Also, as I understand it, many american websites seems to store credit card details, why is that?
In Denmark we often use a payment gateway, exactly to avoid these types of attack. If my webshops database got leaked, my customers would not have to fear creditcard leakage.