44: 12 Years Later: How the TJX Hack Changed Security and Compliance
12m 31s
The podcast episode discusses the monumental 2007 TJX data breach through an interview with Mike Drasher, a former TJX infrastructure engineer. The breach, occurring over 18 months, resulted in the theft of 46 to 90 million credit and debit card numbers from TJX companies like TJ Maxx and Marshalls. Drasher recounts first noticing a suspicious application during routine system maintenance, which was initially deleted but reappeared months later, prompting a full-scale investigation involving the FBI. The attack was orchestrated by hacker Albert Gonzalez, who was later convicted and sentenced to 20 years in prison. Following the breach, TJX dramatically increased its security protocols, underwent frequent audits, and expanded its cybersecurity team. The conversation also highlights how the event influenced global data protection regulations, emphasizing the need for companies to be held accountable for customer data security. Drasher reflects on the stressful remediation process but notes that such breaches are an inherent risk in IT, underscoring the ongoing challenge of staying ahead of cyber threats.
[MUSIC] You're listening to DeFrag This, a podcast for IT Pros. If you're looking for meaningful trends, commentary on breaking news, and more, you've come to the right place. Let's turn it over to your host, Greg Mooney. [MUSIC] Welcome to DeFrag This. This is your host, Jeff Edwards, and today we have in the studio a very special guest who can give us an insider's look at a monumental moment in hacker history. The TJX hack way back in 2007. Mike Drasher is a senior integrations engineer here at Ipswich. But back in 2007, he was an infrastructure engineer at TJX. Welcome to the show, Mike. >> Hey, thank you very much. Now, before we dive in, I just want to jog some of our listeners' memory because while this hack was huge, it's also each in history by cybersecurity standards. I think when we first met, I said, I was trying to remember. And I thought I was at my previous job when this happened, but I was actually thinking of the target hack. I was a freshman in college during the TJX hack. So, 12 years is a long time. And so, at the time of its discovery in 2007, the TJX data reach was one of the biggest breaches of consumer data in the history of the US. Over an 18-month period, at least 46 million credit and debit card numbers were stolen. And that number could be up to about 90 million from TJX, which was the parent company of Marshall's TJ Maxx and Home Goods. And TJX hackers were led by Albert Gonzalez, who would later be convicted to 20 years in federal prison for his part in the attack. As well as the hack of Dave and Buster's and the Heartland payment systems attack. That sentence is still the lengthiest ever imposed for hacking or identity theft. So, it was a big deal at the time. So, Mike, why don't you take me back to the beginning? What were you doing at TJX at the time of the attack? Well, my main job was to just do operating system maintenance and uptake and upkeep. So, I was doing a routine maintenance and saw some rogue data or rogue, I should say rogue application on one of my systems. So, was you personally where the first one to see that? Technically, yes. I was the first one to see that at the time, one of my managers, but brought it to his attention and he wasn't sure what it was. So, we just technically deleted it. Yeah. And ended up a few months later, it came back on. So, what we noticed that it came back on, it was brought to our attention through another party that there was something else that was possibly going on. So, they had us look at this information again and that's when I discovered that the application was back. So, it happened twice and I noticed that the hacker, Albert Gonzalez, when he got busted from the Dave and Buster's hack, which was like a little bit after this, they had continued, whatever the siphoning they had going on, which shut down every time the computers were shut down and was deleted. So, they had to keep going back to Dave and Buster's to install it again. So, I'm wondering if that was actually happening at TJX. That's interesting. So, after the second time, that was when you guys notified your security team and remediation efforts began. Yeah, a lot of remediation efforts started beginning from that point on, yes. And were you involved in that? For the most part, yeah. Yeah. We were working with the FBI and, you know, in cyber security people to slowly trace down where it came from and how it got there and stuff like that. Yeah, and how long did it take before you guys realized the full extent of the. That's hard to say, but it was a good couple of weeks if not a month before, you know, we've. I think they finally were anchoring it down to where it came from. Yeah. That was probably a pretty stressful period for you guys, I think. Oh yeah, we were working diligently for a long time, a lot of hours. Yeah. You lose sleep over that. Yeah. Yeah, I can imagine. I mean, just being in the room for something like that, I can't even imagine. Was that the time of the biggest hack? Do you guys have any idea of the scope of that? I know at the time it was the biggest hack. I'm not sure if it still is, but. I don't think it is still. I think it's been surpassed by, you know, aquifax and things like that. Yeah, I believe so. But was it just another incident at first or did you know that it was this was something big? No, to us, to at least to me, it was just a new incident that we were taking care of just that it was on a big larger scale. Yeah. I didn't know how large of a scale until after the fact, so. Yeah. Yeah. And how long did you stay at TGX after the. Well, till last year, so. Oh, really? Yeah, good amount time, yeah. I was at TGX for 19 years total. 