advertisement
advertisement

The TJX Damage Info Continues To Trickle Out

Written by Evan Schuman
January 25th, 2007

The Massachusetts Bankers Association has now confirmed TJX-related fraudulent credit/debit card purchases in Florida, Georgia and Lousisiana plus in Hong Kong and Sweden. “Thus far, nearly 60 banks have reported into the MBA that they have been contacted by the card companies about compromised cards, and these banks are notifying customers and in many cases reissuing new cards,” the association said.

The ABA has been lobbying for rules that would require the disclosure of a retailer’s name when they “caused a data breach,” as a way of both discouraging retailers from being cavalier about security as well as protecting their member banks from being blamed for something they didn’t do. They also are trying to force retailers to pay for the damage if its’ caused by that retailer’s reckless security procedures.


advertisement

One Comment | Read The TJX Damage Info Continues To Trickle Out

  1. Elaine Satlak Says:

    In the fallout after the TJX mess..some banks and credit card institutions have been as helpful as a broken crutch in helping their customers efficiently replace the cards that were compromised. I was shopping in a store last week and,while attempting to use my major credit card, (issued by a large credit union) a red light flashed on the cashier’s register saying “lost card”. I was stunned. I was holding the card in my hand. The cashier breezily said “oh, it’s probably that TJX thing and they’ve just closed down your acct. ” I paid with another card and immediately called the card company who told me that yes, they had cut off payment because I and several hundred others, it seems, had compromised cards. They did not feel under any obligation to inform all of the customers either in writing or by phone of what they had done…They told me we would be getting replacement cards in 7-10 business days.
    The cut off date was apparently Jan 30… I haven’t gotten a replacement yet…and there were no apologies whatsoever from the institution. Then I went to my bank (a major bank)…and asked them to check to see if my debit card had been compromised.
    This was on Feb 8th. The guy checked and very calmly told me that it was…and that
    I’d be issued a new card “sometime soon” This is insane. Have there been many complaints like this?? I would love to have you address this aspect of the fallout on this fraud thing…..or maybe you could let me know if there have already been such articles…..and where do I complain to someone who doesn’t just yawn at me??
    Thanks for your time.

Leave a Reply

Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk.com? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

Weekly, Monthly Newsletters

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly report, with urgent bulletins as news merits—along with our monthlies on Mobile, Security, In-Store, E-Commerce and CRM.
advertisement

Most Recent Comments

"Careless" Systems Integrators Now Directly Under PCI DSS

This exact issue has been bothering me for years, and I was JUST talking about it with someone only yesterday. This may well be my favorite article, mostly because I'm biased and have hated this particular problem forever. Read more...
Good article, but how does this have anything to do with the DSS? Read more...
Actually, the QIR program has a lot to do with the DSS (or PCI). Since merchants rely on their reseller or integrator to implement their PA-DSS validated application, these resellers and system integrators play a critical role in merchants achieving and maintaining PCI compliance. As far as I can tell, the QIR program is designed to help merchants stay compliant by making sure their payment applications are installed according to the PA-DSS Implementation Guide, for example ensuring default passwords are changed (and protected), that the data encryption keys are properly set and secured, that the merchant's data retention policy is set, that no sensitive cardholder data are stored, and often that a firewall is in place and properly configured. Read more...
Although this is a great move forward in pushing the issue of highly trained people, it is also a good marketing ploy for the council. It begs the question: How much do they stand to make? The problem for this is that for people (like myself) that are just starting out their own business venture, PCI has typically charged a premium for their training and certifications. This change will likely force those of us with less capital to spin into the abyss. I have more than 15 years in the security and compliance fields with heavy hitter certs like CISSP, CRISC, and Sec+. There should not be a guide but a free test or a pre-requisite of either the PCI cert OR other heavy hitter certs. I just don't want the good guys in small places to get flushed out. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.