2007 TJX Companies — multi-year Wi‑Fi / payment-system intrusion; 45.7M+ payment cards disclosed initially
Data compromised
Magnetic-stripe–equivalent payment data at massive scale, with ancillary PII subsets like driver's-license batches in later forensics
Technical writeup
The TJX Companies, Inc.—parent of T.J. Maxx, Marshalls, and related banners—publicized January 17, 2007 that intruders had skimmed payment-card data from U.S. and U.K. transaction streams across an 18‑month discovery window beginning mid‑2005. State consumer-protection postmortems (e.g., Washington AG) cite weak retail Wi‑Fi crypto (WEP), flat networks, and PCI failures enabling card-track harvesting at scale; subsequent payment-brand litigation pushed totals toward nine‑figure card counts. This row maps the `tjx-cos` slug to the canonical circa‑2007 payment breach (separate `tjx` rows may already exist for brand-specific pages).
Root cause
Wireless network crypto weakness plus inadequate segmentation between store ingress and payment processing