Home > Security News > Data breach at TJX could affect millions
Security News:
EMAIL THIS

Data breach at TJX could affect millions

By Robert Westervelt, News Editor
18 Jan 2007 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Retailer TJX Companies Inc., which runs several discount clothing and home goods stores, said Wednesday that its systems had been breached by an attacker who may have stolen the credit card data of millions of customers.

The company said an attacker exploited a flaw in a portion of TJX's computer network that handles credit card, debit card, check, and merchandise return transactions for customers of its T.J. Maxx, Marshalls, HomeGoods and A.J. Wright stores in the U.S. and Puerto Rico, and its Winners and HomeSense stores in Canada. The intrusion may involve customers of its T.K. Maxx stores in the U.K. and Ireland and could also extend to TJX's Bob's Stores in the U.S., the company said.
Data breach:
How to survive a data breach

Complying with breach notification laws

Column: Federal government pushes full-disk encryption

Survey: Data breach costs surge

News: Data breach at Boeing exposes 382,000 employees

News: Hacker exploits UCLA database

Column: Schneier: Data breach at UCLA barely newsworthy

The discovery was made in December, but the retailer said investigators asked to delay an immediate announcement of the breach during the initial part of the investigation.

Customers who shopped in the stores in 2003 and from mid-May to December, 2006 may have been affected, the company said. TJX said it has been able to specifically identify a limited number of credit card and debit card holders whose information was removed from the system.

The company said that "a relatively small number" of customer names and drivers' license numbers were also removed from its system. Those customers are being contacted directly.

The Company also hired consultants from General Dynamics Corp. and IBM to provide assistance in monitoring and evaluating the intrusion, assessing possible data compromise, and seeking to identify affected information. The consultants are also helping bolster TJX computer systems with security upgrades, the company said.

"We have also engaged two of the very best computer security experts to help us strengthen the security of our systems in order to prevent this from happening again and we believe customers should feel safe shopping in our stores," said Ben Cammarata, chairman and acting CEO of the company in an alert to customers on its Web site.

A special helpline is in place for TJX customers who have questions about the data breach. Customers may reach the helpline toll-free at 866-484-6978 in the United States, 866-903-1408 in Canada, and 0800 77 90 15 in the United Kingdom and Ireland.

Data breaches have been making headlines in 2006. In December, a hacker gained access to a computer system at the University of California, Los Angeles. About 800,000 potential victims were notified. Aircraft giant Boeing Co. also said in December that a company-owned laptop containing the personally identifiable information of nearly 400,000 of its employees and former workers was stolen.

According to a list posted by the watchdog group, Privacy Rights Clearing House, dozens of breaches have taken place in recent months. While, the UCLA breach was one of the largest involving a U.S. higher education institution, businesses have been grappling with data protection and notification of breaches.

In August, AT&T notified about 19,000 customers that their personal data was compromised after digital miscreants hacked one of its computer systems and gained access to credit card information and other personal data. In late 2005, a timeshare unit of Marriott International Inc. notified over 200,000 customers that a data on backup tapes were stolen.

Tags: Identity Theft and Data Security BreachesIdentity Theft and Data Security BreachesEnterprise Data GovernanceVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Identity Theft and Data Security Breaches
Man pleads guilty in online banking hacking scam
White House cybersecurity czar faces major hurdles
Heartland breach cost $12.6 million, CEO says
An inside look at security log management forensics investigations
LexisNexis investigates breach, notifies thousands
Senators hear call for federal cybersecurity restructuring
Former Federal Reserve Bank employee arrested
Attackers cash in on fundamental data handling mistakes, Verizon finds
Courts turn aside data breach suits
Data security best practices for PCI DSS compliance

Identity Theft and Data Security Breaches
How to prevent and build protection against online identity theft
Heartland breach highlights PCI limitations
FBI investigates coordinated ATM scam
Encrypt now to meet new Mass. data protection law
Recovery plans essential for preventing data loss disasters
Internal auditors and CISOs mitigate similar risks
Cybersecurity expert sees PCI DSS problems ahead for retailers
PCI is about eliminating data, not securing it, former QSA says
Data breach discovery, disclosure outpaces 2007
PCI groups to focus on wireless, pre-authorization changes
Identity Theft and Data Security Breaches Research

Enterprise Data Governance
Risk management must include physical-logical security convergence
Simple information security mistakes can cause data loss, says expert
Organizations struggle with data leakage prevention, rights management
Encryption in data management should never be ignored, expert says
Attackers cash in on fundamental data handling mistakes, Verizon finds
Data loss prevention benefits in the real world
Mass., Nev. data protection laws wrong, ineffective
Cybersecurity hearing highlights inadequacy of PCI DSS
Enforcing a vendor risk assessment to avoid outsourcing security risks
How to Secure Cloud Computing

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts