Credit cards
Details on 45 million credit and debit cards have been stolen from computers at TK Maxx

Credit card heist hits 45 million users

UK customers of TK Maxx told to check credit and debit card statements

Written by Matt Chapman

A security breach on the computer systems at TK Maxx is now thought to have led to the theft of 45.7 million credit and debit card records. 

The data theft took place over an 18-month period, beginning in July 2005.

"We have been able to specifically identify that a portion of the data believed stolen included account information for approximately 45.7 million separate payment cards," said an official statement from TJX, the American parent of TK Maxx. 

TJX said that 75 per cent of the cards were expired at the time of the theft, or the stolen information did not include the security code data from the magnetic strip on the payment card.

However, that still leaves 11.42 million stolen financial records that are currently active. TJX has warned UK customers to check their credit card statements.

"Today's full declaration by TJX is a graphic example of how a breach in information security can impact a business and its customers," said Greg Day, security analyst at McAfee

"The announcement is just the tip of the iceberg, however, as organisations across the globe continue to evaluate and look to implement security policy to protect against external and internal threat."

Jamie Cowper, data security expert at PGP Corporation, added: "This is a frightening illustration that when retailer's systems are hacked, even if it occurs on the other side of the world, the card details of customers in every country are at risk because of the way companies share and store information globally." 

Cowper explained that the upcoming Payment Card Industry Data Security Standard (PDF) in June 2007 would force retailers such as TJX to safeguard customer card information or face losing its credit card facilities altogether.

"Security technologies such as encryption can greatly simplify the process of protecting information," said Cowper.

"But the recent spate of data breaches suggests that many companies are still a long way off being compliant with this and other data protection standards."

Mike Smart, European product manager at Secure Computing, added: "We find that 80 per cent of confidential data is typically undetectable by 90 per cent of firewalls and as a result sensitive data can leak from the organisation without their knowledge. 

"With the rise of real-time unencrypted communications, such as instant messaging and web mail, hacking into a corporate network and extracting data unnoticed is easy."

Tags:

Further reading

Poor passwords open web bank users to ID theft

Kaspersky Lab finds password security not good enough   More...

Two-year sentence for UK data theft

Government gets tough, but security experts remain unconvinced   More...

Experts warn of soaring ID theft

Expected post-Christmas downturn in cyber-crime has not materialised   More...

Turks arrest 17 online theft suspects

Gang colluded with Russian hackers, police claim   More...

Related articles

2007 Roundup: Data loss hits the headlines

Nationwide, Halifax, TK Maxx, HMRC and many, many more to blame   More...

TJX settles data breach lawsuits

Company agrees to compensate and insure customers   More...

MoD launches inquiry into laptop theft

Parliamentary meeting reveals catalogue of errors   More...

FSA issues first fine for lax security

Organisation cracks down on data protection   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement