Visa To Genesco: PCI Compliance? What PCI Compliance?

Written by Evan Schuman
May 31st, 2013

The predictable other shoe has dropped (please forgive that heel of a play on words) in the legal battle between apparel chain Genesco (NYSE: GCO) and Visa over PCI penalties, with Visa officially asking a federal judge to dismiss the retailer’s lawsuit. The $2.6 billion Genesco chain, which owns Journeys, Lids and Johnston & Murphy, had been breached in 2010 and later had to reimburse its acquiring bank for about $13 million in fines charged by Visa. It sued Visa—with its acquirer’s permission and blessing—saying that it hadn’t violated any PCI rules.

Visa has now reacted, arguing to a federal judge that Genesco’s complaint should be dismissed for three reasons. First, Visa said that Genesco cited the wrong California state law, one that cannot be used in cases where there is a contract dispute. Second, Genesco didn’t claim sufficient facts to make its case. The third Visa argument was that one claim—that Visa had made fraudulent statements—wasn’t valid as the statements didn’t influence “consumers or the public,” nor did even Genesco rely on them. (It’s an interesting defense: Our lies didn’t harm anyone because nobody ever believes us anyway. For the record, of course, Visa hasn’t conceded that it lied, arguing that the law in question only envisioned lies that deceived the public.)

The core of the claim from Genesco—which has more than 2,455 retail stores throughout the U.S., Canada, the United Kingdom and Ireland—was that it had not violated any PCI rules. On that point, Visa said nothing.

But when it came to making as many references as possible to the original breach, that Visa found time for. “Following a massive data compromise event at Genesco in which millions of cardholders’ account data were put at risk, Visa exercised its contractual rights with respect to Genesco’s acquiring banks to collect from these banks money designed to be a partial reimbursement for losses suffered by the banks that had issued the Visa cards that were put at risk by the deficiencies in Genesco’s data security system.”

Many of the details of this case revolve around the precise rules of PCI and the payment systems. Visa stresses that it would never fine a retailer and that it only fines the acquiring banks, knowing full well that the banks are going to pass along those fines. But the existence of the bank middleman was supposed to provide Visa legal protection. In this case, though, Genesco was using Fifth Third and Wells Fargo and Genesco had cut a very specific deal with Wells Fargo. The Wells Fargo deal had the bank signing over its right to sue Visa to Genesco.

Visa’s filing said the fine was literally not a punishment for Genesco for being non-compliant as much as it was a punishment for the acquiring banks for not making sure that Genesco was PCI-compliant. In effect, had the acquirers sued, Visa simply would have had to prove that the banks hadn’t tested and verified Genesco’s compliance vigorously enough. Whether or not the chain was actually non-compliant wouldn’t have mattered, as the obligation of the bank was supervision.

But given that Genesco has taken over the suing function, Visa may actually have to prove direct lack of PCI compliance. Hence, they really want to make this case go away.

That’s part of the PCI ambience. Many of the long list of guidelines are subjective and interpretable.


One Comment | Read Visa To Genesco: PCI Compliance? What PCI Compliance?

  1. Nathan Says:

    Presto, Orwellian non-compliance… I may have to borrow that concept from you in our next PCI/card brand rant. Nicely done, Evan.


StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.