Advertisement
Promo

Security threats Toolkit

TK Maxx owner criticised after security breach

Richard Thurston ZDNet.co.uk

Published: 30 Jan 2007 14:32 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The parent company of TK Maxx, the high-street retailer, was breaking financial standards when its customers' credit card details were stolen just before Christmas, it has been claimed.

According to a Visa email alert sent to financial institutions, parent company TJX was storing credit card information in violation of the Payment Card Industry Data Security Standard, a framework aimed at preventing credit card fraud, which is backed by both Visa and Mastercard.

TJX should not have stored credit card information longer than necessary, yet card information dating from 2003 was stolen, according to experts interviewed for a report by Information Week. "I can see storing data for a few hours or a day until transactions clear, but some of the stolen data goes back to 2003. That's a long time to be out of compliance," said an executive from a California credit union that issues Visa cards to its members, speaking to Information Week.

TK Maxx had not responded to requests for comment at the time of writing.

TJX admitted two weeks ago that customers' credit card details had been stolen after its network security was breached by a hacker, and that it did not know the full extent of the problem. Although the security breach took place in the US, UK customers may have been affected. Millions of card accounts are thought to have been affected, and some account details have since been used fraudulently. Some 23 percent of these fraudulent transactions took place outside the US.

TK Maxx customers who spot unexpected transactions on their bank statements have been urged to contact both the company and their bank. TJX claims it has since shored up its network security.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
46 out of 48 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters