- http://www.securityfocus.com/news/11438
2007-01-26 ~ "Banks and retailers in the United States and Canada have begun to report an increasing amount of illicit transactions thought to be linked to the server breach announced last week by the TJX Companies, the commercial giant that owns retail chains in the U.S., Canada and Europe. More than 60 of the 205 banks in Massachusetts have begun reissuing cards after being contacted by credit-card companies about compromised cards, the Massachusetts Bankers Association stated this week. However, only half of the state's banks have reported in to the group. The transactions have occurred in at least three states–as well as Hong Kong and Sweden, the MBA said in statement… "It is critical that the card associations–Visa, Mastercard, etc.–and public officials carefully evaluate whether the source of the breach should be identified quickly and be held liable for a data breach, particularly if the information being stored is in violation of card-network rules," Forte stated, noting that banks typically shoulder the burden of paying for replacement cards…"
TJX stolen data used in Florida crime spree
- http://preview.tinyurl.com/2yhpup
March 21, 2007 ~ "Law enforcement officials in Florida have arrested six individuals suspected of carrying out a fraud scheme built around the misuse of credit card data stolen from retailer TJX Companies. In partnership with the Gainesville Police Department, officials from the Florida Department of Law Enforcement said they have taken six of 10 suspects into custody for allegedly using the TJX customer data to purchase large quantities of gift cards from discount chains Wal-Mart and Sam's Club. The series of arrests marks the first specific instance of crime to be connected to the TJX data heist, although some banks have previously reported that accounts held by consumers affected by the incident had been used in attempted fraud around the globe. Florida Department of Law Enforcement officials confirmed that they initially reported the crime ring to Framingham, Mass.-based TJX in Nov. 2006. The retail chain began informing its customers about the data breach – blamed on a computer systems intrusion – in mid.-Jan. 2007. TJX media representatives didn't immediately return call seeking comment on the arrests.
The suspects were reported by Florida law enforcement officials to have been traveling throughout the state buying large quantities of Wal-Mart gift cards with the stolen credit card accounts, and then redeeming the cards at other locations. Among the items purchased by the scammers were computers, gaming devices, and big-screen TVs. Losses experienced by Wal-Mart and the banks issuing the credit cards total more than $8 million, and are still being calculated, according to Florida officials. The suspects arrested were charged with organized scheme to defraud, a first-degree felony, and had their bonds set at $1 million each. Arrested and booked in Metro-Dade County for the crime spree were Irving Escobar, age 18; Reinier Camaraza Alvarez, 27; Julio Oscar Alberti, 33; Dianelly Hernandez, 19; Nair Zuleima Alvarez, 40; and Zenia Mercedes Llorente, 23. The Florida Department of Law Enforcement said that it has also issued warrants for four other people believed to be involved in the scheme…"
> http://news.yahoo.com/s/ap/20070329/ap_on_…curity_breach_3
March 29, 2007 ~ "More than two months after first disclosing that hackers accessed customers' financial data from its computers, discount retailer TJX Cos. has revealed that information from at least 45.7 million credit and debit cards was stolen over an 18-month period. In a regulatory filing that gives the first detailed account of the breach initially disclosed in January, the owner of T.J. Maxx, Marshall's and other stores in North America and the United Kingdom also said another 455,000 customers who returned merchandise without receipts had their personal data stolen, including driver's license numbers. The data that was stolen covers transactions dating as far back as December 2002, TJX said in the filing Wednesday with the Securities and Exchange Commission…"
Wi-Fi hack caused TK Maxx security breach
- http://www.zdnet.co.uk/misc/print/0,100000…9001093c,00.htm
8 May 2007 ~ "The biggest loss of credit-card data in history was brought about largely because of lax wireless LAN security, it has emerged. Hackers who stole 45 million customer records from the parent company of TK Maxx did so by breaking into the retail company's wireless LAN , it emerged on Monday. TK Maxx's parent company, TJX, had secured its wireless network using Wired Equivalent Privacy (WEP) — one of the weakest forms of security for wireless LANs. Hackers broke in and stole the records — which included millions of credit card numbers — in the second half of 2005 and throughout 2006. According to The Wall Street Journal*, hackers cracked the WEP encryption protocol used to transmit data between price-checking devices, cash registers and computers at a store in Minnesota. The intruders then collected information submitted by employees logging on to the company's central database in Massachusetts, stealing usernames and passwords. With that information, the hackers set up their own accounts on TJX's system. Over the 18-month period, their software collected transaction data, including credit-card numbers, into approximately 100 large files. Transaction data sent to banks, which was unencrypted by TJX, is also believed to have been intercepted by the hackers. According to The Wall Street Journal, the attackers even left encrypted messages on the TJX network to tell each other which files had been copied. A Securities and Exchange Commission (SEC) filing** in March revealed that TJX believed the attackers had stolen information from its computer systems in Watford that process and store payment card transactions for TK Maxx. TJX also believed data had been stolen from the part of its computer systems in Massachusetts that processes and stores information related to payment card, cheque and unreceipted merchandise-return transactions for US and Puerto Rico customers at a number of its stores. Analysts have estimated the breach will cost the company approximately $1bn (£500m), excluding any litigation costs…"
Wireless Client Update for Windows XP
- http://support.microsoft.com/kb/917021
Last Review: January 29, 2007
Revision: 4.2
"…This update enhances support for Wi-Fi Protected Access 2 (WPA2) options in Wireless Group Policy. This update helps prevent a Windows wireless client from advertising the wireless networks in its preferred networks list…"
- http://preview.tinyurl.com/27wjmk
August 06, 2007 (Computerworld) - "The massive data breach at The TJX Companies Inc. disclosed earlier this year — and a string of smaller breaches at other companies — appears to be goading merchants to accelerate adoption of the Payment Card Industry (PCI) Data Security Standard. Visa U.S.A. Inc. last week reported that about 96% of the world’s largest businesses that accept credit and debit cards have stopped storing magnetic stripe information in their systems, meeting a key PCI requirement. Purging magnetic stripe information, which includes cardholders’ personal data, marks an important step toward full compliance with PCI…"