Dubious Distinction: 45 million credit and debit card records may have been compromised.
TJX, the parent company of T.J. Maxx, Marshall's, and other retailers, disclosed in a Securities and Exchange Commission filing last week that more than 45 million credit and debit card numbers may have been stolen from its IT systems over an 18-month period, making it the largest customer data breach on record. TJX revealed the cybertheft in January but had declined to provide details. The SEC filing indicates a company with haphazard data security practices, at best.
TJX doesn't know "whether there was one continuing intrusion or multiple, separate intrusions," according to the filing. TJX discovered the break-in on Dec. 18, and it most likely dates back to July 2005. The cyberthieves may have stolen card data from TJX's Framingham, Mass., computer system during the approval process, in which payment data is transmitted to card issuers without being encrypted.
TJX recorded a fourth-quarter charge of about $5 million to cover the costs of containing and investigating the breach, as well as improving the security of its IT systems, communicating with customers, and paying legal fees. The Federal Trade Commission has launched an investigation of TJX, and lawsuits have begun to fly, including one by the Arkansas Carpenters Pension Fund, which owns 4,500 shares of TJX stock.
IT's Reputation: What the Data SaysInformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business really views IT's performance in delivering services - and, more important, powering innovation. Our results suggest IT leaders should worry less about whether they're getting enough resources and more about the relationships they have with business unit peers.
What The Business Really Thinks Of IT: 3 Hard TruthsThey say perception is reality. If so, many in-house IT departments have reason to worry. InformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business views IT's performance in delivering services - and, more important, powering innovation. The news isn't great.
InformationWeek Must Reads Oct. 21, 2014InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.