A joint investigation by two Canadian privacy commissioners also notes that the hacker very well may have accessed the TJX network through wireless local area networks at two of the company's U.S. stores. That piece of the puzzle comes after months and months of conjecture and widespread speculation about the break-in entry point.
The investigation also reported that:
Earlier this year, TJX announced the loss of more than 45 million credit and debit card numbers that were stolen from its IT systems during an 18-month period. It's considered to be the largest customer data breach on record.
Canadian investigators pointed out that the breach involved millions of credit and debit card numbers, as well as other personal information, such as driver's license numbers that were collected when customers returned merchandise without receipts. Customer information was stolen from mid-2005 through December 2006, the investigation reported. Some stolen information involved transactions dating back to 2002.
TJX, which is the parent company of retailers like T.J. Maxx, Marshalls, and HomeGoods, reported in its second-quarter earnings in August that the company had to absorb a $118 million charge related to the massive security breach. For the second quarter, which ended July 28, the breach cost 25 cents per share -- 10 times more than the 2 cents to 3 cents company executives estimated just three months ago.
Earlier this week, TJX announced a proposed settlement that offers to reimburse people for the cost of replacing their driver's licenses, three years of credit monitoring, and a three-day, 15%-off sale.
"This case is a wake-up call for all retailers. They must collect only the personal information necessary for a transaction," said Frank Work, the Information and Privacy Commissioner of Alberta, in a written statement. "One positive outcome of this extremely unfortunate breach is that TJX worked cooperatively with us to develop a new process for dealing with un-receipted returns, which strikes an appropriate balance between privacy rights and a retailer's need to take steps to prevent fraud."
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.