, ,

School Graduation Cap & Gown, Yearbook & Class Ring Seller Data Breach Impacted PA Consumers, Officials Say


File photo.

The producer and seller of yearbooks, class rings, caps and gowns, and other graduation memorabilia experienced a data breach that impacted 30,295 Pennsylvania consumers’ payment card information, according to the Pennsylvania Attorney General’s Office.

Advertisements


State Attorney General Josh Shapiro, a Democrat who will become governor next month, announced a settlement last week with Herff Jones LLC. over the data breach.

On April 7, 2021, Herff Jones received word from one of its payment processors that numerous cards with its name on them had been discovered on three distinct websites known for selling stolen credit card information. A forensic analysis found that on December 15, 2020, an unidentified hacker took advantage of a weakness in the business’ web servers to acquire clients’ payment card numbers and other personal data, the attorney general’s office said.

Herff Jones failed to properly implement reasonable data security measures to secure customers’ credit card information, according to an investigation carried out by Shapiro’s office in collaboration with the New York Attorney General’s office.

Advertisements


Herff Jones will give the attorneys general offices in Pennsylvania and New York each $100,000, Shapiro’s office said.

“Protecting Pennsylvanians’ personal information and financial data is a key priority of my office,” said Shapiro. “Every corporation that does business in Pennsylvania needs to stay alert and protect their customer’s personal data or they will have to answer to my office in court. The terms of today’s settlement will help Herff Jones graduate to better protection of consumers’ personal information.”

Advertisements


Herff Jones was found to be in violation of the Payment Card Industry Data Security Standard during the examination. To guarantee that cardholder data is processed in a secure setting, this standard is overseen by the Payment Card Industry Security Standards Council, authorities said.

According to a statement, the settlement with the attorneys general requires Herff Jones to maintain reasonable security policies designed to protect consumer personal information including:

1. Designating an employee to coordinate and supervise its information security program;
2. Conducting security risk assessments of its networks that stores personal information annually;
3. Conducting annual employee training to inform employees who are responsible for handling private information about the company’s data security practices;
4. Designing and implementing reasonable security measures for the protection and storing of personal information, including timely software patch updates, conducting penetration-testing of its networks, and implementing reasonable access controls such as multi-factor authentication.
5. Herff Jones must comply with Payment Card Industry Data Security Standard and validate compliance by engaging a Payment Card Industry Qualified Security Assessor to conduct an assessment resulting in the delivery of a Payment Card Industry Report on Compliance and Attestation of Compliance.

Advertisements


Report a correction via email | Editorial standards and policies



Report a correction via email | Editorial standards and policies