How the TJX breach happened: 45.7 million cards and a store's weak Wi-Fi
One of the largest card breaches of its time began outside 2 discount clothing stores near Miami, where the in-store wireless network used encryption that had already been shown to be weak.[1][2] This case file covers how intruders went from a store's Wi-Fi to a retailer's central systems, how long it took anyone to notice, what it cost, and the one control that was missing.
What happened
TJX, the Massachusetts company behind T.J. Maxx, Marshalls and other chains, used wireless networks inside its stores to move information from handheld devices and registers. In July 2005, intruders got into the wireless network at 2 Marshalls stores in the Miami area.[1]
From there they reached the company's central systems in Framingham, Massachusetts, where card data from stores across the business was processed and stored.[1] They stayed for about 18 months. TJX found suspicious software on its systems in December 2006 and announced the breach in January 2007.[1][3]
On March 28, 2007, the company said at least 45.7 million credit and debit card numbers had been exposed.[1] Fraudulent use of stolen data turned up as far away as Hong Kong and Sweden.[1]
How they got in
The crew behind the theft drove along commercial strips in the Miami area looking for store wireless networks they could break into, a practice known as wardriving.[2] The Marshalls stores used WEP, an early form of Wi-Fi encryption with well-known weaknesses. A stronger standard, WPA, was available, but Canada's privacy commissioner found that TJX took about 2 years to move to it, while other retailers switched faster.[1]
The bigger problem was what the store network could reach. Once inside, the intruders were able to get to central databases instead of being contained within one store.[1] The commissioner also found that TJX had collected too much personal information and kept it too long, including driver's license numbers taken for merchandise returns as far back as 2002.[1] Data that is not kept cannot be stolen.
TJX disputed parts of the findings, saying at the time that the wireless entry was suspected but not proven.[1]
How it was caught
TJX spotted the suspicious software itself in December 2006, and federal investigators later traced the break-in to a ring led by Albert Gonzalez, a hacker who had been working as an informant for the U.S. Secret Service.[2][4] The same group was tied to breaches at other retailers and at payment processor Heartland Payment Systems.[4]
Gonzalez pleaded guilty to the TJX-related charges, and on March 25, 2010, a federal judge in Boston sentenced him to 20 years in prison. A second 20-year sentence in the Heartland case, handed down the next day, runs at the same time.[2][4] He also forfeited more than $1.65 million in cash along with property.[2] Several co-conspirators were convicted and sentenced to shorter terms.[2]
What it cost
TJX settled with the Federal Trade Commission in March 2008 over its data security.[5] In 2009 it agreed to a $9.7 million settlement with state authorities.[6] The company also faced claims from card-issuing banks and card networks, and its costs ran well into the hundreds of millions of dollars.[7]
The missing control
The missing control: strong wireless encryption, plus separating store wireless networks from the systems that hold card data.
Either half would have made this far harder. Moving from WEP to WPA when the stronger standard became available would have removed the easy way in from the parking lot.[1] And if the store Wi-Fi had been walled off from the central card systems, breaking into one store's wireless would have exposed one store's traffic, not a database built from millions of customers. Keeping less old data would have shrunk the damage further.[1]
What to do in your business
- Check your Wi-Fi security setting. Log in to your router and make sure it uses WPA2 or WPA3, not WEP or an open network. Replace equipment that cannot.
- Split guest and business networks. Customers, visitors and smart devices should be on a separate network from your registers, card terminals and office computers.
- Keep card data off your systems. Use a payment provider that handles card numbers so they never sit on your own computers.
- Delete what you do not need. Set a retention rule for customer records, such as ID numbers taken for returns, and purge old records on a schedule.
- Change default router passwords. Give each router and access point a unique admin password and update its software.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- NBC News: Encryption faulted in TJX hacking
- Wikipedia: Albert Gonzalez
- Huntress: TJMaxx data breach
- The Register: TJX hacker sentenced to 20 years
- Federal Trade Commission: Agency announces settlement of separate actions against retailer TJX and data brokers Reed Elsevier and Seisint
- ASIS Security Management: TJX settles data breach for $9.7 million
- TJX Companies: Form 10-Q, fiscal 2008 (SEC)