TRUSTWAVE▊
The compliance assessor named in lawsuits after the two most famous PCI-certified breaches in history — and, twice, the lawsuits went away without anyone proving anything.
- ENTITY
- Trustwave Holdings, Chicago — security services firm and one of the largest PCI Qualified Security Assessors (QSAs); acquired by LevelBlue in August 2025 FACT
- OPERATION
- Paid by the companies it assesses to certify their PCI DSS compliance — the standard arrangement for every QSA, worth keeping in view throughout FACT
- EVENT
- SUED, TWICE — by banks after Target (2014; dropped within weeks) and by insurers over Heartland (2018; merits never adjudicated in this record) FACT-OF-FILING
- DEFENSE
- A point-in-time compliance assessment "in no way guarantees that the company examined has not or cannot be breached" — Trustwave's own words FACT
- DISPOSITION
- No court has found Trustwave responsible for either breach. The Target suit was withdrawn "without prejudice to re-filing"; the record here shows filings and denials, not findings FACT
First party. Trustwave's statement on the Heartland insurer suit, given to The Register in 2018, in full flight:
"Trustwave provided Heartland with an assessment of its compliance with PCI DSS. However, such an assessment, as the contract at issue makes clear, in no way guarantees that the company examined has not or cannot be breached. Trustwave did not manage Heartland's information security, and at no time did Heartland assign blame for the breach or make any claim against Trustwave. The insurers' demand related to a decade-old breach is entirely without merit." Corporate channel today: trustwave.com links
@LevelBlueCyber, its post-acquisition parent's account.
-->
Here is the auditor of the compliance age, observed at the two moments its signature mattered most — and at the two moments the legal system declined to say what that signature was worth. The specimen's defense is candid to the point of self-harm: the certificate never guaranteed anything. Noted, says the archive. Filed under: what the certificate is for.
Every PCI certificate is signed by somebody. Trustwave signed more of them than almost anyone, and by the plaintiffs' telling it signed the two most consequential ones — Heartland's and Target's — inside the windows when those networks were already or about to be compromised. That is why this file exists.
But mind the tiers. The signatures-while-compromised claims come from complaints, not verdicts. One suit evaporated in a week; the other died in cross-filings; no court ever reached the merits in this record. The archive keeps the allegations AND the absence of adjudication in the same drawer, at the same volume.
the drama timeline
ACT I — THE HEARTLAND SIGNATURE (2007–2009)
A processor is certified compliant. A processor is breached. A decade later, the insurers who paid for it come looking for the assessor.
-
2007–2008
The certifications the insurers would later point to
Per the insurers' later complaint, Trustwave assessed Heartland and signed it off as PCI DSS compliant in the very period intruders were inside — the SQL injection landed in late 2007, sniffer malware followed in 2008. Trustwave was "hired to assess — but not manage — Heartland's computer security defenses." The breach itself is documented on the Heartland case file.
ACT II — TARGET, AND THE FASTEST LAWSUIT IN COMPLIANCE HISTORY (2013–2014)
Forty million cards, one scan report, two banks, and a suit that lived for about a week.
-
SEP 20 2013
The scan (as alleged)
Per the banks' complaint, Trustwave scanned Target's network on September 20, 2013 and told Target there were no vulnerabilities; the complaint further alleged, "on information and belief," that Trustwave provided round-the-clock intrusion monitoring. The Target breach began that November and ran for weeks — approximately 40 million cards.
-
MAR 24 2014
Banks sue the auditor — a first
Trustmark National Bank and Green Bank file a would-be class action in the Northern District of Illinois against Target and Trustwave, alleging negligence and misrepresentation — one of the only times a PCI assessor had ever been sued over a client's breach. Trustwave declines all comment: company policy is "not to confirm that any party is a customer."
The industry holds its breath: if the signature carries liability, the entire QSA business model is suddenly interesting.
