News

Ukrainian May Have Ties to TJX Theft

A Ukrainian man recently arrested in Turkey is suspected of selling some of the credit and debit card numbers stolen in a data hack of at least 45 million cards of TJX Cos. retail customers, a U.S. investigator said Tuesday.

TJX is the owner of 2,500 discount retail stores worldwide including T.J. Maxx and Marshalls.

Authorities hope the arrest of Maksym Yastremskiy, suspected of being a major international trafficker in stolen data, will eventually lead to information uncovering the TJX intruders' identities.

"He was involved in the distribution of information," Greg Crabb, an agent with the U.S. Postal Inspection Service's global investigations unit, told The Associated Press. "We do have information that suggests other individuals were the masterminds of the hack."

U.S. investigators' interest in Yastremskiy in connection with the TJX case was first reported Tuesday in The Boston Globe. The 24-year-old was arrested weeks ago in the Turkish resort city of Kemer.

Yastremskiy's capture follows the arrests in Florida of 10 people accused of using stolen TJX customer data to buy Wal-Mart gift cards, though they also aren't believed to be the TJX hackers. Several have entered guilty pleas in recent months.

Crabb said information from Turkish officials holding Yastremskiy indicates he was a major trafficker in stolen data from sources including TJX.

"At one particular instance, he had solicited the sale of over a million credit card numbers," Crabb said. "To be able to gain access to that much data, you've got to have a good source."

Crabb said information from credit card issuers pointed to Yastremskiy as the source of illegally trafficked data stolen in the TJX case. Card numbers were allegedly trafficked online and internationally, as is common in identity theft cases that frequently stretch across the globe and often involve Eastern Europe.

TJX disclosed the breach on Jan. 17, and said March 28 that one or more intruders unearthed data from at least 45.7 million credit and debit cards from transactions as long ago as early 2003.

Independent organizations that track data thefts say the TJX case is believed to be the largest in the United States based on the number of customer records compromised.

TJX says about three-quarters of the 45.7 million cards had either expired by the time of the theft, or the stolen information didn't include security code data from the cards' magnetic stripes. However, TJX also has said the intruders could have tapped the unencrypted flow of information to card issuers as customers checked out with their credit cards.

Officials from the U.S. Secret Service and Department of Justice, which also are investigating the TJX case, declined to comment Tuesday, as did a spokeswoman for Framingham, Mass.-based TJX.

Featured

  • Microsoft Offers Support Extensions for Exchange 2016 and 2019

    Microsoft has introduced a paid Extended Security Update (ESU) program for on-premises Exchange Server 2016 and 2019, offering a crucial safety cushion as both versions near their Oct. 14, 2025 end-of-support date.

  • An image of planes flying around a globe

    2025 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • Notebook

    Microsoft Centers AI, Security and Partner Dogfooding at MCAPS

    Microsoft's second annual MCAPS for Partners event took place Tuesday, delivering a volley of updates and directives for its partners for fiscal 2026.

  • Microsoft Layoffs: AI Is the Obvious Elephant in the Room

    As Microsoft doubles down on an $80 billion bet on AI this fiscal year, its workforce reductions are drawing scrutiny over whether AI's ascent is quietly reshaping its human capital strategy, even as official messaging avoids drawing a direct line.