[Dataloss] follow-up: TJX consumer settlement sale offer draws scorn

security curmudgeon jericho at attrition.org
Wed Nov 21 10:57:50 UTC 2007



---------- Forwarded message ----------
From: InfoSec News <alerts at infosecnews.org>

http://www.theregister.co.uk/2007/11/20/tjx_settlement_offer_kerfuffle/

By John Leyden
20th November 2007

Law enforcement officials have poured cold water on plans by TJX to hold a 
one-day sale for customers as part of a proposed settlement for a consumer 
class-action case against the security incident-afflicted retailer.

TJX faces consumer and bank class action lawsuits over the exposure of an 
estimated 45.7m customer records as the result of a security breach that 
lasted for two distinct six month periods between 2003 and December 2006. 
Hackers broke into a system that stored data on credit card, debit card, 
cheque, and return details in an attack blamed on a poorly secured 
wireless network in one of its stores. Subsequent credit card frauds have 
being traced to data swiped as a result of these breaches and a number of 
arrests have been made.

[..]


More information about the Dataloss mailing list