ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

TK Maxx owner: 45.7m accounts were compromised

Dawn Kawamoto CNET News.com

Published: 30 Mar 2007 15:19 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

TJX Companies said 45.7 million accounts were compromised over nearly a two-year period, in an update on Wednesday of an investigation into a data breach of customer records.

The scope of the breach, which was initially disclosed in January, is far wider than previously believed.

"This is the largest security breach we've ever had worldwide," said Avivah Litan, an analyst with research firm Gartner. "There was a case at CardSystems where 40 million records were exposed, but this one looks like it was a case where the information was stolen."

TJX, which operates such discount retail chains as the UK's TK Maxx and TJ Maxx and Marshalls in the US, released additional details of the breach in a filing with the Securities and Exchange Commission (SEC).

In its filing, TJX noted that cyberthieves first accessed its computer systems in July 2005 and installed software to harvest such sensitive customer information as account information, names and addresses, drivers' licence numbers and military and state identification. The breach continued through mid-January 2007.

Accounts and transactions affected included credit and debit card transactions, as well as checks and returned merchandise without receipts at the company's Marshalls, TJ Maxx, HomeGoods and AJ Wright stores in the US and Puerto Rico. Credit card transactions at TJX's Winners and HomeSense stores in Canada, as well as credit and debit card transactions at its TK Maxx stores in Ireland and the UK were also compromised.

TJX rang up a pre-tax charge of $5m in the fourth quarter to deal with the computer breach, which included the costs associated with investigating the issues, improving its security systems and notifying customers.

Those costs are likely to increase, given the multiple lawsuits customers have filed and investigations launched by a number of government agencies. According to the SEC filing, a multi-state investigation in the US is currently under way that encompasses 30 states, and the Federal Trade Commission is also reviewing whether TJX violated laws pertaining to consumer protection. In Canada, several privacy commissioner offices in various provinces are also reviewing the matter.

The security breach involving CardSystems, a third-party processor of payment data for banks and merchants, resulted in the exposure of credit card numbers for 40 million accounts — a figure comparable to the TJX case. Other notable cases include data broker ChoicePoint, which affected an estimated 145,000 Americans, and the University of California in Los Angeles, in which 800,000 people had their information compromised after a security breach.

In the case of TJX, Litan suspects it was a case where attackers gained access through a wireless regional hub for the company's store controllers that handle the point-of-sale system. From there, the attackers may have been able to work their way into TJX's central system, she noted.

"Most retailers aren't looking at their point-of-sale system," Litan said. "Most enterprises tend to forget about the devices hanging off of their networks. What happened here may not be all that uncommon."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
11 out of 11 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Credit risk / Treasury analyst - SWIFT - Treasury system - Citidirect

Your main responsibilities will be to management of cash payments/receipts for all traded products and reconciliation of accounts payables and ...

Energy Market Risk Tier 1 Investment Bank

You will be joining one of the top risk teams in the industry responsible for performing the following duties within their commodities business: ...

Credit Risk Analyst Role ( London )

You will have: commercial credit analysis experience gained from a top tier bank or commodity trading house, good academics from a numerical ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment