TK Maxx's parent pays out $9.75 million for data breach
The UK clothing retailer's parent company TJX pays out millions for a data breach, but still claims it did not violate any data security laws.

TJX, which owns UK high street favourite TK Maxx, has agreed to pay out $9.75 million in a settlement over data thefts in 2005 and 2006.
International criminals attacked TJX's computer network in 2005 and 2006, which resulted in millions of card accounts being used to defraud credit and debit card users in the US, Europe and Asia.
Although it paid out the settlement, TJX said it "firmly believes" that it did not violate any consumer protection or data security laws.
The company claimed it reached the settlement so that it could concentrate on its core business and to promote cyber security measures.
"The sheer number of attacks by cyber criminals demonstrates the challenges facing the US payment card system in protecting sensitive consumer data," said Jeffrey Naylor, chief financial officer of TJX in a statement.
Last year, the US Attorney announced 11 indictments over the data thefts, with four individuals pleading guilty over related charges.
Get the ITPro. daily newsletter
Sign up today and you will receive a free copy of our Focus Report 2025 - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Multichannel attacks are becoming a serious threat for enterprises – and AI is fueling the surge

Cobalt Strike abusers have been dealt a hammer blow: An "aggressive" takedown campaign by Fortra and Microsoft shuttered over 200 malicious domains – and it’s cut the misuse of the tool by 80%