{"id":698,"date":"2007-09-28T20:18:58","date_gmt":"2007-09-28T20:18:58","guid":{"rendered":"https:\/\/www.darknet.org.uk\/2007\/09\/tjx-tj-maxx-and-marshall%e2%80%99s-largest-breach-of-customer-data-in-us-history\/"},"modified":"2015-09-09T19:39:55","modified_gmt":"2015-09-09T11:39:55","slug":"tjx-tj-maxx-and-marshalls-largest-breach-of-customer-data-in-us-history","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2007\/09\/tjx-tj-maxx-and-marshalls-largest-breach-of-customer-data-in-us-history\/","title":{"rendered":"TJX (T.J. Maxx and Marshall\u2019s) Largest Breach of Customer Data in U.S. History"},"content":{"rendered":"

[ad]<\/p>\n

This case has been going on for a while but obviously hush hush, being that it is the largest breach of customer data in U.S. History. The details of the case have only started emerging in the last couple of months.<\/p>\n

Information Week published a good article covering what has been going on recently.<\/p>\n

Amazing the amount of data we are talking about here, 45 million customer records!<\/p>\n

TJX will be glad when this year is over. The $17 billion-a-year parent company of T.J. Maxx, Marshall\u2019s, and several other discount retail chains has spent the past eight months dealing with the largest breach of customer data in U.S. history, the details of which are starting to come to light.<\/p>\n

Last December, TJX says it alerted law enforcement that data thieves had made off with more than 45 million customer records. Since that time, at least one business, Wal-Mart, has lost millions of dollars as a result of the theft, while TJX has spent more than $20 million investigating the breach, notifying customers, and hiring lawyers to handle dozens of lawsuits from customers and financial institutions. Should TJX lose in the courts, it could be on the hook for millions more in damages.<\/p>\n

But there\u2019s an even broader TJX Effect: The data breach, which actually took place over a period of years, has put the entire retail industry on the defensive and stirred up demands for all businesses that handle payment card information to do a better job of protecting it. Legislators are invoking TJX\u2019s name to fast-track data-security bills.<\/p><\/blockquote>\n

Years? That\u2019s scary, how can something like this happen? I can\u2019t blame the retail industry for being shaken up. Credit card information does need to be safeguarded.<\/p>\n

I hope legislation is approved to hold companies that leak data like water in a sieve, they should be fined some big cash and made to compensate every consumer that was negatively effected by fraudulent use of their credit cards.<\/p>\n

Poorly secured in-store computer kiosks are at least partly to blame for acting as gateways to the company\u2019s IT systems, InformationWeek has learned. According to a source familiar with the investigation who requested anonymity, the kiosks, located in many of TJX\u2019s retail stores, let people apply for jobs electronically but also allowed direct access to the company\u2019s network, as they weren\u2019t protected by firewalls. \u201cThe people who started the breach opened up the back of those terminals and used USB drives to load software onto those terminals,\u201d says the source. In a March filing with the Securities and Exchange Commission,TJX acknowledged finding \u201csuspicious software\u201d on its computer systems.<\/p>\n

The USB drives contained a utility program that let the intruder or intruders take control of these computer kiosks and turn them into remote terminals that connected into TJX\u2019s networks, according to the source. The firewalls on TJX\u2019s main network weren\u2019t set to defend against malicious traffic coming from the kiosks, the source says. Typically, the USB drives in the computer kiosks are used to plug in mice or printers. The kiosks \u201cshouldn\u2019t have been on the corporate LAN, and the USB ports should have been disabled,\u201d the source says.<\/p><\/blockquote>\n

A pretty basic attack eh? Can you believe they were so negligent in setting up the kiosks? They virtually allowed full access to their corporate network!<\/p>\n

Public resources should never have access to the same segments critical data are stored on\u2026this is basic stuff!<\/p>\n

They also owned via open Wifi networks in Marshall\u2019s stores\u2026sad eh?<\/p>\n

<\/p>\n

Source: Information Week<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

[ad] This case has been going on for a while but obviously hush hush, being that it is the largest breach of customer data in U.S. History. The details of the case have only started emerging in the last couple of months. Information Week published a good article covering what has been going on recently. […]<\/p>\n","protected":false},"author":25,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[1,23],"tags":[2373,1203,198,2062,188,2376],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Darknet","author_link":"https:\/\/www.darknet.org.uk\/author\/darknet\/"},"_links":{"self":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/698"}],"collection":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/comments?post=698"}],"version-history":[{"count":0,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/698\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/media?parent=698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/categories?post=698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/tags?post=698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}