In June 2003, a visitor to www.PETCO.com conducted an SQL injection attack and was able to read in clear text credit card numbers stored in respondent’s database.
Privacy & surveillanceRulingAgainst
Judge orders Petco to implement website security program
Judge orders Petco to implement a comprehensive information security program for its website as part of a settlement.
The settlement requires that Petco implement a comprehensive information security program for its Web site.
As a result, a hacker was able to penetrate the Petco Web site and access credit card numbers stored in unencrypted clear text.
It requires that Petco arrange biennial audits of its security program by an independent third party certifying that Petco’s security program is sufficiently effective to provide reasonable assurance that the security, confidentiality, and integrity of consumers’ personal information has been protected.
The FTC alleges that Petco created these vulnerabilities in its Web site by failing to implement reasonable and appropriate security measures to secure and protect sensitive consumer information, including simple, readily available defenses that would have blocked such attacks.
The settlement prohibits Petco from misrepresenting the extent to which it maintains and protects sensitive consumer information.