An ongoing investigation into the security breach has revealed that, while the company previously believed that the intrusion took place from May 2006 to January 2007, TJX now believes its computer system was maliciously hacked in July 2005 and on various subsequent dates in 2005.
Even worse, the company now believes portions of the credit and debit card transactions at its U.S., Puerto Rican, and Canadian stores -- excluding debit card transactions with cards issued by Canadian banks -- from January 2003 through June 2004 were compromised. TJX, whose assets include 826 T.J. Maxx, 751 Marshalls, and 271 HomeGoods locations, had previously reported that the 2003 transaction data had potentially been accessed.
For most of the transactions from September 2003 through June 2004, some of the card information was masked at the time of the transaction, making that portion unavailable to the intruder, the company said in a statement. Further, names and addresses weren't included with the credit and debit card data believed to have been stolen. Debit card PINs, information from transactions at Bob's Stores, and transactions made with debit cards issued by Canadian banks aren't believed to have been compromised.
This bad news about the data breach comes amidst TJX's report Wednesday of strong financials for fiscal 2007, ended Jan. 27. Revenue for fiscal 2007 was $17. 4 billion, up 9% from the previous fiscal year. Profits for fiscal 2007 were $738 million, up from $690.4 million in fiscal 2006. The earnings, however, included a fourth-quarter charge of 1 cent per share, or about $4.5 million, related to the hack, including the costs to investigate and contain the intrusion, enhance computer security, and communicate with customers. TJX says it learned of the data breach in mid-December but, at the request of law enforcement, didn't make news of the attack public. The company has since hired General Dynamics and IBM to evaluate the intrusion and identify affected data.
"We are dedicating substantial resources to investigating and evaluating the intrusion, which, given the nature of the breach, the size and international scope of our operations, and the complexity of the way credit card transactions are processed, is, by necessity, taking time," TJX CEO and president Carol Meyrowitz said in a statement.
TJX also believes that additional drivers' license numbers, along with the related names and addresses, were compromised for the last four months of 2003 and May and June 2004. TJX collected this information when T.J. Maxx, Marshalls, and HomeGoods customers in the United States and Puerto Rico attempted to make merchandise returns without a receipt. TJX has also likely run afoul of the Payment Card Industry Data Security Standard created by Visa and MasterCard, as a number of documents sent by Visa to financial institutions that issue cards and manage Visa transactions indicate TJX was storing credit and debit card data in violation of the standard.
How Enterprises Are Attacking the IT Security EnterpriseTo learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Infographic: The State of DevOps in 2017Is DevOps helping organizations reduce costs and time-to-market for software releases? What's getting in the way of DevOps adoption? Find out in this InformationWeek and Interop ITX infographic on the state of DevOps in 2017.
2017 State of IT ReportIn today's technology-driven world, "innovation" has become a basic expectation. IT leaders are tasked with making technical magic, improving customer experience, and boosting the bottom line -- yet often without any increase to the IT budget. How are organizations striking the balance between new initiatives and cost control? Download our report to learn about the biggest challenges and how savvy IT executives are overcoming them.