I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't authorise them to publish. However I'll leave it to the ICO to make that determination.
I'm pretty sure them ignoring this for a year is illegal as it involves personal information which their privacy policy didn't authorise them to publish. However I'll leave it to the ICO to make that determination.
In reality I don't hold out much hope but fingers crossed we can get some pressure behind this and force companies to take security seriously, especially when the vulnerability is responsibly reported as this seems to have been originally.
They might not even have PCI compliance issues alas.
The management will argue that they knew nothing, although that is becoming less of a defence now.
http://en.wikipedia.org/wiki/General_Data_Protection_Regulat...
The ICO in the UK currently has the ability to fine up to £500k as I understand it.
SSNs are worse, though. The last four digits plus your birth date & location might just give the whole thing away.
I work in eCommerce, we develop a platform - and this stuff pisses me off no end, as it tarnishes the entire industry, and we'll now be dealing with jumpy clients for a month after this news hits the trade rags.