2. Hackers taking it to the TK Maxx
Posted on 17 Jun 2008 at 10:40
Gaffe rating: 878
Until last year, the most disturbing things you'd find in TK Maxx were a pair of novelty "kiss me quick" boxer shorts and a Saturday lad with an acne problem. But hackers found something more alarming on probing the company's servers.
The world's biggest theft of credit card data started in July 2005, and continued for an amazing 18 months. TJX, the US-based parent company of TK Maxx, had its systems breached by a hacker - and when the breach was finally discovered in December 2006, 45.7 million credit and debit card details had been stolen. Investigators believe the breach started with the hackers using a telescope antenna and a laptop to intercept data on a wireless network at one store, and listening in to employees connecting to the TJX central servers. Armed with login details, the gang could set up accounts, install data-harvesting software - do pretty much anything.
Reports published by The Wall Street Journal said a failure to use firewalls and install software patches didn't help either, nor did disregarding the Payment Card Industry Data Security Standard framework on storing financial transaction data for longer than is strictly necessary. You might expect data to be stored until a transaction has cleared, but not dating back years. But then you might also expect wireless networks handling transactional data to be secured with something more robust than the basic WEP protocol when the stronger WPA option has been available for so long.
The moral of this story? Always have levels of security appropriate to the value of the data you're meant to be protecting. Unlike TK Maxx, which was using the electronic equivalent of Ronnie Corbett as a bouncer.
Next: 1. Disappearing disc act
Author: Davey Winder
advertisement
- Q&A: Why Conficker was a victim of its own success
- App developers losing faith in Android
- Biz Stone: Murdoch's Google veto will "fail fast"
- Google adds automatic captions to YouTube
- China ramps up cyber spying
- Mozilla maintains dependence on Google
- Windows 7 flying off the shelves
- Google Chrome OS: full details unveiled
- AOL slashes 2,500 jobs
- YouTube begins streaming full-length shows
- Why Britain's watchdogs have fewer teeth than goldfish
- Tabbed documents: how to make Office 2010 great
- Outlook 2010 People Pane – does it spell death to Xobni
- Microsoft Outlook 2010 screenshots
- Co-Authoring in Word 2010 and SharePoint Foundation 2010
- Microsoft Outlook 2010 screenshots: Backstage view
- Flash 10.1: Developing for Desktop and Device
- Microsoft Office 2010 screenshots: Recover unsaved items
- Microsoft Word 2010 screenshots: Text Effects
- Microsoft Word 2010: inserting screenshots
- Getting to grips with Microsoft's IT Health Environment Scanner
- Virtualise your servers
- The changing face of travel gadgets
- Build your own distributed file system
- The bulletproof Dell that costs an arm and a leg
- Microsoft Office 2010 Technical Preview: Q&A
- Lawnmowers, the TyTN II and one odd insurance request
- There'll never be a bulletproof OS
- How far can we trust apps?
- Five nice touches in Outlook 2010
advertisement
Printed from www.pcpro.co.uk

