IANAL, but this question of "due diligence" and comparing oneself to one's competitors begs the question -- what harm (in the legal sense) has been done here to anyone whose CC or debit card # was revealed? Does your answer vary depending on whether there was fraud associated with that card #?