Skip Links

Network World

  • Social Web 
  • Email 
  • Close

TJX security lapse: Willfully and with malice of forethought?

Paying a big price for not adhering to payment card security standards.
'Net Insider By Scott Bradner , Network World , 01/22/2007
Scott Bradner

If leading newspapers are to be believed, TJX Companies is trying for the record for the number of stolen credit cards. Both the Wall Street Journal and The New York Times reported that the number of card numbers exposed or stolen in the December 2006 break-in at TJX’s data center may exceed the 40 million card numbers exposed by the 2005 breach at CardSystems Solutions. (See "The winner so far: CardSystems Solutions".)

TJX issued a press release stating it had been victimized but it now appears that one of the perpetrators of this crime was the company itself.

In late 2004 the payment card industry (PCI), which includes debit and credit card issuers, laid out a set of PCI Security Standards that, as of June, had to be met by anyone handling credit card numbers electronically.

Revised standards went into effect this month. These standards, both old and new, are quite comprehensive and are a good model of how any high-value corporate information should be protected. Some of the rules are easy to implement and some are hard, such as rule 1.4: “Prohibit direct public access between external networks and any system component that stores cardholder data (for example, databases, logs, trace files)." This rule means, for example, that you cannot have a public Web server that stores credit card numbers on its own disks (or on a shared file system).

According to The Wall Street Journal, TJX was not compliant with the PCI Security Standards. There are a number of different parties involved in the credit/debit card business. First there is the bank that issues the card. Then there is the merchant where you use the card to buy something, and there is the merchant’s bank that acquires the money for the merchant (known as the acquiring bank). Sometimes there also is a clearinghouse that helps the processing. Under PCI rules, acquiring banks are responsible for ensuring that their merchants are meeting the security standard.

There appear to be three crooks -- of commission or omission -- in this case. Clearly the person or persons who broke into the TJX system would likely be a crook of commission. But there are two other crooks of omission and they are just as liable in my opinion. Fifth Third Bank, TJX’s acquiring bank, and TJX itself failed to ensure that TJX met the security standards.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (1)
Login
Forgot your account info?

TJX security lapse: Willfully and with malice of forethought?By Anonymous on January 29, 2007, 6:19 pmINFORMATION THAT WAS RELEVANT TO ALL CARD HOLDERS DEALING WITH THE SECURITY BREAK , WAS INTENTIONALLY WITHHELD FROM PRESS, AND ALL CARD HOLDERS INVOLVED, SO THAT...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.