Blog powered by TypePad

« Ominous Milestone Ahead for Data (In)security | Main | Lessons from the DuPont Data Theft »

March 30, 2007

TJX's SEC Filing Raises New Questions

TJX's 10-K filing to the Security and Exchange Commission was made public Wednesday and has made for a whole new set of news stories, blog posting, and speculation.

The report seems to indicate that the TJX Companies, Inc. were employing encryption technology on their cardholder transactions and did delete confidential data on some sort of a regular basis. That's the good news.

The bad news is the intruders apparently were able to capture the card information of 46 million users by installing software on the systems at TJX's Framingham headquarters that copied the information prior to it being encrypted. TXJ also admitted that it appears the intruders had a copy of their encryption key, apparently as a back-up in case the software failed to work or the data was encrypted prior to the point where the software captured it.

Needless to say, the new questions will swirl around how rogue software was allowed to remain in their systems for so long without detection, as well as how the key was obtained.

The information in the 10-K only reveals TJX's perspective of what happened. It will be interesting to see what is revealed as the SEC begins to dig into this further.

Have these latest revelations changed your perspective on the TJX breach at all? I'd be curious to hear whether these new details are swaying opinions, one way or the other.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d834520ea169e200d83578116c69e2

Listed below are links to weblogs that reference TJX's SEC Filing Raises New Questions:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment