[Dataloss] Visa Check Cards Compromised in TJX Breach

nepen nepen at attrition.org
Sat Apr 14 17:06:38 UTC 2007


Seems like it took them long enough...

My mother received a letter from Commerce Bank today warning her that her
Visa Check Card may have been compromised as a result of the TJX breach.
>From what I can tell, it seems like they took their sweet old time getting
around to notifying customers of the situation--to the tune of waiting
several months. According to the archives*, the credit and debit card
issuers were made aware of this in January.

*http://attrition.org/pipermail/dataloss/2007-January/001012.html


Also, their letter assures me in nice, comforting bold text that my
mother's PIN was not compromised, as though this were of any importance
whatsoever when it comes to Visa Check Cards. According to my mother, the
only time a PIN is required to use this card is when you use MAC. Your PIN
is not required when the card is used to deduct money from the checking
account or when it is used as a credit card.

Ah, there are some days where I'm glad I pay cash for everything...

nepen



I've copied the letter here verbatim and any typos here are mine. All
emphasis is theirs.


Dear Valued Customer,

You may have recently heard about a security breach at TJX Companies, the
parent company of TJ Maxx, Home Goods, Marshalls, AJ Wright, Winners,
HomeSense and Bob's stores. We have been notified that your Check Card may
have been impacted by this situation. [bold emphasis]This breach did not
include your Personal Identification Number (PIN).[/bold emphasis]

Although this breach does not mean your card will be used for unauthorized
activity, we are taking action to further protect your account. Enclosed
is a new Check Card with a new card number and our brand new design. Your
PIN has not changed. lease activate your new card and begin using it
immediately.

If you have any recurring payments on your Check Card, please contact the
merchant(s) and transfer them to your new card. To allow time to change
these payments, your existing card will remain open until May 31, 2007.
During this time you will continue to be protected from any unauthorized
purchases by Visa's Zero Liability Policy.

As always, if you have any questions, please contact our Customer Service
Center at 1-888-751-9000.

Sincerely,

[Signature]
Frank Papotto
Vice President
Chairman's Service Center



More information about the Dataloss mailing list