What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
On March 29, 2007, TJX reported that approximately 45.6 million credit and debit card numbers had been stolen. That exceeded the roughly 40 million records disclosed in the 2005 CardSystems breach, so contemporary coverage called TJX the largest publicly reported payment-card theft. The label was time-bound: later court references commonly use 45.7 million accounts, and Heartland Payment Systems’ 2009 breach was later reported at about 130 million card numbers.
What TJX was and which systems were affected
The TJX Companies operated T.J. Maxx, Marshalls, HomeGoods, A.J. Wright, Winners, HomeSense and TK Maxx. Its retail systems processed payment cards, check-verification data and no-receipt merchandise returns in the United States, Canada, Puerto Rico and potentially the United Kingdom and Ireland. The incident therefore involved more than a single store or database.
Why the headline says 45.6 million—and why some records say 45.7 million
TJX’s March 2007 disclosure, as reported by Computerworld, used 45.6 million stolen credit and debit card numbers. Later court and government references commonly describe at least 45.7 million affected customer accounts, including the figure in the federal litigation opinion. The sources use slightly different counts; the discrepancy should not be treated as proof that a specific number of unique people was affected.
“Card numbers,” “accounts,” “cards,” “records” and “customers” are not interchangeable. One person can hold multiple accounts, and an exposed number does not necessarily mean a fraudulent transaction occurred.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Timeline of the intrusion and disclosure
| Period | What the available records indicate |
|---|---|
| July 2005 | The FTC later alleged that unauthorized access began as early as this month. |
| 2005–2006 | Attackers accessed TJX systems at multiple points. |
| May–December 2006 | Payment-card authorization data was intercepted. |
| December 2006 | TJX detected the intrusion. |
| January 2007 | The company first publicly announced the breach. |
| February–March 2007 | TJX disclosed additional information, including the 45.6-million figure. |
The FTC complaint describes the chronology and later investigative findings in detail: FTC complaint PDF.
How attackers got access
The incident was not simply a story of criminals defeating one advanced defense. The FTC identified a chain of ordinary control failures:
- Sensitive information was stored in clear text on internal networks.
- Payment-authorization requests and responses could travel in clear text within and between networks.
- Wireless access to store networks was not adequately restricted.
- Administrators and other users were not required to use strong, unique passwords.
- Computers handling card authorization were not sufficiently isolated from other systems and the internet.
- Security alerts, antivirus updates, patching, detection and investigation procedures were inadequate.
Wireless access was an important entry or access route, but poor segmentation, unencrypted data and weak monitoring allowed an intruder who reached the environment to obtain far more than a single transaction.
What information was exposed
Payment-card information
TJX reported approximately 45.6 million stolen card numbers. It said the investigation could not determine the contents of many files, some files had been deleted in the normal course of business, and some data was already masked or no longer stored in full. The disclosed total therefore should not be read as a perfectly auditable list of every data element copied.
TJX also said customer names and addresses were not included with the payment-card data it believed had been stolen. It said magnetic-stripe Track 2 data was generally not stored after September 2003 and that PIN data and some other transaction information had begun to be masked by April 3, 2006. Those are TJX disclosures, not an independent guarantee about every file.
No-receipt return records
A separate population of approximately 451,000 to 455,000 people who returned merchandise without receipts had personal identifiers exposed, according to the FTC. Depending on the record, information included a name, address, driver’s-license number, military ID, state or tax ID and, in some cases, a Social Security number. That smaller group faced a different and potentially more persistent identity-theft risk than someone whose payment-card number was replaced.
Consumer and bank impact
The FTC said issuing banks reported tens of millions of dollars in fraudulent charges on some accounts and cancelled and reissued millions of cards. A compromised card could mean temporary loss of access while a replacement arrived, but exposure, cancellation, a fraudulent charge and identity theft are separate events.
Consumers could also incur time and expense dealing with replacement cards, account reviews, credit monitoring, identity-theft insurance and, for some no-receipt return customers, replacement identification. TJX’s proposed consumer settlement included three years of credit monitoring and identity-theft insurance for approximately 455,000 affected return customers, with two years for some people who had already accepted an offer; it also contemplated reimbursement for certain license-replacement costs and other relief. The provisions appear in TJX’s SEC filing.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
Legal and financial consequences
Federal litigation in the District of Massachusetts was consolidated into separate tracks for consumers and financial institutions, involving TJX, banks, credit unions, payment networks and Fifth Third Bank and Fifth Third Bancorp. The FTC’s settlement required TJX to establish a comprehensive information-security program with administrative, technical and physical safeguards, and to obtain independent assessments every other year for 20 years. See the FTC announcement and the agency’s case file.
A later Senate report cited an estimated TJX resolution cost of about $25 million. That is not a universal total: estimates may include different combinations of investigation, card replacement, fraud reimbursement, legal work, settlements, monitoring, insurance and remediation. The report also contrasts TJX with Heartland’s later breach: Senate report PDF.
Who was responsible?
Responsibility has several layers: the people who entered TJX systems, those who used or sold stolen card data, and the company’s documented security failures. The Senate report confirms that Albert Gonzalez was later indicted in connection with the TJX and Heartland attacks, but that does not establish a complete “one hacker” account of the operation. Criminal responsibility and corporate control failures are related but distinct questions.
Was TJX really the biggest data breach ever?
In the public record available in March 2007, yes—but only within a defined comparison. It was described as the largest publicly reported payment-card breach and the largest retail security breach, surpassing CardSystems’ approximately 40 million records. It was not a timeless ranking of every kind of personal-data breach. Heartland’s 2009 incident was later reported at about 130 million payment-card numbers, exceeding TJX.
Rankings also change depending on whether a source counts numbers, accounts, records, customers or data fields. The defensible modern wording is: TJX was the largest publicly reported payment-card theft known at the time, involving roughly 45.6 million card numbers.
Quick Recap
Security lessons that still apply
- Encrypt sensitive data. Clear-text storage and transmission turn an internal foothold into a data-extraction opportunity.
- Segment payment environments. Authorization systems should not be broadly reachable from store networks, wireless clients or the public internet.
- Secure wireless access. Restrict, authenticate and monitor every path into corporate systems.
- Require strong, unique authentication. Shared or weak passwords magnify the effect of a stolen credential.
- Patch and manage endpoints. Antivirus, operating-system updates and configuration controls are basic containment measures.
- Centralize detection and response. Alerts must be investigated quickly enough to limit attacker dwell time.
- Minimize retention. Delete or tokenize payment and identity data that the business no longer needs.
What consumers can learn
- Monitor both credit-card and bank-account statements, and enable issuer alerts.
- Report unauthorized transactions promptly and follow the issuer’s replacement instructions.
- Remember that credit cards generally provide stronger dispute protections than debit cards, while neither should be ignored.
- Consider a credit freeze when a driver’s-license number, tax ID or Social Security number may have been exposed.
- Treat credit monitoring as a detection service, not prevention.
- Do not assume that every TJX shopper’s Social Security number was exposed; the FTC tied such data to some no-receipt return records.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




