← All enforcement actions
PCI DSSFTC ActRetail

TJX Companies~$256M PCI fine (2007)

The breach that wrote PCI DSS — 94M cards stolen via insecure WEP wireless

Penalty
~$256M
Regulator
FTC + state AGs + card networks
Jurisdiction
United States
Records affected
94M

What happened

Attackers parked outside a Minnesota Marshalls and broke the store's WEP wireless encryption, pivoting to corporate networks and exfiltrating 94M card numbers over 18+ months. The total cost — fines, card-network assessments, settlements, and remediation — exceeded $256M and accelerated the PCI DSS 1.2 wireless requirements.

Root cause

What every team should do

  1. PCI DSS Req 4.1 / 11.1 — strong wireless cryptography + scanning for rogue APs
  2. Segment store / branch networks from the cardholder data environment
  3. FIM on POS systems is non-negotiable (PCI DSS Req 11.5)
Source: TJX 10-K (Mar 2007), FTC settlement (Mar 2008).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which PCI controls you are missing — mapped to enforcement patterns like this one.

Run my PCI audit Generate missing policies

Related enforcement actions

Equifax
$700M+
Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days
BetterHelp
$7.8M
Disclosed sensitive mental-health data to Meta / Snap ad pixels
Target
~$202M
HVAC vendor credentials → 40M payment cards + 70M customer records