Jonathan Richards
Download 'Too Hot', an exclusive Specials track from iTunes
TJX, the US retailer that owns the TK Maxx stores, revealed today that 45.7 million credit and debit card numbers had been stolen from its computer systems.
British and US police are investigating the theft, which took place over an 18-month period, and is believed to be the biggest card heist on record.
It affects purchases going back to December 2002, including some made by British customers at the company's 210 UK stores, for which details were stored on a system in Watford.
Read the SEC filing here.
TJX said that it did not know now many British customers had been affected, or the extent of any fraud arising out of the stolen information, but that banks with which it has contracts had indicated that they had "preliminary evidence of possible fraudulent misuse" of the card details.
The Metropolitan Police, the Information Commissioner's Office and Visa Europe have all received intelligence on the theft, which is understood to have happened in the US and involved the thieves hacking into TJX's US and UK computer systems.
In a filing with the Securities and Exchange Commission, TJX said that its systems were first infiltrated in July 2005, and that the unauthorised access continued over an 18-month period.
The filing said another 455,000 customers who returned merchandise without receipts, and so had to provide personal data such as driving license numbers, had these details stolen as well.
TJX first discovered that there was suspicious software on its system in December and revealed it suspected numbers had been stolen in January, but has only today provided details of the full extent of the theft. It said it still knows little about the full scope of the breach, in part because the hacker or hackers accessed TJX’s encryption software and could have known how to unscramble the information.
In addition, TJX deleted much of the transaction data in the normal course of business between the time of the breach and the time that TJX detected it, making it impossible to know how many total cards were affected.
TJX says its computer systems were first breached in July 2005 by a hacker or hackers who accessed information from customer transactions dating to January 2003.
Police charged six people in Florida last week with using credit card numbers that investigators believe were stolen from a TJX database to buy about $1 million in merchandise with gift cards. These numbers may have been bought from the original hackers.
TJX is facing an investigation by the Federal Trade Commission and lawsuits from individuals and banks accusing it of failing to do enough to safeguard private data and of delaying disclosure of the problem.
Articles from our sister site WSJ.com:
You may be asked to subscribe to read certain articles
Win a luxury weekend to Newcastle and its neighbour Gateshead, find out more here
Risk, resilience and embracing new technology
Industry sectors news at a glance. Interactive heatmap, video and podcast
Discover the power of collective thinking. Submit a solution and be in with a chance to win a Media Hub Home Entertainment System
The inside track on current trends in the charity, not for profit and social enterprise sectors
Everything the Business Traveller needs to know to make a better trip
Make the most of the summer and enter our fabulous photographic competition, you could win a £5000 holiday
Corsica is an island of beauty and contrast, an ideal holiday destination
Enjoy further reading from Travel to Fashion, Business to Sport, discover more
Shortcuts to help you find sections and articles
The clever way to lease a new car is with Car leasing made simple™
2009
per month on 36-month
Personal Contract Hire (PCH)
2008
42850
Car Insurance
£24,250 - £30,346
MI5
London
£60,000
The Environment Agency
Bristol
Up to £90K
Boots
Midlands
OTE £85k
Credit Protection Association
Nationwide Opportunities
Completely London
Luxury Condo's in Manhattan with NYC views
The best new homes in Wimbledon?
Nationwide
Fabulous Cruise And Cruise & Stay Offers Including Virgin Atlantic Flights Prices Start From Only £699pp!
Last Minute Cruise And Cruise & Stay Offers. Med From £499pp, Caribbean From £699pp!
5 star quality at a 3 star price.
8 fabulous Canadian cities ...you won’t find cheaper
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths | Subscriptions | E-paper
News International associated websites: Globrix Property Search | Property Finder | Milkround
Copyright 2009 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
They have for a number of years collected data on postcodes of UK customers as part of "their customer service". One wonders if this too has been stolen. Why have they been holding credit card data for this period of time?
John, Leeds, UK
That;s a mind boggling security lapse. Systems like that should be locked down and all ports closed not essential for transacting business; then those ports should be monitored for all traffic. I trust the security manager has been sacked. I would also hazard its been an inside job.
Neil Murphy, cromer,
Is there any particular reason TKX need to hold credit and debit card details for such a long period of time? They're just sitting ducks holding 45 million card details.
Matt, Manchester,
This article suggests that TJX used encryption software.
Many of the articles in US publications over the past year suggest that they didn't.
If they didn't, then they are negligent.
If they did, then we have a problem. For security purposes, our ePassports (and ID cards) here in the UK rely on (and will rely on, if we ever get ID cards) encryption software.
If it doesn't work, then the theft of 45.7m sets of ID data would just about clear out the UK.
So, note to editors. Did TJX use encryption software, yes or no? And if so, which encryption software? We don't want to use that supplier for our ePassports and ID cards.
David Moss, London, UK
In the US, TJ MAxx asks customers for their home address and phone number after every sale, which I've always considered an oddity amd not right. Why they do it is beyond me.
Jack Lee, Austin, TX USA
I hope that TK Maxx get prosecuted under the Data Protection Act.
Michael Cawood, Wrexham, Wales, UK
Only of online crime?
bill, bristol, UK