ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Community Banking

Banks Turn to the Courts for Data Breach Claims

September 13, 2018
Reading Time: 3 mins read

By Dawn Causey, Thomas Pinder and Andrew Doersam

Banks frequently absorb fraud losses when the consumer is compensated for damage done by other sectors. When retailers with questionable security protocols are breached, banks support the customer throughout the fraud cycle: consumer outreach and notification, card reissuance, enhanced transaction monitoring and reassurance that the bank’s systems are safe.

The payment brands provide processes for banks to recover some costs and to assign liability for transaction losses—and the EMV chip card transition both created liability incentives for retailers to accept payment credentials which are less susceptible to fraud and introduced technologies to drive down the frequency of card reissuances.

But as data breaches have continued to become more pervasive, some financial institutions are now suing merchants to recover additional data breach costs which may fall outside of those covered in contracts with payment brands. A recent Seventh Circuit decision provides a glimpse into how courts analyze liability for data breaches when there are established contracts governing data security.

In 2012, hackers infiltrated Schnucks, a large Midwestern grocery chain, and stole nearly 2.5 million credit and debit card numbers in a breach believed to have continued for four months before Schnucks detected the intrusion. Once Schnucks recognized that its systems had been compromised by hackers, the grocer took another two weeks before announcing the breach publicly. Financial losses from the unauthorized purchases and cash withdrawals made using the stolen data reached into the millions.

In response, banks issued new cards and promptly reimbursed their customers and sought compensation available under contractual frameworks in place at the time of the breach. Four banks filed a claim against the merchants, seeking to recover the data breach costs that were not reimbursed by their payment brand contracts. The banks invoked several common law tort theories seeking compensation from the grocer and sought damages for losses incurred because Schnucks negligently failed to detect the breach until several months after the initial intrusion.

The Seventh Circuit dismissed the banks’ claims, holding that the banks’ remedies were confined to the provisos of their card brand contracts and, as a result, they could not use alternative litigation to recover additional costs. The court concluded the banks and Schnucks participate in a complicated network of contracts that unite all the participants in the card payment system. When banks and merchants joined the card payment system, they agreed to abide by the payment card industry data security standard, or PCI DSS. Merchants such as Schnucks agreed to pay a fine assessed under payment brand rules in the event that they (the merchants) were responsible for data breaches and unauthorized card activity. The court decided that the banks accepted the risk of not being fully reimbursed for the costs of Schnucks’ mistake, and as a result, cannot seek additional recovery because the banks were “disappointed” with their reimbursement.

The court also reiterated that state courts generally decline to impart tort liability in instances where one business inflicts purely economic loss on another and their interactions are governed by contract. Additionally, the court dismissed the banks’ consumer protection claims, concluding that the banks’ charge that Schnucks failed to implement and maintain reasonable payment card data security measures was not enough to prove fraud by the merchant. Finally, the court rejected the banks’ unjust enrichment, implied contract and third-party beneficiary claims under contract law principles and state laws in Missouri and Illinois.

The court recognized that the electronic card payment processing system is a complex network of contracts between various parties. Although the banks did not contract directly with Schnucks, the court found the card network contract sufficiently demonstrated that the parties had taken adequate steps to allocate the economic risks of a data breach.

In the absence of demonstrated retailer commitment to implement PCI DSS compliant safeguards, banks may continue to turn to the courts while also supporting federal data breach legislation that extends Gramm-Leach-Bliley Act-like requirements to other sectors and creates a legal framework for financial accountability. Even though banks incur obvious costs on the back end of data breaches, the Schnucks decision suggests that banks should not expect relief from the courts when faced with losses caused by retailer negligence.

Dawn Causey is general counsel at ABA, where Thomas Pidner is SVP for litigation and Andrew Doersam is a paralegal.

Tags: Credit cardsData breachesDebit cardsPayments system
ShareTweetPin

Related Posts

Banker op-ed: Durbin-Marshall credit card bill will hurt small businesses

Former Trump adviser warns against credit card interest rate cap

Newsbytes
November 7, 2025

A proposal to create a nationwide cap on credit card interest rates would hurt millions of Americans by cutting off access to credit, President Trump’s former campaign adviser Steve Moore said in a new report.

Trump to nominate Miran for Fed board seat

Fed’s Miran: Stablecoins pose little risk to bank deposits

Economy
November 7, 2025

Passage of a new regulatory framework for stablecoins likely won’t lead to a flood of bank customers pulling their money out of deposit accounts and into the digital currency, Federal Reserve Governor Stephen Miran said.

Fed’s Waller remains unconvinced of need for CBDC

Fed’s Waller: ‘Skinny’ master account would only be available to banks

Newsbytes
November 7, 2025

Federal Reserve Governor Christopher Waller sought to clear up confusion about his proposal for the creation of a “skinny” master account by saying the accounts would only be made available to chartered depository institutions.

U.S. Supreme Court agrees to hear debit card rule challenge

Rate caps hurt consumers they’re designed to help

Payments
November 7, 2025

How a recent Vanderbilt Policy Accelerator for Political Economy and Regulation study gets the credit card market wrong.

Podcast: The Erie Canal at 200

Podcast: The Erie Canal at 200

ABA Banking Journal Podcast
November 6, 2025

Economic historian John Steele Gordon and editor-in-chief Evan Sparks discuss how the Erie Canal was financed and built—and how it transformed America.

FDIC proposes defining unsafe and unsound practices, removing reputational risk

The brokered deposit statute is out of sync with today’s financial marketplace 

Community Banking
November 6, 2025

Congress should repeal Section 29 of the Federal Deposit Insurance Act and replace it with a targeted asset-growth restriction for troubled banks. 

NEWSBYTES

Former Trump adviser warns against credit card interest rate cap

November 7, 2025

Fed’s Miran: Stablecoins pose little risk to bank deposits

November 7, 2025

Fed: Policy uncertainty, AI sentiment pose financial stability risks

November 7, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The Erie Canal at 200

November 6, 2025

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.