19 years, okay. So did the culture change significantly after that? Oh, definitely. Security was 100% tenfold beefed up. To what it is now today, it's one of the major points of IT there now. Yeah, I can imagine they don't want to have another incident like that. Oh, definitely not. And was that was the regulators? Was that like a right where they up in, you know, business afterwards? Yes, every year, twice a year, there's regulators there, so. Two audits. Oh, yeah. Well, there's multiple than two audits, but that's just, you know, there's, there's, you know, PCI audits and AT&T audits, so. Yeah. Multiple different audits, yeah. Yeah, TGX eventually paid out $9.7 million in a settlement to like 41 states. But the company has firmly denied that it was negligent at all and allowing the attack to happen. But in 2004, an audit of its security systems found high level deficiencies. So, did it, something that you think would have happened, regardless of, you know, the security there? Or do you think if they, they were higher standards, it wouldn't have gone. There's always someone smarter. There's always someone figuring out a better way to get around security. So, eventually, what had happened to, and it could have happened to anybody. Yeah. Yeah. That's true. I mean, you, every day, the government attacked. Yeah. I mean, they're not exactly. They're not exactly lacks. Yeah. So, not exactly lacks. But also, I mean, the OPM hack was the systems there were not really up to, spec, you know. It's hard to keep on top of all of it. It's, I mean, especially with the vast amount of systems, it's hard to keep on top of all of it. Yeah, yeah, yeah, absolutely. So, what would you consider the crucial steps to preventing an attack like this from happening? Go paper. No, but it's just due diligence, really. It's just trying to be one step ahead of all the new technology, all the new, you know, the, the smarter, the smarter hackers, basically higher hackers. Yeah. You know, they're one step ahead of you already. So, why not have them on your side? Yeah, that's a good point. Was that something you saw happening at TJAX after the event? They did hire some, I don't want to say high level hackers, but they did hire very well-trained security people who know what they're doing. So, yes. Yeah. And did you see a lot more, you know, third-party security companies consultants and things like that around after that? Yeah, I'll definitely. Yeah, definitely. So, it sounds like you don't really blame TJAX or any lack of it. Not at all. No, it was bound to happen to somebody. It's sad that it just happened at that time. It was too to the company that I was employed at. Yeah. Yeah. After that, this attack prompted credit bureaus to seek legislation, requiring retailers to be responsible for the compromised customer information, saved in their systems. And now, 10 years later, we're finally starting to see that kind of legislation gains steam globally with the global data protection regulation in Europe. And other GDPR type regulations cropping up in Brazil, UK and states across the US. Do you think that type of regulation is a good idea? Do you think holding companies to a higher level of accountability will force them to be more prepared for attacks like this or like-- Definitely. Yeah. Yeah, definitely. It's your customer is trusting you to keep their information safe. So, the company should be held responsible, I believe. Yeah. So, do you think that sort of regulation would be a good idea in the US as a-- I have a regulation, yeah. Yeah. And anything to tighten it up would be great for that, I believe. Yeah. Because at the time of the attack, I mean, TJX was PCI compliant. So-- And that was the only real regulation for that card data that you had to comply to. So, if you're compliant and you're still able to fall victim to attack on that scale, I mean, what does that say about the regulations? Yeah, they weren't tough enough then. They're getting tougher now. Yeah. We hope so. All right, so take me back to when the attack first started. You guys are working, you know, 15 hour days to take care of this. What were the some of the steps you were taking to remediate? Well, we were, you know, still trying to keep our systems up and running for daily routine. So, you know, you couldn't take the credit switch offline or anything like that. So, we would build systems and new systems and swap the active systems to over to the newer systems just so we could do the forensics on the systems to find out what was being done and how it was being done and to that effect. And were you guys able to trace it back to the attackers yourself? Or was that something the FBI did connecting it to Alpregans, Alas? Yeah, the FBI with the forensics teams.
