Tjx Data Breach Write Up

566 Words3 Pages
TJX DATA BREACH WRITE UP TJX is a company that runs a chain of retail stores, which include T.J. Maxx, Marshalls, and Bob’s Stores. On December 18, 2006, TJX discovered an unauthorized intrusion into their computer systems that processes and store information related to customer transactions. TJX Company did not make the data breach known to public until February 2007. My team and I performed an analysis of the internal controls that were not implemented within TJX. Three major areas of vulnerability were inadequate wireless network security, improper storage of customer data, and failure to encrypt customer account data. The intruders had access to TJX record for 18 months without being detected which makes it clear that no traffic logs were kept if not the breach would’ve been detected much more sooner. Overall TJX Company was simply just not in compliance with PCI Data Security standards. Below is a description of lack of internal controls for the three major areas impacted. * Inadequate wireless network security: store network was using a security protocol known as wired equivalent privacy (WEP). WEP is extremely easy to crack, can usually take less than a minute to do so. WEP does not satisfy PIC standards, which require the use of Wi-Fi protected access (WAP protocol). This gave hackers the opportunity to intrude the stores network and breach security at the corporate headquarters given them access to obtain the customer information that was stored there. Job application kiosks were also on the main network giving anyone that applied at the store access to it. * Improper storage of customer data: TJX data storage practices violated PIC standards. TJX Company was storing the full-track contents scanned from each customer’s card, including the credit card validation code number (CVC) and personal identification numbers (PIN) associated

More about Tjx Data Breach Write Up

Open Document