ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Community Banking

Banks Turn to the Courts for Data Breach Claims

September 13, 2018
Reading Time: 3 mins read

By Dawn Causey, Thomas Pinder and Andrew Doersam

Banks frequently absorb fraud losses when the consumer is compensated for damage done by other sectors. When retailers with questionable security protocols are breached, banks support the customer throughout the fraud cycle: consumer outreach and notification, card reissuance, enhanced transaction monitoring and reassurance that the bank’s systems are safe.

The payment brands provide processes for banks to recover some costs and to assign liability for transaction losses—and the EMV chip card transition both created liability incentives for retailers to accept payment credentials which are less susceptible to fraud and introduced technologies to drive down the frequency of card reissuances.

But as data breaches have continued to become more pervasive, some financial institutions are now suing merchants to recover additional data breach costs which may fall outside of those covered in contracts with payment brands. A recent Seventh Circuit decision provides a glimpse into how courts analyze liability for data breaches when there are established contracts governing data security.

In 2012, hackers infiltrated Schnucks, a large Midwestern grocery chain, and stole nearly 2.5 million credit and debit card numbers in a breach believed to have continued for four months before Schnucks detected the intrusion. Once Schnucks recognized that its systems had been compromised by hackers, the grocer took another two weeks before announcing the breach publicly. Financial losses from the unauthorized purchases and cash withdrawals made using the stolen data reached into the millions.

In response, banks issued new cards and promptly reimbursed their customers and sought compensation available under contractual frameworks in place at the time of the breach. Four banks filed a claim against the merchants, seeking to recover the data breach costs that were not reimbursed by their payment brand contracts. The banks invoked several common law tort theories seeking compensation from the grocer and sought damages for losses incurred because Schnucks negligently failed to detect the breach until several months after the initial intrusion.

The Seventh Circuit dismissed the banks’ claims, holding that the banks’ remedies were confined to the provisos of their card brand contracts and, as a result, they could not use alternative litigation to recover additional costs. The court concluded the banks and Schnucks participate in a complicated network of contracts that unite all the participants in the card payment system. When banks and merchants joined the card payment system, they agreed to abide by the payment card industry data security standard, or PCI DSS. Merchants such as Schnucks agreed to pay a fine assessed under payment brand rules in the event that they (the merchants) were responsible for data breaches and unauthorized card activity. The court decided that the banks accepted the risk of not being fully reimbursed for the costs of Schnucks’ mistake, and as a result, cannot seek additional recovery because the banks were “disappointed” with their reimbursement.

The court also reiterated that state courts generally decline to impart tort liability in instances where one business inflicts purely economic loss on another and their interactions are governed by contract. Additionally, the court dismissed the banks’ consumer protection claims, concluding that the banks’ charge that Schnucks failed to implement and maintain reasonable payment card data security measures was not enough to prove fraud by the merchant. Finally, the court rejected the banks’ unjust enrichment, implied contract and third-party beneficiary claims under contract law principles and state laws in Missouri and Illinois.

The court recognized that the electronic card payment processing system is a complex network of contracts between various parties. Although the banks did not contract directly with Schnucks, the court found the card network contract sufficiently demonstrated that the parties had taken adequate steps to allocate the economic risks of a data breach.

In the absence of demonstrated retailer commitment to implement PCI DSS compliant safeguards, banks may continue to turn to the courts while also supporting federal data breach legislation that extends Gramm-Leach-Bliley Act-like requirements to other sectors and creates a legal framework for financial accountability. Even though banks incur obvious costs on the back end of data breaches, the Schnucks decision suggests that banks should not expect relief from the courts when faced with losses caused by retailer negligence.

Dawn Causey is general counsel at ABA, where Thomas Pidner is SVP for litigation and Andrew Doersam is a paralegal.

Tags: Credit cardsData breachesDebit cardsPayments system
ShareTweetPin

Related Posts

OCC sees need for regulatory reform in bank merger process

Bank acquisitions announced in Oklahoma, Wisconsin

Community Banking
November 18, 2025

BancFirst in Oklahoma City to buy American Bank of Oklahoma; Jewel Box Financial Services to buy Ambanc Financial Services in Wisconsin.

Report: Republicans push back against proposed cuts to CDFI Fund

Trump administration rescinds CDFI Fund staff layoffs

Community Banking
November 18, 2025

The Trump administration has rescinded reduction-in-force notices sent to the employees of the CDFI Fund during the government shutdown.

Fed, FDIC withdraw statements on managing risks for crypto

OCC allows banks to hold crypto to cover related fees

Newsbytes
November 18, 2025

The OCC issued an interpretive letter stating that national banks are permitted to hold small amounts of crypto assets, as principal, to pay fees used to cover transaction costs on cryptocurrency networks.

FDIC proposes tying agency regulatory thresholds to inflation

CSBS: Data show regulatory burden falls hardest on community banks

Community Banking
November 17, 2025

Ten years of survey data from banks show that the cost of regulatory compliance eats up a larger percentage of resources for smaller community banks than it does for larger banks, according to a recent report by the...

Bank marketers double down on AI

Agentic commerce and the new checkout imperative for banks

Technology
November 17, 2025

AI agents, real-time rails and customer trust are redefining the retail experience.

Basel Committee: Permissionless blockchains pose ‘novel’ risk challenges for banks

FDIC considering tokenized deposit insurance guidance, stablecoin issuer rules

Newsbytes
November 14, 2025

The FDIC is considering guidance on tokenized deposit insurance for banks that want to explore the option, and the agency plans to issue a proposal later this year to establish an application process for stablecoin issuers, FDIC Acting...

NEWSBYTES

FOMC minutes show division over December rate cut

November 19, 2025

Fed’s Miran warns against overregulation of the banking industry

November 19, 2025

Senate Banking Committee advances Hill nomination to be FDIC chair

November 19, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The Erie Canal at 200

November 6, 2025

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.