictment would certainly see this lawsuit revisited, perhaps in another jurisdiction – either where a plaintiff resides, where a data center is located, or Cal-litigate-afornia, where it fairly easy to sue anyone.

    The judge’s opinion was strong regarding the likelihood that Carr and Baldwin will be sanctioned for misleading statements to investors, but it certainly did not dismiss the notion that material adverse information was deliberately withheld from investors between December of 2007 and January of 2009.

    The dismissal also does little to undermine charges of possible insider trading by HPS executives, the crux of the SEC investigation.

    And let us not forget that more financial impact form the breach cleanup is to be expected, which already had Heartland backpedaling on their last quarterly earnings statement to the tune of nearly $80M.

    The ruling was definitely a victory for Heartland, but potential liabilities still threaten the company’s viability, with a their market cap at about $430m.

    If Heartland’s liabilities begin to approach the $200m to $250m range, Heartland could likely file for BK. We certainly have not heard the last of this breach.

  2. Evan Schuman Says:

    Anthony is clearly correct that anyone can sue anyone for anything in this country and the SEC can probe almost anything it wants. But whether or not you happen to agree with the federal judge’s decision in this case, her decision was clearly articulate. In other words, she laid out her thinking and evidence for all to see, so observers can judge for themselves whether the ruling has merit.
    But I do take slight exception to Anthony’s comment that the judge’s ruling “certainly did not dismiss the notion that material adverse information was deliberately withheld from investors between December of 2007 and January of 2009.” Actually, it did indeed dismiss that. That was the basis of her ruling, that she saw no material information deliberately withheld from anybody. You can certainly disagree with her conclusion but you can’t say that she didn’t dismiss that scenario. She clearly did.

  3. Anthony M. Freed Says:

    Very true – and I should clarify by saying that given the outcome of the SEC investigation, Heartland executives could very well face a charge of withholding material information both criminally and in civil litigation.

    The judges decision is not based on all the facts and information that may be available after the SEC weighs in, but is based on the facts and arguments presented in the plaintiffs complaint, which was dismissed.

    And a dismissal is not an acquittal. It does not necessarily reflect on the validity of the allegations per se, as much as it is a ruling on the validity of the complaint as filed.

    I would not rule anything out yet.

  4. Evan Schuman Says:

    It’s absolutely fair to say that an SEC probe could easily be aware of things that the a civil lawsuit judge may not.
    But, to be fair, a dismissal in a federal civil lawsuit is more significant than you’re suggesting. It either indicates a lack of validity to the complaint or VERY bad counsel filing that complaint. The threshold to have a civil lawsuit proceed to trial is quite low in the U.S., and I’ve covered enough ludicrous civil trials to know that all too well.
    For a judge–especially a federal judge–to dismiss a lawsuit, the judge pretty much has to conclude that the accusations and support points made are absolutely without merit. In this instance, the complaint didn’t even support its own accusations. It’s not like the plaintiffs accused Heartland of XXXX and Heartland disputed it with documents or a witness. The judge looked at the plaintiff’s own claims and concluded that they weren’t making a good enough case to even go to trial.
    Again, Anthony, I’m agreeing with you that an SEC probe could go in a different direction, but let’s not make light of a federal judge ordering a complete dismissal with prejudice. That’s not something that happens every day.

  5. Anthony M. Freed Says:

    Agreed!

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.