LaCie's online store was compromised for nearly a year, exposing credit cards and contact info
Hardware Giant LaCie Acknowledges Year-Long Credit Card Breach — Computer hard drive maker LaCie has acknowledged that a hacker break-in at its online store exposed credit card numbers …
Context & Ripple Effects
LaCie's disclosure lands three months after the Neiman Marcus breach that went undetected from July to December, making it the second high-profile case this year of a retailer learning about card theft long after it began. The near-year dwell time on LaCie's online store puts it in the same category of failure: attackers resident on payment infrastructure while routine monitoring missed them.
The story traveled widely on the day of disclosure — pickups at Threatpost, ZDNet, SC Magazine UK, eSecurityPlanet and The Mac Observer — which reflects how sensitive the timing is: the disclosure came just months after LaCie launched its Fuel wireless drive aimed at mobile consumers, a product line whose buyers overlap heavily with the store's customer base.
First-order effects
- Customers who bought from LaCie's online store over the past year face fraudulent charges and card reissuance, while issuing banks absorb the replacement costs and fraud losses tied to the exposed numbers.
- LaCie must take its storefront offline or harden it mid-investigation, directly cutting off a sales channel during the same quarter it is promoting consumer products like Fuel.
Second-order effects
- Every hardware maker running a direct-to-consumer web store now faces renewed issuer and acquirer scrutiny of its PCI compliance posture, because two long-dwell breaches in quick succession — Neiman Marcus and now LaCie — show detection timelines measured in months, not days.
- Payment processors and security vendors selling transaction monitoring gain leverage in pricing and mandates, as merchants discover that compliance checkboxes did not surface a compromise lasting most of a year.
Third-order effects
- If long-dwell card breaches keep surfacing through 2014, expect pressure to shift US e-commerce toward stronger authentication of card-not-present transactions and away from storing raw card data on merchant servers — a structural change driven by breach economics rather than by regulation alone.
- The pattern points toward brand damage becoming the binding constraint on direct online sales for hardware vendors: once consumers associate a manufacturer's storefront with card risk, those vendors may cede checkout to third-party platforms rather than own the liability themselves.
The trend: Early 2014's run of long-undetected retail card breaches is turning payment-data dwell time into the metric by which merchants' security programs are judged.