Wi-Fi hack caused TK Maxx security breach

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Hackers who stole 45 million customer records from the parent company of TK Maxx did so by breaking into the retail company's wireless LAN , it emerged on Monday.

TK Maxx's parent company, TJX, had secured its wireless network using Wired Equivalent Privacy (WEP) — one of the weakest forms of security for wireless LANs. Hackers broke in and stole the records — which included millions of credit card numbers — in the second half of 2005 and throughout 2006.

According to The Wall Street Journal, hackers cracked the WEP encryption protocol used to transmit data between price-checking devices, cash registers and computers at a store in Minnesota. The intruders then collected information submitted by employees logging on to the company's central database in Massachusetts, stealing usernames and passwords.

With that information, the hackers set up their own accounts on TJX's system. Over the 18-month period, their software collected transaction data, including credit-card numbers, into approximately 100 large files. Transaction data sent to banks, which was unencrypted by TJX, is also believed to have been intercepted by the hackers. According to The Wall Street Journal, the attackers even left encrypted messages on the TJX network to tell each other which files had been copied.

A Securities and Exchange Commission (SEC) filing in March revealed that TJX believed the attackers had stolen information from its computer systems in Watford that process and store payment card transactions for TK Maxx.

TJX also believed data had been stolen from the part of its computer systems in Massachusetts that processes and stores information related to payment card, cheque and unreceipted merchandise-return transactions for US and Puerto Rico customers at a number of its stores. Analysts have estimated the breach will cost the company approximately $1bn (£500m), excluding any litigation costs.

Many security experts have criticised the strength of WEP encryption. WEP was initially cracked in 2001, and most recently broken by German researchers last month, who beat the encryption using an ordinary laptop in under three seconds.

TJX had not responded to a request for comment at the time of writing.

Talkback

will happen over and over again until immediate realistic liability by law is introduced and enforced throughout the entire chain involved.

Bad security is mostly never a single entity fault. Usually a whole chain is involved with plenty of room for pointing blaming fingers. There's also the market attitude, whole generations out there that don't have the first clue about what's involved with security. Poorly educated in that area but worked their way up to decision making of advising level nonetheless. No-one will force the solution that's secure but customers and end-users won't swallow or can't get wrap their poorly security wise minds around. User friendliness and "functionality" is still chosen above security. Also because most of the stuff in use out there is insecure. For instance, WEP is still a de facto standard out there. And USB. Why?

With hindsight plenty of people demand security. Are even willing to give up privacy and other rights. But ask them to give up WEP, USB, Windows and such and they refuse. You can't have it both ways. You can't smoke and be guaranteed to not get long cancer. You can't drink and be guaranteed to not get liver problems. You can't eat fat and sugar all the time and be guaranteed to not die early. You can't use IT stuff that you can buy in any store and be guaranteed IT security. In short, you get you what you pay for. Shape up or shut up. Either put in the effort beforehand or deal with the consequences afterwards. It's as simple as that.

Reality of life is that if you ask a question to any vendor, advisor, expert, decision maker, etc, you're likely to get an answer that will differ from the answer you would get if a huge contractual penalty clause is involved. Problem is that most are not in the position to introduce such clauses in realistic ways.

The real issue is that IT holds a very unique liability position in today's world. They can practically say or do anything and get away with it, or slightly damaged (but still way below their profit margins). For the record, Microsoft is not alone in this. Somehow I can't blame them for milking that all the way business wise but I blame them for not taking their social responsibility. Again, you get what you pay for. And if you pay for what you're told then, boy, you will be milked. Big time.

To sum it up: "they should have" is a much too simple conclusion. That's symptom fighting with hindsight. The trick is to solve causes beforehand. No-one will put in the effort to reach real security market wide until fingers get tapped real hard and people get educated.

Thing is that real security is not on the corporate and political agenda. And even if it is, it's only about fighting symptoms, PR, power, control, votes and such.

Arthur B. 12 May, 2007 23:08
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

SPM

The 2 million number quoted is shipments not sales, an exact repeat of last year's dire sales of WP7. Sales to customers are likely to number only...

