NTA Monitor

Latest News

60% of UK website tests revealed Internet encryption and cross-site scripting vulnerabilities

10th April 2008 60% of web application tests performed for UK organisations showed that their websites contain weak encryption or cross-site scripting (XSS) vulnerabilities Read More

Demilitarised Zone most secure option for BlackBerry device

28th February 2008 Recent BlackBerry testing by IT security consultancy, NTA Monitor, has revealed that organisations are still not configuring these mobile devices correctly Read More

Retailers should put security top of their Christmas list

13th November 2007 With British consumers spending more than £6.6 billion online in the last two months of last year, the 2007 festive season is set to be one of great cheer for online retailers Read More

Businesses warned not to have skeletons in cupboards

13th November 2007 For many organisations, the festive season is an opportunity to heave a corporate sigh of relief and enjoy the brief respite in frenetic business activity as countless people all over the world, go home to celebrate Christmas Read More
Date: 2nd April 2007
Risk: Informational

TJX, the US parent company of TK Maxx, has had over 45 million of its customers' credit and debit card details stolen.

TJX confirmed that between 31st December 2002 and 23rd November 2003, information had been stolen from 45.6 million cards used in Britain and North America and also stated that it did not know how many details had been stolen for transactions made between 24th November 2003 and 28th June 2004. It is known that customers' card details have been fraudulently used in Britain and TJX said that banks had indicated that they possessed "preliminary evidence of possible fraudulent misuse".

TJX's CEO and President, Carol Meyrowitz, said in an open letter on TJX's website: "With the help of computer security experts, we have strengthened the security of our computer systems and we believe customers should feel safe shopping in our stores."

According to TJX, the security breach happened in July 2005 and continued unnoticed for 18 months. The company discovered the breach in December 2006 but only disclosed its details recently; it's the biggest credit card theft in the world to date.

References