← TJX Cos

2007 TJX Companies — multi-year Wi‑Fi / payment-system intrusion; 45.7M+ payment cards disclosed initially

2007 45.7M records affected Share on X

Data compromised

Magnetic-stripe–equivalent payment data at massive scale, with ancillary PII subsets like driver's-license batches in later forensics

Technical writeup

The TJX Companies, Inc.—parent of T.J. Maxx, Marshalls, and related banners—publicized January 17, 2007 that intruders had skimmed payment-card data from U.S. and U.K. transaction streams across an 18‑month discovery window beginning mid‑2005. State consumer-protection postmortems (e.g., Washington AG) cite weak retail Wi‑Fi crypto (WEP), flat networks, and PCI failures enabling card-track harvesting at scale; subsequent payment-brand litigation pushed totals toward nine‑figure card counts. This row maps the `tjx-cos` slug to the canonical circa‑2007 payment breach (separate `tjx` rows may already exist for brand-specific pages).

Root cause

Wireless network crypto weakness plus inadequate segmentation between store ingress and payment processing

References