Originally published February 22, 2007 at 12:00 AM | Page modified February 22, 2007 at 12:58 AM
Retailer's data breach wider than believed
Retail giant TJX, whose stores include discount clothing chains T. J. Maxx and Marshalls, said Wednesday a computer-security breach stretched...
The Washington Post
WASHINGTON — Retail giant TJX, whose stores include discount clothing chains T.J. Maxx and Marshalls, said Wednesday a computer-security breach stretched back 10 months earlier than it had originally thought, compromising credit- and debit-card data, driver's license numbers, and names and addresses.
The announcement underscores a trend of breaches involving sensitive credit-card data and reflects failures to properly secure computer systems, to notify customers when breaches occur and to update laws for the cybercrime age, lawmakers and analysts said.
T.J. Maxx and Marshalls each have seven locations in the Seattle-Tacoma metropolitan area.
TJX said that while it first thought the intrusion took place from May 2006 to January 2007, it now thinks its computer system was also hacked in July 2005 and on "various subsequent dates" in that year.
The company first reported the intrusion in January, a month after it said it discovered the breach.
It has refused to say how many customers may have been affected and how many have been notified.
"We don't have a number for you there. Our work is not finished," spokeswoman Sherry Lang said Wednesday.
More than 50 computer experts are helping investigate the breaches, she said.
Banks that issued the credit cards have not said how much they have had to cover in fraud-related losses.
More than 30 states, including Washington, have laws that require companies to notify customers as soon as possible when a breach has occurred, although most of the statutes allow companies to delay notification while law-enforcement agencies investigate.
A bipartisan group of senators had reintroduced legislation that would mandate customer notification and require companies that maintain personal information to establish internal policies to protect it.
"Americans live in a world where their most sensitive personal information can be accessed and sold to the highest bidder, with just a few keystrokes on a computer, yet our privacy laws haven't kept pace," Sen. Patrick Leahy, D-Vt., said in a written statement when the legislation was reintroduced this month.
![]()
The credit-card industry has set up rules for data protection called the Payment Card Industry Data Security Standard.
They include encrypting transmission of cardholder data, regularly testing security systems and processes, and restricting access to data to those with a "need to know."
But most large retailers have not complied with the standard, and noncompliance is about 80 percent among smaller retailers, said Avivah Litan, an analyst with Gartner, an information-technology research firm.
Copyright © The Seattle Times Company
UPDATE - 03:28 AM
Sources: Obama near decision on Afghanistan troops
UPDATE - 03:29 AM
Bill Clinton meets with Senate Dems on health care
FBI reassessing past look at Fort Hood suspect
D.C. sniper mastermind set to be executed Tuesday
Case against Ohio bodies suspect expands overseas

Ken Auletta talks about "Googled"
Ken Auletta talks about Google with Brier Dudley at the Seattle Central Library.
nwjobs

Post a comment

Michelle Goodman blogs about work/life balance.
How to tell your office you're gravely ill
Post a comment
nwautos

Choosing a new sedan? Weigh the impact of your choice on your wallet and on the planet.
Post a comment
- 'Missing' SeaTac man found with new name, in new state
- Police: DNA from officer's slaying matches suspect
- Prosecutors consider charges against suspect in police shooting
- Three more fires ignite in Greenwood
- Steve Kelley | Hasselbeck gives Seahawks' sagging season a stay of execution
- Plans call for Triangle to become West Seattle gateway
- Bill Clinton meets with Senate Dems on health care
- Trucker dies as big-rig plummets off SF bridge
- McGinn next Seattle mayor; Mallahan concedes as vote gap widens
- Washington coordinator Nick Holt says his Huskies defense is improving
- Prosecutors prepare charges against suspect in police shooting
258 - House health bill unacceptable to many in Senate
246 - Pelosi tours Seattle's Swedish after health-care vote
171 - Prosecutors prepare charges against suspect in police shooting
143 - Alleged shooter tied to mosque of 9/11 hijackers
135 - Obama puts heat on Senate to speed health bill
123 - Resolute Fort Hood soldiers ready for return
119 - McGinn more than doubles his lead over Mallahan
99 - Cutaia says replay handled properly on Austin TD
69 - Josh Smith picks UCLA
69
- For 80-year-old Maple Valley man, hoops aren't just a dream
- Plans call for Triangle to become West Seattle gateway
- Three more fires ignite in Greenwood
- 'Missing' SeaTac man found with new name, in new state
- Pakistani-American cafe, bar owner on verge of being Granite Falls mayor
- Silver Lake restaurant destroyed by fire
- All You Can Eat | Fruit flies: thrill to the kill
- Taste | Ruth Reichl still reigns as queen of America's culinary scene
- Police: DNA from officer's slaying matches suspect
- Book review | Ayn Rand: goddess of the market, gateway to the American right





