The company Thursday reported a $20 million computer-intrusion-related charge for its third quarter, ended April 28. Sales were up about 6%, to $4.11 billion, from the same quarter a year ago.
TJX claimed in a regulatory filing Thursday that it does not know "who took this action, whether there were one or more intruders involved, or whether there was one continuing intrusion or multiple, separate intrusions." The $20 million, or 0.5% of net sales for the quarter, TJX already has spent related to the intrusion has gone toward investigating and containing the computer intrusion, work to improve the company's computer security and systems, communicating with customers, and technical, legal, and other related costs, the company stated.
Costs are likely to increase quickly. Payment card issuers, such as Visa, have initiated Payment Card Industry security standard compliance claims against some of TJX's acquiring banks seeking reimbursement, according to TJX, for about $4 million in fraudulent payment card transactions. The transactions were made with counterfeit payment cards believed to have been created using payment card transaction information allegedly stolen during the TJX computer intrusion. PCI members also could issue fines against TJX for noncompliance with the PCI standards.
That's just scratching the surface, as TJX is facing class-action lawsuits from customers in state and federal courts in Alabama, California, Illinois, Massachusetts, Michigan, Ohio, and Puerto Rico, as well as in provincial Canadian courts in Alberta, British Columbia, Manitoba, Ontario, Quebec, and Saskatchewan. Additional class-action suits from financial institutions affected by the computer intrusion -- those issuing credit and debit cards used during the time of the intrusion -- have been filed against TJX in federal court in Massachusetts. All-told, nine lawsuits have been filed against TJX since April 17.
TJX claims that it doesn't know the extent of any fraudulent use of any of the payment card information believed stolen and that the company doesn't know the details of the ongoing law enforcement investigations into the crime. The company is aware, however, that law enforcement and 37 state attorneys general are looking into whether the computer intrusion violated any laws regarding consumer protection. The company has received subpoenas from 11 of these attorneys general.
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.