Contributors

Jeremiah Grossman
(WhiteHat Security)

Ofer Shezaf
(Breach Security ) [Project Leader]

The Web Hacking Incidents Database
Last update:07 November 2007

Incident WHID 2007-02


WHID 2007-02: Massive Security Breach Reveals Credit Card Data at TJX
Date: 18 January 2007
Incident Type: Security Breach
WASC Threat Classification: Unknown

A massive security breach, estimated to be the largest in history, has been discovered at TJX companies, a major US retail chain operating chains such as such as Bob's Stores, HomeGoods, Marshalls, T.J. Maxx and A.J. Wright. The extent of the breach is still unclear but the hack may have started as early as July 2005 and information stolen is from as early as 2003 and up until the discovery at December 2006. Apart from credit card and debit card numbers driver license numbers were also stolen.

As of today a single arrest was done in this case in Florida, in which 5 people were arrested for using the stolen information to steal $8 million. The arrested people are believed to have bought the information and are probably not the hackers.

Information regarding the method used to hack TJX computers is still not available.

References:




This work is licensed under the Creative Commons Attribution License. To view a copy of this license, visit http://creativecommons.org/licenses/by/2.5/ or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA.

© Copyright 2005, Web Application Security Consortium. All rights reserved.