Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

TJX Says 45.7M Card Numbers Stolen
Associated Press ^ | Wed Mar 28, 10:25 PM | A/P

Posted on 03/29/2007 4:05:32 AM PDT by mmanager

BOSTON - At least 45.7 million credit and debit card numbers of TJX Cos. customers were stolen from the discount retailer's computer system over several years, according to a regulatory filing by the company Wednesday.

The filing with the Securities and Exchange Commission gave the first detailed account of the breach that the company initially disclosed in January.

It also said another 455,000 customers who returned merchandise without receipts had their personal data stolen, including driver's license numbers.

TJX owns T.J. Maxx, Marshall's and other stores in North America and the United Kingdom.

TJX spokeswoman Sherry Lang did not immediately return a telephone message from The Associated Press seeking comment late Wednesday.

But Lang told The Boston Globe, which first reported the filing Wednesday night, that about 75 percent of the compromised cards either were expired or had data in the magnetic stripe masked, meaning the data was stored as asterisks, rather than numbers.

Lang said the extent of the damage may never be known because of the methods used by the intruder as well as file deletions made by TJX in the normal course of business.

"There's a lot we may never know and it's one of the difficulties of this investigation," Lang said. "It's why this has taken this long and why it's been so tedious. It's painstaking."

Avivah Litan, vice president of research and advisory company Gartner Inc., told the Globe the TJX breach is "the biggest card heist ever."

"This was obviously done over a long period of time, in many locations," she said. "It's done considerable damage."

Police charged six people in Florida last week with using credit card numbers stolen from a TJX database to buy about $1 million in merchandise with gift cards.

In Wednesday's filing, TJX said for the first time that Dec. 18, 2006, was the date it first learned that there was suspicious software on its computer system.

TJX said it believes hackers invaded its systems in July 2005, on later dates in 2005 and also from mid-May 2006 to mid-January 2007. The company said no customer information was stolen after Dec. 18, one day before it hired General Dynamics Corp. and IBM Corp. to investigate. By Dec. 21, those investigators determined that the computer systems had been intruded and that an intruder remained on the systems.

TJX said it notified federal authorities Dec. 22, and on Jan. 3, TJX officials and Secret Service agents met with banks and payment card and check processing companies to discuss the computer intrusion.

Framingham-based TJX is facing an investigation by the Federal Trade Commission and lawsuits from individuals and banks accusing it of failing to do enough to safeguard private data and of delaying disclosure of the problem.


TOPICS: Crime/Corruption
KEYWORDS:
Go back to writing checks?
1 posted on 03/29/2007 4:05:33 AM PDT by mmanager
[ Post Reply | Private Reply | View Replies]

To: mmanager

Or using good old fashioned cash?


2 posted on 03/29/2007 4:49:33 AM PDT by july4thfreedomfoundation (My Number One Goal in Life is to Leave a Bigger Carbon Foot Print Than Al Gore)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmanager

I had somebody from Mexico try to charge my Debit/Check Card for $347 the other week. I racked my brain thinking of where they could of gotten the card number. That same day before the charge I had updated my iTunes account. Otherwise there were a couple of places that I don't normally go to(gas stations and such). Online wise I didn't go to any abnormal places. So since then I have done mostly cash transactions.


3 posted on 03/29/2007 4:55:47 AM PDT by neb52
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmanager

My dad always said cash is king. Maybe he was right.


4 posted on 03/29/2007 4:57:27 AM PDT by LIConFem (Fred Thompson 2008. Lifetime ACU Rating: 86 -- Duncan Hunter 2008 (VP) ACUR: 92)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmanager
Never been in a tjx or whatever, so no problem!
5 posted on 03/29/2007 5:16:23 AM PDT by org.whodat (Never let the facts get in the way of a good assumption.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmanager
Lang said the extent of the damage may never be known because of the methods used by the intruder as well as file deletions made by TJX in the normal course of business.

Whew, that's a relief. I'm sure it's nothing but a coincidence anyway.
Chronology of Data Breaches

6 posted on 03/31/2007 10:23:59 AM PDT by Chief_Joe (From where the sun now sits, I will fight on -FOREVER!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson