What to Do After a Payment Data Breach
A suspected breach is stressful, and the first hours matter. Here is a calm, general sequence to follow while you bring in the right professionals.
Discovering that card data may have been stolen from your business is one of the most unsettling moments an owner can face. It may start with a call from your processor, a notice from a card network, a cluster of customers reporting fraud after shopping with you, or something odd on your own systems. Whatever the trigger, the instinct is to panic or to quietly fix things. Neither helps.
What follows is general information to help you think clearly, not legal advice. Breach obligations vary by state, by the type of data and by your contracts, and mistakes can be costly. Engage an attorney experienced in data privacy as early as possible, and treat this article as a map to the questions you will be asked.
Key takeaways
- Contain the problem but preserve evidence; do not wipe systems prematurely.
- Notify your processor, attorney and insurer quickly.
- Card brands may require an approved forensic investigator.
- State notification laws vary, so get legal advice before sending notices.
- Prevention through encryption, tokenization and PCI compliance is far cheaper.
Step one: contain without destroying evidence
Your first goal is to stop further loss. Disconnect affected devices from the network, but do not wipe, reformat or reinstall anything yet. Powering off a system can erase volatile evidence, so follow the guidance of your forensic investigator or your processor on whether to unplug a network cable or shut down.
Change passwords and revoke access for any account that may have been exposed, starting with administrator accounts, payment dashboards and remote-access tools. Write down what you did and when. A timeline made in the first hours is invaluable later.
- Isolate affected devices from the network
- Do not wipe or reinstall systems before advice
- Change passwords and disable compromised accounts
- Start a written log of actions and times
Step two: call your processor and your advisors
Most merchant agreements require prompt notice of a suspected compromise. Contact your processor right away so that the card brands and issuing banks can be alerted and customers' cards can be monitored or reissued. Delay can lead to larger penalties and a rougher relationship.
At the same time, contact your attorney and your insurance carrier. If you carry cyber insurance, there may be notification deadlines and a required list of approved responders. MCCPS offers free 24/7 technical support and can help you find the right contact for your account.
Step three: investigate with qualified help
Card brands may require a payment-card forensic investigator from an approved list to determine what happened, which data was exposed and for how long. The cost can be significant, which is one reason prevention matters.
Cooperate fully, but have your attorney coordinate communications so privilege and accuracy are protected. Preserve logs, receipts, device images, vendor contracts and records of who had access. The investigator will want to know about every terminal, software package and remote-access arrangement you use.
One more practical point: keep a short incident contact sheet somewhere other than your computers, such as a printed page in a locked drawer. It should list your processor's support line, your attorney, your insurance carrier, your IT provider and your bank. During a real incident your email and shared drives may be unavailable or untrusted, and hunting for phone numbers wastes the first and most valuable hours.
Step four: understand your notification duties
Many states have laws requiring notice to affected individuals, and sometimes to state officials or credit reporting agencies, when personal information is exposed. Triggers, definitions, timelines and content of notices differ from one state to the next, and federal rules may apply in particular industries.
Do not draft or send notices without legal advice. Poorly worded notices can create liability, and missed deadlines can bring penalties. Your attorney will help determine who must be told, how and when, and what to say about the steps you are taking.
Step five: fix the cause and rebuild trust
Once the immediate danger passes, address the root cause. That might be a weak remote-access password, an unpatched system, malware on a register, or a tampered card reader. Replace compromised equipment with trusted devices, apply updates and tighten access. Your investigator's report will help you prioritize.
Be honest and plain with customers. A short, factual message that explains what happened, what you are doing and how customers can protect themselves is more convincing than silence or spin. Offer a contact number for questions and make sure staff know what they may say.
- Remove malware and rebuild affected systems from clean sources
- Replace compromised card readers
- Close the weakness that allowed access
- Brief all employees on the approved message
What may happen financially
Depending on the case, a business could face forensic fees, fines or assessments passed through from card brands, the cost of reissuing cards, legal expenses and lost sales. Your contract and insurance policy will determine who pays what. Read both now, before an incident, rather than after.
Cyber liability insurance exists for this reason, though policies differ widely in what they cover. Ask your agent about coverage for forensic investigation, notification costs and regulatory defense, and about conditions such as required security measures.
Reduce the odds of a repeat
After an incident, many businesses discover that simple controls would have prevented it. Use encrypted, chip-enabled terminals, tokenize stored cards, segment your network, enforce unique passwords with two-step verification and complete your PCI self-assessment annually. Our payment security checklist walks through these measures in order.
MCCPS offers PCI compliance help, and its platform supports tokenization and encrypted card entry so your systems never touch raw card numbers wherever possible. If you have questions about your current setup, you can call 844.826.6227 and ask for a conversation about what a safer configuration would look like.
Frequently asked questions
What should I do first if I suspect a payment data breach?
Disconnect affected devices from the network without wiping them, change compromised passwords and write down what you know. Then notify your processor and contact an attorney experienced in data privacy. Do not delete files or reinstall systems until you have advice. Check the details against your own agreement, since terms differ between providers.
Do I have to tell my customers about a breach?
Many states require notice to affected individuals when personal information is exposed, with rules varying on timing and content. This is general information, not legal advice. Consult your attorney before sending notices so you comply with the law in every relevant state.
Will I need a forensic investigator?
Card brands may require an approved payment-card forensic investigator when a compromise of card data is suspected. Your processor will tell you what is required. Your attorney can help coordinate the investigation and protect the confidentiality of findings. A quick call to your processor can confirm how this works on your specific account.
Does insurance cover a data breach?
Some cyber liability policies cover forensic costs, notification expenses and legal defense, but coverage varies widely and often has conditions and deadlines. Review your policy before an incident and ask your insurance agent exactly what is included and what must be done after a breach.
How can I lower the chance of a breach?
Use chip and encrypted terminals, tokenize stored cards, use unique passwords with two-step verification, isolate payment devices on their own network and complete your PCI self-assessment every year. Train employees to recognize phishing and social-engineering calls. Write the answer down so every manager and employee gives customers the same explanation.
This article is general information, not legal, tax or compliance advice. Card-network and state rules change — confirm current requirements before acting. Savings depend on your individual statement analysis.