The TJX Companies breach was publicly disclosed in January 2007, though the intrusion had begun at least 18 months earlier. Attackers gained initial access by wardriving - driving through TJX parking lots with a laptop and antenna to capture wireless traffic from in-store payment terminals that were still using the deprecated WEP encryption protocol. From that initial wireless sniff, they obtained credentials, escalated into TJX's internal network, installed packet-sniffing software on systems throughout the network, and over 18 months captured approximately 94 million credit and debit card numbers - the largest known card theft at the time. The primary operator was Albert Gonzalez.

The TJX breach established the template for retail card theft that the industry would struggle with for the next decade. It demonstrated that physical proximity to a store (in a parking lot) could translate into access to a multinational retailer's payment infrastructure. It demonstrated that a persistent attacker willing to maintain a long-term presence on a network could extract data gradually without triggering volume-based alerts. And it demonstrated that PCI DSS compliance - TJX had been in the process of compliance when the breach was discovered - did not guarantee security. The breach prompted the card brands, federal legislators, and security practitioners to have the most serious discussion to that point about whether the payment card security model was structurally adequate.

Wardriving into a Multinational Retailer

The initial access vector in the TJX breach was wireless network sniffing in retailer parking lots. TJX stores - TJ Maxx, Marshalls, HomeGoods, Bob's Stores - used wireless networks to connect their payment terminals to back-office systems. Those wireless networks used WEP (Wired Equivalent Privacy), a Wi-Fi encryption standard that was known to be cryptographically broken since 2001. By 2005-2006, tools to crack WEP encryption were freely available and well-documented; a WEP network could be broken in under a minute with the right traffic capture.

Gonzalez's team drove through parking lots at TJX locations, captured enough WEP-encrypted wireless traffic to crack the key, and then used that access to connect to TJX's in-store wireless networks. From the wireless network, they identified systems on the corporate network, moved laterally, and eventually reached TJX's central systems in Framingham, Massachusetts. They installed custom sniffer software that captured card track data as it moved through TJX's payment processing infrastructure.

The attackers also accessed systems in Canada (through a similar wireless access at a Canadian TJX store) and transferred stolen data to servers in Ukraine and Latvia. The exfiltrated data included card magnetic stripe track data - the full magnetic stripe information needed to clone physical credit cards - making the stolen cards immediately usable for in-store fraud.

[TECHNICAL NOTE]
The WEP vulnerability in the TJX breach was an inexcusable use of known-broken cryptography. WEP had been demonstrated to be cryptographically flawed in 2001 (Fluhrer, Mantin, and Shamir paper on RC4 key scheduling). WPA (Wi-Fi Protected Access) was introduced as a replacement in 2003 and WPA2 in 2004. By 2005-2006, when TJX was being breached, WEP was three years past its demonstrated cryptographic failure and had been replaced by a standard widely available on commercial hardware. The payment card industry's standards (PCI DSS) required migration away from WEP by 2004 for new implementations, yet TJX was still using it. This gap between standard availability and adoption reflected both the cost of hardware replacement across thousands of retail locations and the difficulty of enforcing security standards across large distributed retail environments. PCI DSS subsequently added explicit timelines for WEP deprecation and required wireless penetration testing as part of annual compliance assessments. The TJX breach also highlighted that wireless networks, unlike wired networks, extend beyond the physical perimeter of a building - a corporate security perimeter defined by walls provides no protection against an attacker in the parking lot who can connect to an in-store wireless network.

Scale and Discovery

TJX discovered the breach in December 2006 after its security team noticed suspicious software on its systems. The company retained General Dynamics and IBM to investigate. The investigation revealed the 18-month intrusion and the scale of the card data exposure - approximately 94 million card numbers, though TJX's initial public disclosure in January 2007 characterized the scope as "portions" of the card database. The full scope emerged gradually over months of investigation and litigation.

The breach's discovery came too late to prevent the stolen cards from being used. Within months of the disclosure, fraudulent transactions using cloned TJX cards were appearing across the US, Canada, and Europe. The cards were used to purchase prepaid gift cards and electronics - easy-to-resell items. Florida was particularly affected, with law enforcement tracking large-scale use of cloned cards at Walmart stores.

[WARNING]
TJX's breach disclosure and legal response illustrated the litigation landscape for major retail breaches that would recur in Target (2013), Home Depot (2014), and others. The company settled with Visa for $41 million, with MasterCard for $24 million, with a class of financial institutions for $40.9 million, and reached a consumer settlement worth up to $30 in merchandise vouchers per affected individual. Total settlements exceeded $200 million. The FTC reached a consent decree with TJX requiring 20 years of comprehensive security assessments by independent auditors - a form of ongoing regulatory supervision. State attorneys general in 41 states and the District of Columbia investigated and settled for an additional $9.75 million. The settlements established dollar ranges for per-card liability that became reference points in subsequent breach litigation. They also established that retailers, not just payment processors, bore direct liability to card-issuing banks when breaches resulted from inadequate security - a legal clarification that motivated the subsequent wave of retail security investment.

Albert Gonzalez and the End of the Operation

Albert Gonzalez was identified as the operator of the TJX breach through a combination of Secret Service investigation (he was already a known figure from prior card fraud), law enforcement infiltration of the criminal markets where TJX card data was being sold, and eventual informant testimony. He was indicted for the TJX breach in 2008 and pleaded guilty in 2010. His sentence on the TJX and Heartland charges combined was 20 years.

The prosecution of Gonzalez's network also resulted in convictions for Christopher Scott and Damon Patrick Toey (who conducted the wardriving and wireless access), Ukrainian nationals who had received and monetized the stolen card data, and Turkish nationals who had purchased TJX card data and used it for large-scale retail fraud. The operation's full scope - spanning initial access in parking lots through card monetization across multiple continents - was the most fully documented case of organized retail card fraud up to that point.

[IOC]
TJX Companies breach summary: initial access via WEP wireless network capture in TJX store parking lots, approximately 2005-2006. Network: TJX's in-store wireless payment networks in US and Canada. Technique: WEP key cracking, lateral movement to TJX corporate systems in Framingham MA, custom sniffer software deployment to capture payment card track data. Cards stolen: approximately 94 million (initial TJX estimates were lower; 94M figure emerged from litigation). Data type: full magnetic stripe track data (sufficient to clone physical cards). Exfiltration: via FTP to servers in Ukraine and Latvia. Perpetrators: Albert Gonzalez ("soupnazi") - primary operator; Christopher Scott and Damon Toey - wardriving access; Eastern European buyers and monetizers. Detection: December 2006 by TJX internal security team. Public disclosure: January 17, 2007. Settlements: Visa $41M; MasterCard $24M; financial institution class $40.9M; consumer class up to $30 vouchers; 41 AGs $9.75M. FTC consent decree: 20 years of independent security assessments. Gonzalez sentence: 20 years concurrent with Heartland sentence (2010). Technical legacy: accelerated WEP deprecation, PCI wireless testing requirements, in-store network segmentation standards, and the payment card industry's transition away from magnetic stripe reliance toward EMV chip.