US retailer Target confirmed that attackers had stolen data from up to 40 million credit and debit cards used in its stores. The breach was first reported by journalist Brian Krebs on 18 December 2013, and Target confirmed it the following day.
What happened
- Card data was stolen from point-of-sale systems between late November and mid-December 2013, covering the busy Thanksgiving shopping period.
- Stolen data included customer names, card numbers, expiry dates, and security codes.
- In January 2014, Target said personal information on up to 70 million people had also been taken.
- Investigations later found the attackers had first gained access using credentials stolen from a third-party supplier.
Why it mattered
The breach was one of the largest retail breaches at the time, led to the departure of Target’s chief executive, and accelerated the US move to chip-and-PIN (EMV) cards.
Lessons for organisations
Organisations should limit supplier access to only the systems needed and segment networks so a supplier compromise cannot reach payment systems. Acting quickly on security alerts is just as important as having monitoring tools.
Sources: Krebs on Security, The Washington Post
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.