, ,

Wawa, Attorneys General Come To Agreement Over Data Breach


File photo

An agreement in the wake of a 2019 data breach has been reached between Wawa and the attorneys general offices of several states, including Pennsylvania.

Pennsylvania Attorney General Josh Shapiro, who is running for governor as a Democrat, said on Monday that the states and Pennsylvania-based Wawa had reached an $8 million agreement over the December 2019 data breach that compromised approximately 34 million payment cards used across all Wawa stores.

Advertisements


Pennsylvania will collect $2.5 million through the settlement and the rest will be split by Delaware, Florida, Maryland, New Jersey, Virginia, and Washington D.C.

In addition, Wawa has agreed with the attorneys general to put in place a series of actions intended to strengthen programs to protect customer data.

Below is specific information on the actions agreed to in the settlement:

  • Maintaining a comprehensive information security program designed to protect consumersโ€™ sensitive personal information;
  • Providing resources necessary to fully implement the companyโ€™s information security program;
  • Providing appropriate security awareness and privacy training to all personnel who have key responsibilities for implementation and oversight of the information security program
  • Employing specific security safeguards with respect to logging and monitoring, access controls, file integrity monitoring, firewalls, encryption, comprehensive risk assessments, penetration testing, intrusion detection, and vendor account management; and
  • Consistent with previous state data breach settlements, the company will undergo a post settlement information security assessment which in part will evaluate its implementation of the agreed upon information security program.
Advertisements


The agreement and payment to the states will release Wawa from all civil claims the offices could have brought against the company, according to the agreement presented to the court.

The settlement is third largest attorneys general credit card breach settlement behind Target and The Home Depot.

Advertisements


Pennsylvania authorities said they immediately began an investigation after Wawa “proactively notified” the attorney general’s office that the company experienced a data breach.

The investigation found that Wawa had disregarded basic security precautions, allowing hackers to access its network and install malware on its payment processing servers in its retail locations. Between April 18, 2019, and December 12, 2019, the malware gave the hackers access to the payment card details of Wawa customers. Approximately 9.1 million credit cards in Pennsylvania could have been compromised by the hacker, Shapiro’s office said.

โ€œTodayโ€™s settlement will help protect Pennsylvanians personal information going forward and will hold Wawa accountable for the data breach that occurred on their watch,โ€ Shapiro said. โ€œThanks to this work Wawa will adopt new corporate policies to deter data breaches in the future. Every corporation that does business in Pennsylvania needs to stay alert and protect their customerโ€™s personal data or they will have to answer to my office.โ€

Advertisements


Shapiro and New Jersey Acting Attorney General Matthew Platkin led the coalition of seven states.

Advertisements



Report a correction via email | Editorial standards and policies



Report a correction via emailย |ย Editorial standards and policies