Data Theft Believed to Be Biggest Hack

Business Law

A hacker or hackers stole data from at least 45.7 million credit and debit cards of shoppers at off-price retailers including T.J. Maxx and Marshalls in a case believed to be the largest such breach of consumer information.

For the first time since disclosing the theft more than two months ago, the parent company of nearly 2,500 discount stores put a number on how much card data was compromised _ and it's a number TJX Cos. acknowledges could go still higher.

Experts say TJX's disclosures in a regulatory filing late Wednesday revealed security holes that persist at many firms entrusted with consumer data: failure to promptly delete data on customer transactions, and to guard secrets about how such data is protected through encryption.

"It's not clear when information was deleted, it's not clear who had access to what, and it's not clear whether the data kept in all these files was encrypted, so it's very hard to know how big this was," said Deepak Taneja, chief executive of Aveksa, a Waltham, Mass.-based firm that advises companies on information security.

The case has led banks to reissue cards to customers as a precaution against further fraud beyond cases detected as far away as Sweden and Hong Kong, according to the Massachussets Bankers Association, which is tracking fraud reports linked to Framingham, Mass.-based TJX, parent company of stores across North America and the United Kingdom.

The only arrests believed tied to the case involve a gift card scam in which 10 people are suspected of buying data from the TJX hackers to purchase Wal-Mart gift cards in northern Florida. The group _ who aren't believed to have committed the TJX hack _ then used the cards to buy $1 million worth of electronics and jewelry at Wal-Mart's Sam's Club stores, according to Gainesville, Fla., police.

Information from 45.7 million cards was stolen from transactions beginning in January 2003 and ending Nov. 23 of that year, TJX said in the filing with the Securities and Exchange Commission after business hours Wednesday. TJX did not estimate the number of cards from which information was stolen for transactions occurring from Nov. 24, 2003, to June 28, 2004.

TJX said about three-quarters of the 45.7 million cards had either expired at the time of the theft, or the stolen information didn't include security code data from the cards' magnetic stripes. Starting in September 2003, TJX began masking the codes by storing them in computers as asterisks rather than numbers, the company said.

The filing also said another 455,000 customers who returned merchandise without receipts had their data stolen, including driver's license numbers.

With at least 46 million consumer records accessed, the TJX case outranks the previous largest case tracked by the Privacy Rights Clearinghouse: a June 2005 disclosure by credit card processor CardSystems that hackers accessed accounts of 40 million card holders.

Related listings

  • Investors Continue to Challenge Dean Food

    Investors Continue to Challenge Dean Food

    Business Law 03/26/2007

    [##_1L|1206532251.jpg|width="90" height="119" alt=""|_##]Socially concerned investors for the second year in a row have filed a shareholder proposal asking Dean Foods Co. (NYSE: DF) to report to shareholders how it is responding to widespread concern...

  • Recall of pet food hits close to home

    Recall of pet food hits close to home

    Business Law 03/19/2007

    More than 60 million cans of dog and cat food sold under dozens of brand names were recalled on Saturday after being linked to the deaths of 10 animals.The food was manufactured by Menu Foods, of Streetsville, Ontario, which makes wet food sold as st...

  • Downtown Los Angeles Revival Going Strong

    Downtown Los Angeles Revival Going Strong

    Business Law 02/14/2007

    Downtown Los Angeles is undergoing a real estate revival of epic proportions. And the Los Angeles Urban Redevelopment Group and its people are in the thick of it. In just the last few years, the number of downtown residents has increased by over 30%,...

Illinois Work Injury Lawyers – Krol, Bongiorno & Given, LTD.

Accidents in the workplace are often caused by unsafe work conditions arising from ignoring safety rules, overlooking maintenance or other negligence of those in management. While we are one of the largest firms in Illinois dedicated solely to the representation of injured workers, we pride ourselves on the personal, one-on-one approach we deliver to each client.

Work accidents can cause serious injuries and sometimes permanent damage. Some extremely serious work injuries can permanently hinder a person’s ability to get around and continue their daily duties. Factors that affect one’s quality of life such as place of work, relationships with friends and family, and social standing can all be taken away quickly by a work injury. Although, you may not be able to recover all of your losses, you may be entitled to compensation as a result of your work injury. Krol, Bongiorno & Given, LTD. provides informed advocacy in all kinds of workers’ compensation claims, including:

• Injuries to the back and neck, including severe spinal cord injuries
• Serious head injuries
• Heart problems resulting from workplace activities
• Injuries to the knees, elbows, shoulders and other joints
• Injuries caused by repetitive movements

For Illinois Workers’ Compensation claims, you will ALWAYS cheat yourself if you do not hire an experienced attorney. When you hire Krol, Bongiorno & Given, Ltd, you will have someone to guide you through the process, and when it is time to settle, we will add value to your case IN EXCESS of our fee. In the last few years, employers and insurance carriers have sought to advance the argument that when you settle a case without an attorney, your already low settlement should be further reduced by 20% so that you do not get a “windfall.” Representing yourself in Illinois is a lose-lose proposition.

Business News

St Peters, MO Professional License Attorney Attorney John Lynch has been the go-to choice for many professionals facing administrative sanction. >> read