TJX Rumor: Attacks Used Employment Kiosks
Written by Evan SchumanMarch 15th, 2007
More TJX rumors flying around. This one–which seems only a little wackier than some of the stranger rumors–has that the TJX data breach was launched via job-application kiosks.
The story ran in Dark Reading. I mostly note it because the writer–Kelly Jackson Higgins–is a very top-notch pro whose work I knew years ago.
Like any good reporter, she both reports the kiosk theory and lays out the theory’s weaknesses, including methods for getting the data to be returned to them. Interesting reading.
Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code.
-Marc
