Breach report
RetailTJX Companies (T.J. Maxx, Marshalls)
TJX breach could top 94 million accounts
Hackers who first slipped in through a poorly secured store Wi-Fi network spent roughly 18 months stealing card data from T.J. Maxx parent TJX, a breach court filings later put at 94 million accounts, then the largest ever disclosed.
Reported by NBC News
Records exposed
94M
At least 94 million payment card accounts
Scale vs. largest on file
- When
- 2005–2007 (disclosed 2007)
- How they got in
- Wireless network intrusion (weak WEP Wi-Fi encryption at stores)
- Sector
- Retail
In January 2007, TJX Companies, the Massachusetts-based parent of discount chains T.J. Maxx and Marshalls, announced that hackers had broken into the computer systems that processed and stored customer transactions. In a March 2007 regulatory filing, the retailer said at least 45.7 million credit and debit card numbers had been stolen over a period of about 18 months beginning in mid-2005. By October 2007, court filings by banks suing the company put the number of affected Visa and MasterCard accounts at roughly 94 million, more than double TJX's own estimate and a record at the time.
Investigators determined that the attackers first gained access by exploiting weak wireless security at stores, including one in Minnesota, where networks relied on the outdated WEP encryption standard that could be cracked in minutes. From there, the intruders worked their way into central servers, installed tools to capture card data as it was processed and siphoned information over many months. In addition to card data, some records included driver's license numbers and addresses from customers who had returned merchandise without receipts.
The investigation led to one of the most prominent cybercrime prosecutions of the decade. Federal prosecutors charged Albert Gonzalez, a former Secret Service informant, as the ringleader of a group that also targeted other retailers, including BJ's Wholesale Club, OfficeMax and DSW. Gonzalez pleaded guilty and was sentenced in 2010 to 20 years in prison, then among the longest sentences ever handed down for computer crime in the United States.
TJX faced lawsuits from banks, consumers and state regulators. It reached settlements with Visa and MasterCard to reimburse card issuers, agreed to an FTC order requiring a comprehensive security program with outside audits for 20 years, and in 2009 paid $9.75 million to settle investigations by 41 states. The company's total breach-related costs ran into the hundreds of millions of dollars, making it an early benchmark for the financial toll of data theft.
The TJX breach is widely credited with accelerating adoption of the Payment Card Industry Data Security Standard and exposing the dangers of storing card data longer than necessary. It demonstrated that a single weak entry point in a store's wireless network could compromise a national retailer. Many of the security failures it exposed, including weak encryption, flat networks and excessive data retention, would recur in the retail breaches that followed, including Target and Home Depot.