On CHOW: Why do onions make you cry?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Colin Barker , ZDNet (UK)
Posted on ZDNet News: Sep 26, 2007 8:53:00 AM

The breach of sensitive personal information held by TJX, operator of discount chains including T.J. Maxx and Marshalls, earlier this year was foreseeable, but the company failed to put in place adequate security safeguards, according to a report.

"The company collected too much personal information, kept it too long, and relied on weak encryption technology to protect it, putting the privacy of millions of its customers at risk," Jennifer Stoddart, the privacy commissioner of Canada, wrote in the report, which was released Tuesday.

Modern crime made a large-scale breach of this kind inevitable, Stoddart concluded. "Criminal groups actively target credit card numbers and other personal information," she said in the report. "A database of millions of credit card numbers is a potential goldmine for fraudsters, and it needs to be protected with solid security measures."

What made such a breach more likely was that the information had been kept for a long time, she said. "The TJX breach is a dramatic example of how keeping large amounts of sensitive information, particularly information that is not required for business purposes, for a long time can be a serious liability."

Stoddart said the affair was a "wake-up call" for all retailers.

Frank Work, the information and privacy commissioner of Alberta, added: "They must collect only the personal information necessary for a transaction."

TJX disclosed in January that its computer system had been breached, putting millions of credit and debit card numbers as well as other personal information at risk. In May, TJX said it believed the hackers gained access to its information via the Wi-Fi networks.

Details of 45 million customers of TJX were put at risk. The company could offer no comment at the time of writing.

Colin Barker of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 3 Talkback(s)
Just don't leave it connected to the network
They needed to study their network setup and have a "secure" segment which was completely separate from the general network for this sort of data, especially any wireless segment. Info was not needed ... (Read the rest)
Posted by: 3dguru Posted on: 09/30/07 You are currently: a Guest | | Terms of Use
Byron Acohido: Zero Day Threat  mighetto | 09/26/07
Tough balance here  Been_Done_Before | 09/27/07
Just don't leave it connected to the network  3dguru | 09/30/07

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More