Originally published February 22, 2007 at 12:00 AM | Page modified February 22, 2007 at 12:58 AM
Retailer's data breach wider than believed
Retail giant TJX, whose stores include discount clothing chains T. J. Maxx and Marshalls, said Wednesday a computer-security breach stretched...
The Washington Post
WASHINGTON — Retail giant TJX, whose stores include discount clothing chains T.J. Maxx and Marshalls, said Wednesday a computer-security breach stretched back 10 months earlier than it had originally thought, compromising credit- and debit-card data, driver's license numbers, and names and addresses.
The announcement underscores a trend of breaches involving sensitive credit-card data and reflects failures to properly secure computer systems, to notify customers when breaches occur and to update laws for the cybercrime age, lawmakers and analysts said.
T.J. Maxx and Marshalls each have seven locations in the Seattle-Tacoma metropolitan area.
TJX said that while it first thought the intrusion took place from May 2006 to January 2007, it now thinks its computer system was also hacked in July 2005 and on "various subsequent dates" in that year.
The company first reported the intrusion in January, a month after it said it discovered the breach.
It has refused to say how many customers may have been affected and how many have been notified.
"We don't have a number for you there. Our work is not finished," spokeswoman Sherry Lang said Wednesday.
More than 50 computer experts are helping investigate the breaches, she said.
Banks that issued the credit cards have not said how much they have had to cover in fraud-related losses.
More than 30 states, including Washington, have laws that require companies to notify customers as soon as possible when a breach has occurred, although most of the statutes allow companies to delay notification while law-enforcement agencies investigate.
A bipartisan group of senators had reintroduced legislation that would mandate customer notification and require companies that maintain personal information to establish internal policies to protect it.
"Americans live in a world where their most sensitive personal information can be accessed and sold to the highest bidder, with just a few keystrokes on a computer, yet our privacy laws haven't kept pace," Sen. Patrick Leahy, D-Vt., said in a written statement when the legislation was reintroduced this month.
![]()
The credit-card industry has set up rules for data protection called the Payment Card Industry Data Security Standard.
They include encrypting transmission of cardholder data, regularly testing security systems and processes, and restricting access to data to those with a "need to know."
But most large retailers have not complied with the standard, and noncompliance is about 80 percent among smaller retailers, said Avivah Litan, an analyst with Gartner, an information-technology research firm.
Copyright © The Seattle Times Company
FBI denounces rumors: Palin not investigated
Biden: Israel free to set own course on Iran
Obama warns of 'difficult' days in Iraq, pledges support for troops
Top Iran clerics decry election, defy supreme leader
NEW - 07:00 PM
Honduran military told to turn back Zelaya's jet

2009 fireworks time lapse
With strict parking rules enforced at this year's July 4th celebration on Wallingford Ave North, less cars and more spectators filled the streets.
Entertainment | Top Video | World | Offbeat Video | Sci-Tech
- Plasma and LCD beware; OLED screens ready to go mainstream
- Landmark Smith Tower mostly vacant
- Former NFL MVP McNair killed
- Russell Branyan, Mariners fight off the Red Sox
- Property taxes: Appeals shoot up in King, Snohomish Counties
- Palin takes to Web for hints of political future
- Fourth of July festivals and fireworks in Seattle, the suburbs and beyond
- Palin links resignation to 'higher calling' and blasts media in Facebook posting
- Hard times for tourist towns means good deals for travelers
- The Blotter | Man pistol-whipped after argument at nightclub
- Palin resigning as Alaska governor
785 - Seattle Mariners at Boston Red Sox: 07/05 game thread
247 - Palin links resignation to 'higher calling' and blasts media in Facebook posting
162 - Hatred for the NBA runs deep, but don't take it out on the players
130 - Tukwila residents rally against light-rail noise
118 - Former NFL MVP McNair killed
112 - Property taxes: Appeals shoot up is King, Snohomish Counties
103 - Tent City on campus: UW stalls decision
94 - Anti-tax rally in Olympia attracts about 1,500
63 - Seeking your questions
49
- Plasma and LCD beware; OLED screens ready to go mainstream
- Property taxes: Appeals shoot up in King, Snohomish Counties
- Merchant Marine veterans fight for recognition
- Hard times for tourist towns means good deals for travelers
- Landmark Smith Tower mostly vacant
- Close-up | Prison guards intercept carrier pigeon with a cellphone
- Amtrak cleared for 2nd daily train to Vancouver, B.C.
- Tent City on campus: UW stalls decision
- Pre-grill drill: marinate steaks
- Concert Review | Green Day blasts off 4th weekend with KeyArena show

