Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

TJX faces five more breach-related state lawsuits

  • Email a Friend
  • Print Page
TJX faces five more breach-related state lawsuits
By Dan Kaplan
Jun 12, 2007 10:20 AM
Tags: TJX | faces | five | more | breach-related | state | lawsuits
Framingham, Mass.-based TJX, which operates more than 2,000 locations, including hundreds of Marshall’s and T.J. Maxx stores, was named in lawsuits in Illinois, Michigan, Ohio, Texas and Missouri, according to the filing with the Securities and Exchange Commission (SEC). The company previously has been named in lawsuits in Massachusetts, Alabama and California and in Puerto Rico and six Canadian provinces.

The plaintiffs mostly contend in the lawsuits that TJX exhibited "negligence" related to the intrusions in which thieves quietly pilfered sensitive customer data for two years until TJX detected the breach last December.

A company spokesperson did not return a telephone call for comment. CEO Carol Meyrowitz apologized for the breach to a number of stockholders at the company’s annual shareholders meeting earlier this week.

Some of the new lawsuits also name Cincinnati-based Fifth Third Bank, the credit card processor for TJX, as a defendant. A bank spokesperson could not immediately be reached for comment.

The banks responsible for issuing the credit and debit cards must cover the millions of dollars of costs associated with the breach, according to most state laws. But by filing the lawsuits, banks and customers are calling for TJX to be held liable, Diana Kelley, an analyst with the Burton Group, told SCMagazine.com.

"They’re saying, ‘We’d like somebody to absorb the costs of this. We didn’t do anything improper, yet we’re incurring huge fees for the replacement of these cards and the notifications to cardholders.'"

Kelley said Minnesota has approved a law that shifts the burden to the merchants in the event of a data breach, and Massachusetts and Texas are considering similar measures.

"I’m looking at this as a watershed moment," she said. "I do think we will look back [at TJX] and say, ‘This really started to change things.’"

The SEC filing also reported that TJX is the subject of a 37-state attorneys general investigation studying whether the company violated any laws related to consumer protection. TJX is not believed to have been Payment Card Industry (PCI) compliant because Visa has since said it is not aware of any compliant companies ever being breached.

At least one financial institution is not waiting for a court to decide whether TJX is responsible to absorb fees. According to media reports, Brockton, Mass.-based HarborOne Credit Union has billed the company for US$590,000 – US$90,000 to replace credit cards and US$500,000 for alleged brand reputation damage.

Meanwhile, TXJ on Thursday reported 2007 sales are up three percent compared to the same 17-week period last year.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Breaches & Exposures Whitepapers