Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

TJX Offers Settlement in Wake of Massive Data Breach

Jaikumar Vijayan, Computerworld

  • 0 Yes
  • 0 No

The TJX Companies Inc. is offering three years of credit-monitoring services along with identity theft insurance coverage to all consumers whose driver's license or other personal data may have been compromised by the massive data breach disclosed earlier this year by the retail company.

Consumers who had to replace their driver's licenses because of the compromise will also be reimbursed for the actual replacement costs under a proposed consumer class-action settlement announced by the company on Friday.

In addition, individuals whose driver's license or other ID numbers were the same as their Social Security numbers will be reimbursed for "certain losses from identity theft," the company said. Customers who had to change bank and credit card information because of the breach will receive vouchers redeemable in TJX stores in the U.S, Canada and Puerto Rico. As part of its settlement action, sometime next year TJX will hold a one-time, three-day customer appreciation event at which it will offer a 15 percent discount on all goods.

The settlement is not yet final and is subject to court approval. It is also contingent on an independent evaluation of the information security enhancements implemented by the company in the wake of the breach. TJX did not say how much the proposed settlement would cost. But it noted that the estimated costs were part of its previously announced fiscal 2008 second-quarter charge of US$118 million and fiscal 2009 noncash costs of $21 million.

The proposed settlement, which covers all class actions in the U.S., Canada and Puerto Rico, "addresses the different ways customers have told us they have been impacted by the intrusion(s)," TJX CEO Carol Meyrowitz said in a statement. "Importantly, we truly appreciate our customers' continued patronage. TJX has been working diligently to reach a settlement that offers a good resolution for our customers."

The company's statement is available as an "important customer alert" on the main TJX Web page.

TJX is the owner of a number of retail brands, including T.J. Maxx, Marshalls and Bob's Stores. In January, the company announced that someone had illegally accessed one of its payment systems and made off with card data belonging to an unspecified number of customers in the U.S., Canada, Puerto Rico and potentially the U.K. and Ireland. Later, it revealed that the number of cards compromised in the break-in was 45 million, making it the biggest compromise of personal data ever reported.

The proposed settlement is likely to satisfy consumers, who for the most part appear to have been less concerned about the breach than the media has been, said Khalid Kark, an analyst at Forrester Research Inc. in Cambridge, Mass.

"I think [TJX has] gotten off cheaply" so far, Kark said, noting that neither the company's stock price nor its sales have been affected by the breach. "My overall sense is that people aren't really [as] concerned with these breaches as the media is. It seems like the reaction of the public is, 'It's not such a big deal.' So people may be OK with this settlement."

Kark had earlier this year estimated that costs to TJX from the breach over the next few years could amount to $1 billion. However, so far TJX's own disclosures have pegged breach-related costs at a much lower $150 million.

Computerworld
For more enterprise computing news, visit Computerworld. Story copyright © 2007 Computerworld Inc. All rights reserved.

  • Recommend this story?
  • 0 Yes
    0 No

"TJX Offers Settlement in Wake of Massive Data Breach" Comments

 

Featured APC Accessories

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC Smart-UPS Loaded with cutting-edge features, unique battery life predictor, unbeatable on-line efficiencies and software agents allowing remote UPS monitoring. Get 10% off your entire kart purchase!

People who read this also read:

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links