Albertson’s Bungles Data Breach PR

In 1905, George Santayana wrote that “Those who cannot remember the past are condemned to repeat it”.

In the world of retail data theft, memories are extraordinarily short. Just last December, Target bungled the communications surrounding a massive credit card data theft which resulted in a massive loss of customer trust. This loss of trust profoundly contributed to a stock price that is down 15 percent from a year ago and first quarter earnings plummeted 16 percent, financial results that were so poor that senior executives including the CEO were sent packing.

AB Acquisitions is one of the nation’s largest grocers and owns Albertson’s, ACME Markets, Jewel-Osco, Shaw’s and Star Markets and they either have a short memory or didn’t pay attention to recent history and how screwing up communications from stolen credit card information can have a devastating impact companies and brands.

On August 14th, Albertson’s announced a data breach which tried “to obtain credit and debit card payment information”. Typically, credit card data bases include names, account numbers, the expiration date and the three digit security code.

According to cybercrime guru Brian Krebs, credit card information from brick-and-mortar stores are highly prized and can command up to ten times the price of card information stolen on-line. Information collected from a physical swipe of a card’s magnetic strip can be easily turned into fake cards and used to fund high value purchases at other physical stores, removing the risk of having goods shipped. Walk in, buy a flat screen, walk out and disappear into the ether.

The value of information that is physically swiped was one reason Verizon’s 2014 annual report on data breaches said that criminals are focusing on “large scale attacks on payment card systems” and called 2013 the “Year of the Retailer Breach”.

Criminals are focusing on “large scale attacks on payment card systems.”

With so much information readily available on the risk to consumers from an attack like Albertson’s experienced, they should have been lighting the world on fire to warn their customers of fraud risk — it’s only by fast, honest communications that customer trust can be preserved. If stolen credit card data from the Albertson’s breach starts to show up in criminal circles, expect a loss of trust similar to Target’s and a hit on their business.

However, instead of open, clear, customer communication, Albertson’s has taken the road of obfuscation. In their press release, they didn’t point out the dangers of stolen credit card data, but rather said that it has “not yet been determined whether any cardholder data was in fact stolen” and that there was no evidence of “any misuse of such data”.

Instead of open, clear, customer communication, Albertson’s has taken the road of obfuscation.

They buried the information on the breach on their webpage below the weekly grocery specials, a contest to win a car and besides consumer product ads and only left the notice on their homepage for five days. Would the small headline “AB Acquisition LLC Confirms incident Involving Payment Card Data Processing” warn any customers that they could be at risk?

Bad communications during a data breach crisis can quickly destroy years, decades, of brand trust and customer loyalty. Public communications needs to be comprehensive and communicate clearly to the media and customers, whether it is through the press, social channels, call centers or stores. And communicating clearly means informing customers about their risk from stolen credit card data so they see the retailer as a fellow victim and partner in protecting themselves from further criminal activity. Conversely, lack of open and honest communications invariably leads to a feeling of betrayal and loss of trust.

Criminals spent a month inside of Albertson’s databases trying to steal information that they could turn into money. Once Albertson’s has finished their investigation, if it turns out that massive numbers of credit cards were stolen, then Albertson’s and their associated brands will pay a heavy price — they simply have to remember the immediate past of what happened to Target.

– By: David Fuscus – President & CEO |

