Your membership has expired

The payment for your account couldn't be processed or you've canceled your account with us.

Re-activate

Sleuthing a credit card data breach

Does a bank have to tell you which retailer caused the problem?

Published: August 03, 2015 03:15 PM

Q. For the fifth time, my Bank of America credit card number was changed due to a data breach. Isn't the credit card issuer required to disclose the merchant that compromised my data? —E.F., Davidson, Md.

A. Although federal law provides consumer financial data protections, it is the states (except Alabama, New Mexico, and South Dakota) that require that customers be notified. But the state laws apply to the entity where the hacking occurred, not to the credit card issuer. Consequently, the bank that issued the credit card may detect fraud and issue new cards to stop losses, but it may not know which retailer was breached. The merchant, though, should give you full disclosure about the breach.

Have you had the same problem? Give us your comments, below.

—Consumer Reports

Consumers need better protections for their financial data. Read our recommendations.


E-mail Newsletters

FREE e-mail Newsletters! Choose from cars, safety, health, and more!
Already signed-up?
Manage your newsletters here too.

Money News

Cars

Cars Build & Buy Car Buying Service
Save thousands off MSRP with upfront dealer pricing information and a transparent car buying experience.

See your savings

Mobile

Mobile Get Ratings on the go and compare
while you shop

Learn more