Case Study On Tjx Breach

817 Words2 Pages

TJX breach overview
TJX, the largest off‐price clothing retailer in the United States. Winners and HomeSense in Canada are two from the eight organizations. TJX faced the largest online hack with about 94 million records lost in 2006. The company found in December 2006 about the breach. After the investigation, the company found that they were losing sensitive information since 2005.
Many small gift card transactions are recorded in the US. One Walmart employee had doubt on it because of the huge amount of small transactions within a small-time frame and called the police. After the investigation, TJX know about breach. Albert Gonzalez broke into TJX 's systems and stole visa and debit card numbers initially accessed the organization 's …show more content…

TJX Cos. said its costs from the largest computer data breach in corporate history, in which thieves stole more than 94 million customer credit and debit card numbers.
Fundamental security issues
1. Weak technology: -TJX was using a weak WEP (Wireless Equivalent Privacy) security protocol for its wireless networks within the stores, which can be hacked very quickly. WEP is used at the two lowest layers of the OSI model - the data link and physical layers; it therefore does not offer end-to-end security so it is not enough strong to prevent breaches (Beal, 2007). WPA is more secure than WEP. WPA aims to provide stronger wireless data encryption than WEP (Beal, 2007).
2. Lack of in-store physical security:- Per Information week, the hackers had opened the in-store kiosks and used USB drives to load the software onto those terminals and turned them into remote terminals that connected to TJX’s networks. This brings forth the issue of negligence, lack of monitoring and securing physical in-store IT assets (Googleca, 2016).
3. Lack of firewalls:- Much unwanted software’s found in TJX computers. Firewalls are unable in some …show more content…

Organizations do not want to spend money on security.
1. Properly secure wireless systems: - To prevent data breaches it is very important to secure wireless networks. WI- Fi network security is necessary because it is very easy to hack the data and unauthorized access. Breaches can be prevented by using strong passwords, encryption methods, and strong verification.
2. Implement a system Intrusion Detection/Prevention System (IDS/IPS): - Make the investment in an IDS/IPS to distinguish and prevent potential system dangers. sensors ought to be circulated all through the system, with a specific focus on general society untrusted section. Take alerts very seriously.
3. Encryption: - Data encryption is the best way to reduce risks associated with misplaced, lost or stolen data.
4. Implement physical security: - “Physical security protects people, data, equipment, systems, facilities and company assets” (Harris,

More about Case Study On Tjx Breach

Open Document