We're able to trace it back to, I believe, was a storm in Miami. - Really? It was a retail store. - Yeah. - It was first hacked. So, it's similar to how he did the Dave and Buzzer's hack. - Yeah, I believe it was, if I remember correctly, it was through a Wi-Fi connection. - Okay, so. - Prior to the new stronger ones. - Yeah, exactly. - Yeah, that's not really a, it's still a point of attack, but not on that scale anymore. - Oh, not at all. - Yeah. So, after during the remediation process, you guys traced it back to Albuquerque and Zollis and that crew, and then what was the next step from there? Did that where prosecution began? Or? - It's not a year. - That was really out of my range. I did, you know, another stress that was added on it, I had to be deposed in Boston, a state street. So, they wanted to make sure that people were being lining up and up because we were so heavily involved in it. - Yeah, well, at the end of the day, do you have ill will towards the hackers for, you know, ruining your year, your month, or whatever it was? - Well, of course. (laughing) It's a job. It was a job and I did my best and I loved my job. So, yeah, it was a little added on stress and a lot of added on time. That, yeah, I wish they didn't do anything. So, I had some of my life back, but it happens. You know, that's part of being the job. It's part of being in the IT world. - Yeah. - Especially with all the security that's out there now. Yeah, you gotta be on top of it. - Yeah. So, I think that's about all we need from you today. And I really appreciate you coming in here. - No problem, thank you for having me. - And talking to us, yeah. Thanks again and to all of our listeners, if you guys have any questions for Mike, he is in house here at Ipswitch, so maybe we can bother him and try to get him back on the show. Just a comment below with any questions and as usual, stay safe out there, folks. - Thanks for listening to Defrag This. If you enjoy the show, you can find more from Ipswitch on Twitter, @Ipswitch, or on Facebook. And be sure to subscribe to the Defrag This Blog at blog.ipswitch.com. Thank you so much for listening. Until next time.
Podcast Summary
Key Points:
The TJX data breach in 2007 was one of the largest consumer data breaches in U.S. history, compromising 46-90 million credit/debit card numbers over 18 months.
Mike Drasher, a TJX infrastructure engineer at the time, first discovered a rogue application during routine maintenance, which was deleted but later reappeared, leading to the full investigation.
The attack was led by Albert Gonzalez, who received a 20-year prison sentence—the longest ever for hacking/identity theft at that time.
Post-breach, TJX significantly enhanced its security measures, faced regular audits, and hired specialized security personnel.
The incident spurred discussions about stronger data protection regulations, like GDPR, to hold companies more accountable for safeguarding customer information.
Summary:
The podcast episode discusses the monumental 2007 TJX data breach through an interview with Mike Drasher, a former TJX infrastructure engineer. The breach, occurring over 18 months, resulted in the theft of 46 to 90 million credit and debit card numbers from TJX companies like TJ Maxx and Marshalls. Drasher recounts first noticing a suspicious application during routine system maintenance, which was initially deleted but reappeared months later, prompting a full-scale investigation involving the FBI.
The attack was orchestrated by hacker Albert Gonzalez, who was later convicted and sentenced to 20 years in prison. Following the breach, TJX dramatically increased its security protocols, underwent frequent audits, and expanded its cybersecurity team. The conversation also highlights how the event influenced global data protection regulations, emphasizing the need for companies to be held accountable for customer data security.
Drasher reflects on the stressful remediation process but notes that such breaches are an inherent risk in IT, underscoring the ongoing challenge of staying ahead of cyber threats.
FAQs
The TJX hack in 2007 was one of the largest consumer data breaches in U.S. history, involving the theft of at least 46 million credit and debit card numbers over 18 months from the parent company of stores like TJ Maxx and Marshalls.
An infrastructure engineer at TJX noticed a rogue application during routine system maintenance, deleted it, and later found it had reappeared, prompting further investigation and involvement of security teams.
The attack was led by Albert Gonzalez, who was later convicted and sentenced to 20 years in federal prison, the longest sentence ever imposed for hacking or identity theft at that time.
Following the breach, TJX significantly enhanced its security measures, making it a major focus in IT, and began undergoing regular audits such as PCI compliance checks to prevent future incidents.
The breach highlighted the need for stronger data protection laws, leading to initiatives like GDPR in Europe and similar regulations globally to hold companies more accountable for safeguarding customer information.
Remediation involved building new systems to maintain operations while conducting forensics on compromised systems, collaborating with the FBI to trace the attack back to its source, and enhancing overall security protocols.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.