I guess the details are still not known? I was confused by the target hack in my earlier comment(sorry). That was where hvac contractors had their credentials stolen, and malware was installed on their pos system. The home depot hack was malware suspected to have been installed on their self checkout machines[1].
" it shouldn't be the customers who suffer when this happens. The people that made it so easy for my personal information to leak, the ones who necessitated that my personal information even be required as part of the transaction, should be the ones feeling the pain"
I get what you mean about some services collecting everything they can, and not taking the best possible care of it. I agree with you there. I was trying to point out an exception where there isnt anything that can be done. For example, try and stop finfisher :)[2] Companies will get hacked, and it is not always negligence. I was trying to point out that you wouldn't blame a shopkeeper if an armed robber stole credit card info, but if he left it in an unlocked room then we should. And I dont think either home depot or target were collecting more than they needed to.
PS, if anyone has a link as to how we can be more proactive about working with law enforcement to catch the fraudsters, I would love to see it. Either from the point of view of a consumer, or service provider.
1. http://krebsonsecurity.com/2014/09/home-depot-56m-cards-impa...
2. http://news.softpedia.com/news/finfisher-s-account-of-how-he...