-
MAR–APR 2014
And then the banks fold
Within days, both banks dismiss their cases "without prejudice to re-filing." Trustwave CEO Robert McCullen writes to clients that Target "did not outsource data security" to Trustwave, and that Trustwave "did not monitor Target's network or process its cardholder data." Neither Target nor Trustwave would confirm whether they were partners at all; no re-filing against Trustwave appears in this record.
ACT III — THE INSURERS RETURN (2018)
Ten years after Heartland, the money that covered the breach comes back up the chain looking for the signature.
-
2018
Lexington and Beazley v. Trustwave — $30M
Lexington Insurance and Beazley Insurance — who had paid Heartland $20M and $10M respectively — sue Trustwave in Illinois, alleging negligence in failing to detect the SQL-injection attack, suspicious network activity, and malware, and in certifying Heartland compliant while compromised. Trustwave had already filed first in Delaware to have the demands declared baseless, calling them "time-barred" and "entirely without merit," and noting "at no time did Heartland assign blame for the breach or make any claim against Trustwave."
No adjudication of the merits of either action appears in the sources in hand; the file asserts the filings, the defense, and nothing more.
-
EPILOGUE — AUG 2025
Absorbed, still assessing
After a decade under Singtel and an abandoned merger dance with Cybereason, LevelBlue completes its acquisition of Trustwave, billing the result as the world's largest pure-play managed security services provider. The QSA practice continues. The signature is still for sale — and still, per its own fine print, guarantees nothing.
both sides, on the record
Its signature sat on both marquee failures — by the plaintiffs' telling, Trustwave certified Heartland while intruders were inside, and cleared Target's network weeks before the largest retail card breach then known [1] [3].
The defense concedes the critics' whole premise. "In no way guarantees that the company examined has not or cannot be breached" is Trustwave's own description of its product — a certificate the market treated as a security signal and the assessor treats as a snapshot [2].
Paid by the assessed, liable to no one — the structural critique: both times the signature was tested in court, the QSA's accountability evaporated before the merits were reached [4] [5].
Nobody ever proved anything. The Target suit was dropped by the plaintiffs themselves within days, "without prejudice" language notwithstanding, and was never re-filed against Trustwave in this record; the Heartland insurer action produced filings and counter-filings, not findings. No court has held Trustwave responsible for either breach [2] [5].
The contested facts may simply be wrong. McCullen's on-record position: Target did not outsource its data security to Trustwave, and Trustwave did not monitor Target's network or process its cardholder data — directly contradicting the complaint's "round-the-clock monitoring" theory, which the banks pleaded only "on information and belief" [3] [5].
A point-in-time assessment is what everyone bought. The victim's own CEO never blamed Trustwave — "at no time did Heartland assign blame for the breach or make any claim against Trustwave" — and the profession's consensus, aired in the Carr affair, is that a QSA certifies compliance with a minimum standard, not immunity from professional criminals [2] [7].
YOU DECIDE
Scoped to the claims. That Trustwave was sued after both breaches is fact; that every "failed to detect" line is a plaintiff's allegation, twice abandoned or unresolved, is equally fact. What remains, undisputed because Trustwave itself keeps saying it, is the product definition: a compliance certificate that guarantees nothing. Whether that is an honest limitation or the confession of an industry — and whether the fault lies with the assessor, the standard, or the buyers who mistook a receipt for a shield — is yours to weigh. The PCI Council file holds the scoreboard.
Weigh the costly signal: when the signature was finally priced in court — twice — nobody, plaintiff or defendant, was willing to pay to find out what it was worth.
The archive does not judge. It keeps the filings, and the withdrawals.
evidence locker
THE LAWSUITS & THE DEFENSE
CONTEXT & STATUS
The standard. Every "failed to detect" and "certified while compromised" line on this page is a plaintiff's allegation, attributed to the complaint that made it and paired with Trustwave's denial at full strength. The Target suit's withdrawal — the fact that most flatters the subject — is stated prominently and repeatedly. No adjudication is claimed because none exists in this record; no motive is asserted; the client relationships themselves are asserted only as the complaints and reporting asserted them. If it couldn't survive a defamation challenge, it wouldn't be on this page.