← Case Files · The Breach Files

2007 · Retail

TJX, 2007: the wireless network in the car park

Case file · 3 min read · Published 14 September 2026

People affected
45.7 million cards confirmed; court filings suggested up to 94 million
When it happened
July 2005 – December 2006
Made public
January 2007
How they got in
Weak WEP wireless encryption at a store, then lateral movement to card processing systems
Attributed to
Albert Gonzalez and associates; Gonzalez was sentenced to 20 years in 2010
What it cost
Reported at around $256 million by the company

What was exposed: Card numbers · Magnetic stripe track data · Some driver's licence numbers and names

Before there were nation-state intrusions and ransomware cartels, there was a man in a car outside a Marshalls store in Miami with a laptop and an antenna. The TJX breach was the first of the modern mega-breaches, and its entry point was the shop's own wireless network.

What happened

TJX Companies operates T.J. Maxx, Marshalls, HomeGoods and, in Europe, TK Maxx. In 2005 its stores used wireless networks — for price scanners and inventory devices — protected by WEP, an encryption standard whose fatal weaknesses had been published in academic papers four years earlier and packaged into point-and-click tools shortly after.

Attackers captured enough wireless traffic from outside a store to recover the key. That put them on the store network. From the store network they reached corporate systems, and from there the systems that handled payment card transactions, where they installed software to capture card data as it was processed.

They remained for roughly eighteen months. TJX discovered the intrusion in December 2006 and disclosed it in January 2007.

The flat network is the real failure. Weak wireless encryption got them onto a shop network. Nothing stopped them going from a shop network to payment systems. The controls that would have contained this — segmentation between store operations and payment processing, monitoring of movement between segments — are now mandatory in card industry standards specifically because of this case.

Why the numbers disagree

TJX confirmed 45.7 million cards. Filings in subsequent litigation by banks put the figure closer to 94 million. Both appear in accounts of the breach, and the discrepancy is not evidence of dishonesty so much as of how breach counting works: the company counts what its logs can prove, plaintiffs count what the evidence supports as a maximum, and the incomplete logging that allowed an eighteen-month intrusion is the same incomplete logging that makes the count uncertain.

The general principle, useful for reading any breach: a confirmed figure is a floor, established by evidence that survived; it is rarely a ceiling.

Albert Gonzalez

The same individual is behind TJX and Heartland Payment Systems, along with intrusions at other retailers. Gonzalez had previously been arrested and then worked as a paid informant for the US Secret Service — while continuing to run the operations he was supposedly helping to investigate.

He was sentenced to 20 years in 2010, at the time the longest US sentence for computer crime. The technique used across his campaigns was consistent and, by modern standards, unsophisticated: find a weakly protected entry point, move inwards, install capture software on systems that handle card data in the clear, exfiltrate steadily.

What it changed

PCI DSS became enforceable rather than aspirational. The Payment Card Industry Data Security Standard already existed. TJX made card networks and acquirers treat it as something to audit and penalise rather than certify and forget, and it directly produced the requirement to retire WEP — new deployments prohibited from 2009, all use banned from mid-2010.

Retention limits arrived. Part of what made the haul so large was that TJX had retained card data it did not need. "Do not store what you do not need, and delete what you no longer need" became an explicit requirement rather than a recommendation.

Breach notification laws spread. TJX happened during the period when US state notification statutes were proliferating, and it was the case legislators cited. The Canadian and Alberta privacy commissioners' joint investigation was one of the first cross-border regulatory examinations of a retail breach.

The part that has not changed

Read the failure list without the dates and it could be any year: obsolete technology left running because replacing it was not funded, a flat network where a foothold anywhere reached everything, data retained beyond its purpose, and monitoring insufficient to notice eighteen months of theft.

The specific technologies age out — nobody runs WEP now — and the patterns do not. Target six years later is the same shape with a contractor's portal instead of a wireless antenna.

What to take from it

  1. Check statements, not just balances. Card fraud from this era was detected by cardholders far more often than by issuers.
  2. Prefer payment methods with a dispute buffer. A credit card or payment service puts a layer between a fraudulent charge and your own money.
  3. If you run any network: segment it. The single control that would have reduced this from a national story to a store incident.
  4. Retire legacy systems on a schedule, not on an incident. Every breach in this archive with a decade-old root cause was preventable by a decision that got deferred.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

What was WEP and why was it a problem?

Wired Equivalent Privacy was the original Wi-Fi encryption standard. Fatal flaws in it were published in 2001, and by 2005 tools existed that could recover a WEP key from captured traffic in minutes. It had been formally superseded by WPA, but plenty of retail deployments were still running it because replacing working equipment costs money and nobody had been forced to.

How long were the attackers inside?

Roughly eighteen months, from mid-2005 to the end of 2006. They installed software that captured card data during processing and moved it out steadily. The length of that dwell time is the part that shocked people: the intrusion was not a moment, it was a tenancy.

Why do the numbers vary between 45 million and 94 million?

TJX confirmed 45.7 million cards. Filings by banks in subsequent litigation argued the true figure was closer to 94 million. Both numbers are in circulation because the company and the plaintiffs were counting different things with different access to the evidence — a pattern that repeats in almost every large breach.

What happened to the people responsible?

Albert Gonzalez, who had previously worked as a paid informant for the US Secret Service, was convicted for this and other intrusions and sentenced to 20 years in prison in 2010 — at the time the longest sentence handed down in the United States for computer crime.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →