Don't VISA et al require some kind of PCI compliance for storing credit card details?
Audits are few and far between, lots of places have shoddy security but claim they are Fort Knox.
PCI compliancy is quite meaningless unless the people that implement it take their job seriously. That's very frequently not the case, it is just seen as a small obstacle in the way of doing business.