T.J. Maxx Probe Reveals Data Breach Worse Than Originally Thought - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


T.J. Maxx Probe Reveals Data Breach Worse Than Originally Thought

The retailer's parent company believes portions of the credit and debit card transactions at its U.S., Puerto Rican, and Canadian stores from January 2003 through June 2004 were compromised.

The theft of customer data from TJX Companies' retail stores is worse than originally thought, the parent company of T.J. Maxx, Marshalls, HomeGoods, and others acknowledged Wednesday in a statement.

An ongoing investigation into the security breach has revealed that, while the company previously believed that the intrusion took place from May 2006 to January 2007, TJX now believes its computer system was maliciously hacked in July 2005 and on various subsequent dates in 2005.

Even worse, the company now believes portions of the credit and debit card transactions at its U.S., Puerto Rican, and Canadian stores -- excluding debit card transactions with cards issued by Canadian banks -- from January 2003 through June 2004 were compromised. TJX, whose assets include 826 T.J. Maxx, 751 Marshalls, and 271 HomeGoods locations, had previously reported that the 2003 transaction data had potentially been accessed.

For most of the transactions from September 2003 through June 2004, some of the card information was masked at the time of the transaction, making that portion unavailable to the intruder, the company said in a statement. Further, names and addresses weren't included with the credit and debit card data believed to have been stolen. Debit card PINs, information from transactions at Bob's Stores, and transactions made with debit cards issued by Canadian banks aren't believed to have been compromised.

This bad news about the data breach comes amidst TJX's report Wednesday of strong financials for fiscal 2007, ended Jan. 27. Revenue for fiscal 2007 was $17. 4 billion, up 9% from the previous fiscal year. Profits for fiscal 2007 were $738 million, up from $690.4 million in fiscal 2006. The earnings, however, included a fourth-quarter charge of 1 cent per share, or about $4.5 million, related to the hack, including the costs to investigate and contain the intrusion, enhance computer security, and communicate with customers. TJX says it learned of the data breach in mid-December but, at the request of law enforcement, didn't make news of the attack public. The company has since hired General Dynamics and IBM to evaluate the intrusion and identify affected data.

"We are dedicating substantial resources to investigating and evaluating the intrusion, which, given the nature of the breach, the size and international scope of our operations, and the complexity of the way credit card transactions are processed, is, by necessity, taking time," TJX CEO and president Carol Meyrowitz said in a statement.

TJX also believes that additional drivers' license numbers, along with the related names and addresses, were compromised for the last four months of 2003 and May and June 2004. TJX collected this information when T.J. Maxx, Marshalls, and HomeGoods customers in the United States and Puerto Rico attempted to make merchandise returns without a receipt. TJX has also likely run afoul of the Payment Card Industry Data Security Standard created by Visa and MasterCard, as a number of documents sent by Visa to financial institutions that issue cards and manage Visa transactions indicate TJX was storing credit and debit card data in violation of the standard.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
1 of 2
Comment  | 
Print  | 
More Insights
2021 State of ITOps and SecOps Report
2021 State of ITOps and SecOps Report
This new report from InformationWeek explores what we've learned over the past year, critical trends around ITOps and SecOps, and where leaders are focusing their time and efforts to support a growing digital economy. Download it today!
InformationWeek Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the InformationWeek site in the coming months.

Becoming a Self-Taught Cybersecurity Pro
Jessica Davis, Senior Editor, Enterprise Apps,  6/9/2021
Ancestry's DevOps Strategy to Control Its CI/CD Pipeline
Joao-Pierre S. Ruth, Senior Writer,  6/4/2021
IT Leadership: 10 Ways to Unleash Enterprise Innovation
Lisa Morgan, Freelance Writer,  6/8/2021
Register for InformationWeek Newsletters
Current Issue
Planning Your Digital Transformation Roadmap
Download this report to learn about the latest technologies and best practices or ensuring a successful transition from outdated business transformation tactics.
White Papers
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll