2011 — On March 1, 2012, BJ's Wholesale Club learned of the…
Data compromised
Payment, Personal
Technical writeup
On March 1, 2012, BJ's Wholesale Club learned of the unauthorized use of the name, address and membership number of a resident of the State of New Hampshire. The data was used to create a new online profile on BJs.com, which was used to purchase goods on the website. The purchases were made between 11/11 and 3/12 using fraudulent credit cards. In addition, this profile contained a SSN which was provided by him for check writing privileges at BJs.
Root cause
Social engineering: Forgery