Shopped in Forever 21? There was bank-card-slurping malware in it for, like, forever

John Brown (no body)

Re: Question

"- Isn't encryption mandatory by PCI DSS? What are the consequences for them if they "forgot" to turn it on?"

If your PCI costs are a rounding error then you get cut off from the system until you pay for re-compliance and then get monitored and re-certified more frequently (at your own cost). If your PCI compliance payments and transactions costs are noticeable to the c-suite bonus grabbers, then you get a slap on the wrist and told not to be a naughty boy again.