3 hours ago by SPM on Nokia earnings fail to shine despite Lumia
apexwm

It sounds like this is just another variable in the complex equation of Microsoft licensing, which often results in customers overpaying as it is....

5 hours ago by apexwm on UK customers to lose out in Microsoft licensing change
chonzchor

I am really thankful to you for this nice and beautiful information.I really like this. cable ties

5 hours ago by chonzchor on Currys £16.99 USB cable rip-off.
Brian Jones

What would be nice would be if Microsoft practiced consistent pricing between the US and Europe.

10 hours ago by Brian Jones via Facebook on UK customers to lose out in Microsoft licensing change
Karen Friar

@Scott Deagan: Ofcom dedicated a section to upload speeds - see page 19 onward of its full report:...

11 hours ago by Karen Friar on UK broadband speed climbs 22 percent
EUDataProtection

The EU proposals can all be read in full on the reform website: http://ec.europa.eu/justice/data-protection/minisite/index.html

12 hours ago by EUDataProtection on Firms face tough new EU fines for data breaches
Jake Rayson

Found out that Taskwarrior stores all data in plain text files: "Task writes all pending tasks to the file ~/.task/pending.data and all completed...

14 hours ago by Jake Rayson on Taskwarrior: command line task manager
ians1

"...based 6,000 miles away..." Indeed, so who do you complain to when things go wrong? I would not buy shares in Faecebook even if I could...

14 hours ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

These are really very useful tips of backing up the system. Each tips are important and essential to prevent loosing all the data that we have....

17 hours ago by servermanagement on Ten ways to take the sting out of IT disasters
Scott Deagan

Why is the upstream never discussed? I'd like to see Ofcom explain to Internet users why people in the UK can only get a maximum of 10Mb/s upstream...

1 day ago by Scott Deagan via Facebook on UK broadband speed climbs 22 percent
Moley

Seemingly a very strange decision, even perverse. Mind you, the basis of the decision is hardly explained here or in Cnet. Perhaps we will hear...

1 day ago by Moley on Free Maps costs Google £400K in damages in France
Jake Rayson

@OccupyACAT: I had heard mention of the Emacs extension but not the Ubiquity project. Interesting to see an idea spread almost simultaneously! Re....

1 day ago by Jake Rayson on Ubuntu HUD Intenterface? Sublime already there!
markhumphryes

With no Flash support on LoveFilm, mobile devices running Android will not be able to use it - I presume - I tried a trial via my Galaxy Tab 10.1...

1 day ago by markhumphryes on Lovefilm drops Flash, kills Linux support
manek

And people wonder why there is caution about doing business with large, consumer-focused technology companies, most of which are based 6,000 miles...

2 days ago by manek on Facebook plans to raise $5bn via share launch
manek

Yes, frameworks and smarter compilers - but I suspect a lot of the code will have to be written with parallel processing as one of its fundamental...

2 days ago by manek on Parallel computing takes a step forward
Simon Bisson and Mary Branscombe

Well, this is why I'm both fascinated and slightly worried; parallel computing and concurrency and complex architectures don't seem to be something...

2 days ago by Simon Bisson and Mary Branscombe on Parallel computing takes a step forward
ians1

Let's hope that they take more notice of their shareholders than they do of their poor customers! I have never experienced customer service as bad...

2 days ago by ians1 on Facebook plans to raise $5bn via share launch
servermanagement

Thanks for the heads up. Will definitely check this HUD Intenterface.

2 days ago by servermanagement on Linux Minterface
Will A

Some more observations by an extremely frustrated user in Canada (apparently every country has a different set of "issues"): The web interfaces...

2 days ago by Will A on Cambridge researchers knock Verified by Visa
Jake Rayson

@zdnetukuser: I hope there's more conciliation and less bitterness in the graphical shell camps, I'd like to Ubuntu to succeed, I *want* to have a...

2 days ago by Jake Rayson on Linux Minterface