The TJX Companies breach was publicly disclosed in January 2007, though the intrusion had begun at least 18 months earlier. Attackers gained initial access by wardriving - driving through TJX parking lots with a laptop and antenna to capture wireless traffic from in-store payment terminals that were still using the deprecated WEP encryption protocol. From that initial wireless sniff, they obtained credentials, escalated into TJX's internal network, installed packet-sniffing software on systems throughout the network, and over 18 months captured approximately 94 million credit and debit card numbers - the largest known card theft at the time. The primary operator was Albert Gonzalez.
The TJX breach established the template for retail card theft that the industry would struggle with for the next decade. It demonstrated that physical proximity to a store (in a parking lot) could translate into access to a multinational retailer's payment infrastructure. It demonstrated that a persistent attacker willing to maintain a long-term presence on a network could extract data gradually without triggering volume-based alerts. And it demonstrated that PCI DSS compliance - TJX had been in the process of compliance when the breach was discovered - did not guarantee security. The breach prompted the card brands, federal legislators, and security practitioners to have the most serious discussion to that point about whether the payment card security model was structurally adequate.
Wardriving into a Multinational Retailer
The initial access vector in the TJX breach was wireless network sniffing in retailer parking lots. TJX stores - TJ Maxx, Marshalls, HomeGoods, Bob's Stores - used wireless networks to connect their payment terminals to back-office systems. Those wireless networks used WEP (Wired Equivalent Privacy), a Wi-Fi encryption standard that was known to be cryptographically broken since 2001. By 2005-2006, tools to crack WEP encryption were freely available and well-documented; a WEP network could be broken in under a minute with the right traffic capture.
Gonzalez's team drove through parking lots at TJX locations, captured enough WEP-encrypted wireless traffic to crack the key, and then used that access to connect to TJX's in-store wireless networks. From the wireless network, they identified systems on the corporate network, moved laterally, and eventually reached TJX's central systems in Framingham, Massachusetts. They installed custom sniffer software that captured card track data as it moved through TJX's payment processing infrastructure.
The attackers also accessed systems in Canada (through a similar wireless access at a Canadian TJX store) and transferred stolen data to servers in Ukraine and Latvia. The exfiltrated data included card magnetic stripe track data - the full magnetic stripe information needed to clone physical credit cards - making the stolen cards immediately usable for in-store fraud.
Scale and Discovery
TJX discovered the breach in December 2006 after its security team noticed suspicious software on its systems. The company retained General Dynamics and IBM to investigate. The investigation revealed the 18-month intrusion and the scale of the card data exposure - approximately 94 million card numbers, though TJX's initial public disclosure in January 2007 characterized the scope as "portions" of the card database. The full scope emerged gradually over months of investigation and litigation.
The breach's discovery came too late to prevent the stolen cards from being used. Within months of the disclosure, fraudulent transactions using cloned TJX cards were appearing across the US, Canada, and Europe. The cards were used to purchase prepaid gift cards and electronics - easy-to-resell items. Florida was particularly affected, with law enforcement tracking large-scale use of cloned cards at Walmart stores.
Albert Gonzalez and the End of the Operation
Albert Gonzalez was identified as the operator of the TJX breach through a combination of Secret Service investigation (he was already a known figure from prior card fraud), law enforcement infiltration of the criminal markets where TJX card data was being sold, and eventual informant testimony. He was indicted for the TJX breach in 2008 and pleaded guilty in 2010. His sentence on the TJX and Heartland charges combined was 20 years.
The prosecution of Gonzalez's network also resulted in convictions for Christopher Scott and Damon Patrick Toey (who conducted the wardriving and wireless access), Ukrainian nationals who had received and monetized the stolen card data, and Turkish nationals who had purchased TJX card data and used it for large-scale retail fraud. The operation's full scope - spanning initial access in parking lots through card monetization across multiple continents - was the most fully documented case of organized retail card fraud up to that point.