
Intrusion fallout continues...
By Steve Ranger
Published: 30 March 2007 14:47 GMT
Shoppers who have used their credit and debit cards in high street retailer TK Maxx are being urged to review their statements after it was revealed hackers may have stolen details of 45 million payment cards from the retailer's US parent company.
TJX - which operates the TK Maxx chain in the UK - revealed it has suffered "an unauthorised intrusion or intrusions" into the systems that process and store information related to customer transactions.
It said the intrusion affected the portion of TJX's computer system that handles most of credit card, debit card, cheque and merchandise return transactions for most of its stores in Canada, Puerto Rico and the US, along with a portion of its computer system in the UK that handles credit and debit card transactions for stores in the UK and Ireland.
It said the systems were first accessed by intruders in July 2005, and then on subsequent dates in 2005, and from mid-May 2006 to mid-January 2007. But the company said no customer data was stolen after 18 December 2006.
The company said in warning on its website: "We do not know who the intruder was, whether there was one or more intruders, or whether there was one or separate intrusions," the company said but warned that credit and debit card transactions at TK Maxx stores in the UK and Ireland could have been affected.
It added: "If any unauthorised or suspicious card use is detected, please contact the credit card issuer or bank immediately."
The company said it does not know whether any fraudulent use of the data has occurred.
It has strengthened the security of its computer systems and TJX president and CEO, Carol Meyrowitz, said: "We believe customers should feel safe shopping in our stores."
TJX said it learned of "suspicious software" on its computer systems on 18 December last year and, following an investigation, notified law enforcement on 22 December. It wasn't until 27 December that the company "learned that any customer data apparently had been stolen", it said.
It added in a statement: "The credit and debit card information that we believe was stolen does not include customer names and addresses, only numerical card information."
You will have recent experience of working within Bank that issues cards on a First Data platform, as well as developing in-house SQL routines to ...
The Credit Cards Risk Analytics team is part of the Impairment and Capital team. A leading retail banking organisation, based in London (WC) ...
This role offers a fantastic chance to help shape the future of the cards business, with good career development prospects leading to more senior ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business