Originally published February 22, 2007 at 12:00 AM | Page modified February 22, 2007 at 12:58 AM
Retailer's data breach wider than believed
Retail giant TJX, whose stores include discount clothing chains T. J. Maxx and Marshalls, said Wednesday a computer-security breach stretched...
The Washington Post
WASHINGTON — Retail giant TJX, whose stores include discount clothing chains T.J. Maxx and Marshalls, said Wednesday a computer-security breach stretched back 10 months earlier than it had originally thought, compromising credit- and debit-card data, driver's license numbers, and names and addresses.
The announcement underscores a trend of breaches involving sensitive credit-card data and reflects failures to properly secure computer systems, to notify customers when breaches occur and to update laws for the cybercrime age, lawmakers and analysts said.
T.J. Maxx and Marshalls each have seven locations in the Seattle-Tacoma metropolitan area.
TJX said that while it first thought the intrusion took place from May 2006 to January 2007, it now thinks its computer system was also hacked in July 2005 and on "various subsequent dates" in that year.
The company first reported the intrusion in January, a month after it said it discovered the breach.
It has refused to say how many customers may have been affected and how many have been notified.
"We don't have a number for you there. Our work is not finished," spokeswoman Sherry Lang said Wednesday.
More than 50 computer experts are helping investigate the breaches, she said.
Banks that issued the credit cards have not said how much they have had to cover in fraud-related losses.
More than 30 states, including Washington, have laws that require companies to notify customers as soon as possible when a breach has occurred, although most of the statutes allow companies to delay notification while law-enforcement agencies investigate.
A bipartisan group of senators had reintroduced legislation that would mandate customer notification and require companies that maintain personal information to establish internal policies to protect it.
"Americans live in a world where their most sensitive personal information can be accessed and sold to the highest bidder, with just a few keystrokes on a computer, yet our privacy laws haven't kept pace," Sen. Patrick Leahy, D-Vt., said in a written statement when the legislation was reintroduced this month.
![]()
The credit-card industry has set up rules for data protection called the Payment Card Industry Data Security Standard.
They include encrypting transmission of cardholder data, regularly testing security systems and processes, and restricting access to data to those with a "need to know."
But most large retailers have not complied with the standard, and noncompliance is about 80 percent among smaller retailers, said Avivah Litan, an analyst with Gartner, an information-technology research firm.
Copyright © The Seattle Times Company
Senate Democrats split on health bill's fate
UPDATE - 06:32 PM
SC gov faces 37 charges he broke state ethics laws
U.K. started planning early for war, leaked papers show
Vaccine to kill nicotine buzz now in late tests by small drug firm
India's feeling bruised even before White House visit

PNW Magazine | Easy As Pie
A little friendly competition between professional pie-baker Kate McDermott and The Seatttle Times' Kathleen Triesch Saul is handled with great taste.
general classifieds
Garage & estate salesFurniture & home furnishings
Sporting goods
just listed
42" Hitachi Plasma 1080i - $500
8 Drawer Dresser with Attached Mirror - $200
8 seat pecon formal dining table and china hutch - $1500
More listings
POST A FREE LISTING
shopping
Give yourself a treat and visit Watson Kennedy's Holiday Open Houses
More minding the store
events for Monday, Nov. 23
- Amy Bengtson Holiday Trunk Show
- Metropolitan Pilates Pre-Thanksgiving Sale
- Castle Discount with Military ID
- Sur La Table November sale
editors' picks
- Spas & beauty salons
- Vintage, consignment and used clothing
- Phinney Ridge & Greenwood shopping
- Independent video stores
- 'The Road' takes Viggo Mortensen to Mount St. Helens and Astoria, Ore.
- Tugboat sinks at Seattle waterfront pier
- Illegal workers quietly let go
- Child-support error costs nearly $21,000
- Vikings easily beat the Seahawks
- Craigslist adoption ad: A plea by young mother-to-be? A scam?
- Chase shrugs off loss of CD investors
- Woman stabbed by stranger in North Seattle
- Snow piles up on Cascade slopes
- Denny Triangle gains skyline, but tenants slow to come
- Illegal workers quietly let go
383 - Climate change speeds up since 1997 Kyoto accord
210 - Metro won't cut bus service after all
159 - New Husky recruit: Enes Kanter
101 - Historic health care bill clears Senate hurdle
96 - Tattoos at Mill Creek Church pierce skin, soul
85 - Middleton says Huskies "plan on scoring at least 50 points'' Saturday
82 - Jerry Brewer: Seahawks can't lean on the Hutch Crutch now
74 - Seattle woman charged with knife attack on boyfriend's ex
70 - UW, WSU once again meet to see who's worse
68
- Sprouts, raw fish on attorney's 'do not eat' list
- Tattoos at Mill Creek church pierce skin, soul
- Food-safety lawyer's wish: Put me out of business
- Illegal workers quietly let go
- Architects, chefs find 'kid' within to build Gingerbread Village
- Rediscovering Moab, 'the most beautiful place on Earth'
- It's possible to recover a life lost to hoarding
- Child-support error costs nearly $21,000
- 'The Road' takes Viggo Mortensen to Mount St. Helens and Astoria, Ore.
- Taste | The Great Pie Bake-off pits friends and fruit

