Latest Comments
"very good"
by abc | Oct 13, 2008 7:42 PM
 
"It sounds very good if it lives up to the statements"
by John Williams | Oct 11, 2008 11:57 AM
 
"Any good log system is going to be modular (separate from the web site itself), and more than ..."
by Russ | Oct 9, 2008 7:21 PM
 
"Good"
by Francis Ayitey | Oct 6, 2008 10:48 AM
 
"With regard to the battle against cybercrime, Kaspersky Labs, the creator of the famous and ..."
by Mr. Anonymous | Oct 4, 2008 9:08 AM

TJX faces five more breach-related state lawsuits

  • Email a Friend
  • Print Page
TJX faces five more breach-related state lawsuits
By Dan Kaplan
Jun 12, 2007 10:20 AM
Tags: TJX | faces | five | more | breach-related | state | lawsuits
Framingham, Mass.-based TJX, which operates more than 2,000 locations, including hundreds of Marshall’s and T.J. Maxx stores, was named in lawsuits in Illinois, Michigan, Ohio, Texas and Missouri, according to the filing with the Securities and Exchange Commission (SEC). The company previously has been named in lawsuits in Massachusetts, Alabama and California and in Puerto Rico and six Canadian provinces.

The plaintiffs mostly contend in the lawsuits that TJX exhibited "negligence" related to the intrusions in which thieves quietly pilfered sensitive customer data for two years until TJX detected the breach last December.

A company spokesperson did not return a telephone call for comment. CEO Carol Meyrowitz apologized for the breach to a number of stockholders at the company’s annual shareholders meeting earlier this week.

Some of the new lawsuits also name Cincinnati-based Fifth Third Bank, the credit card processor for TJX, as a defendant. A bank spokesperson could not immediately be reached for comment.

The banks responsible for issuing the credit and debit cards must cover the millions of dollars of costs associated with the breach, according to most state laws. But by filing the lawsuits, banks and customers are calling for TJX to be held liable, Diana Kelley, an analyst with the Burton Group, told SCMagazine.com.

"They’re saying, ‘We’d like somebody to absorb the costs of this. We didn’t do anything improper, yet we’re incurring huge fees for the replacement of these cards and the notifications to cardholders.'"

Kelley said Minnesota has approved a law that shifts the burden to the merchants in the event of a data breach, and Massachusetts and Texas are considering similar measures.

"I’m looking at this as a watershed moment," she said. "I do think we will look back [at TJX] and say, ‘This really started to change things.’"

The SEC filing also reported that TJX is the subject of a 37-state attorneys general investigation studying whether the company violated any laws related to consumer protection. TJX is not believed to have been Payment Card Industry (PCI) compliant because Visa has since said it is not aware of any compliant companies ever being breached.

At least one financial institution is not waiting for a court to decide whether TJX is responsible to absorb fees. According to media reports, Brockton, Mass.-based HarborOne Credit Union has billed the company for US$590,000 – US$90,000 to replace credit cards and US$500,000 for alleged brand reputation damage.

Meanwhile, TXJ on Thursday reported 2007 sales are up three percent compared to the same 17-week period last year.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below: