Breach report
RetailTarget
Forty Million Target Customers Affected By Data Breach
During the 2013 holiday rush, hackers planted malware on Target's checkout registers and siphoned data from roughly 40 million payment cards, then personal details on up to 70 million shoppers, reshaping how U.S. retailers approach payment security.
Reported by Forbes
Records exposed
70M
40 million payment cards; personal data of up to 70 million customers
Scale vs. largest on file
- When
- 2013
- How they got in
- Point-of-sale malware via stolen HVAC vendor credentials
- Sector
- Retail
In the weeks between Black Friday and mid-December 2013, criminals quietly harvested card data from shoppers at nearly every Target store in the United States. The breach first surfaced through security journalist Brian Krebs, and on December 19 Target confirmed that about 40 million credit and debit card accounts used in its stores between November 27 and December 15 may have been compromised. Weeks later, in January 2014, the retailer said a separate set of personal information, including names, mailing addresses, phone numbers and email addresses, belonging to as many as 70 million customers had also been taken.
Investigators traced the intrusion to credentials stolen from Fazio Mechanical, a heating and refrigeration contractor that had network access for billing and project management. Using that foothold, the attackers moved deeper into Target's environment and deployed memory-scraping malware, a variant of the BlackPOS family, onto point-of-sale terminals. The malware captured unencrypted magnetic-stripe data as cards were swiped and staged it on internal servers before exfiltrating it. Later reporting revealed that security tools Target had purchased generated alerts during the intrusion that were not acted upon in time.
The stolen card numbers quickly appeared on underground carding markets, forcing banks to reissue millions of cards during the busiest shopping weeks of the year. Target offered a year of free credit monitoring and said customers would not be liable for fraudulent charges, but holiday traffic and sales dropped sharply as shoppers lost confidence.
The fallout reached the top of the company. Chief information officer Beth Jacob resigned in March 2014, and chief executive Gregg Steinhafel stepped down in May, making him one of the first Fortune 500 CEOs to lose his job in the wake of a cyberattack. Target paid $10 million to settle a consumer class action, reached separate settlements with card issuers including Visa and MasterCard, and in 2017 agreed to an $18.5 million settlement with 47 states and the District of Columbia. All told, the company booked hundreds of millions of dollars in breach-related costs.
The Target case became a textbook example of third-party risk: a small vendor with weak controls opened the door to one of America's largest retailers. It also accelerated the long-delayed U.S. transition to chip-based EMV cards and pushed companies to segment their networks so that a compromised supplier account cannot reach payment systems. For consumers, it was an early lesson in monitoring statements closely and treating breach notifications as a prompt to watch for fraud and phishing.