Skip Links

Network World

  • Social Web 
  • Email 
  • Close

TJX breach could hurt 30% of New Englanders

By Jaikumar Vijayan , Computerworld , 01/26/2007

Between 20% and 30% of all New Englanders may have been affected by the recently disclosed data breach at Framingham, Mass.-based retailer TJX Companies, according to the New Hampshire Bankers Association (NHBA).

That estimate is based on feedback the association has received so far from discussions with its 33 member banks, according to Jerry Little, president of the NHBA.

So far, 11 banks have reported being contacted by credit card companies about compromised card use, Little said. But indications are that all of NHBA's members have been affected by the breach, he said. The association has sent a survey to all its members and will have a better estimate of the financial fallout by early next week.

The banks that have reported in so far "have had significant compromises," Little said.

It's been a more difficult to get a handle on the extent to which the compromised cards are being used in fraudulent transactions, he said. But a few of the banks have reported fraudulent use of cards that are on the list of cards compromised in the TJX breach, and in some cases, the fraud appears to have been going on even before the breach was disclosed by TJX last week, he said.

It is still too early to say what the NHBA's response will be to the incident, Little said. But the group is considering options that include legal action against TJX and a push for legislative reform that would hold breached entities financially liable for the costs associated with blocking and reissuing credit and debit cards, he said.

Typically, a bank spends between $5 and $15 to replace a single card, which for a small bank can be quite steep, he said. A compliance process exists where banks can request at least a partial reimbursement from the acquiring bank -- the bank that grants merchants the approval they need to accept credit cards. "I know of a number of institutions that have made these types of filings in the past, and they say they have never received a penny," Little said.

At this point, "the best thing is if TJX would step up to the plate and indemnify financial institutions who are incurring these costs for no fault of theirs," he said.

Experts have said that while it is difficult to prevent such breaches, it can be even harder to uncover them after the fact.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.