Target stores' customers hit by major credit card attack

Published December 19, 2013
Shoppers are seen at a Target store during Black Friday sales in the Brooklyn borough of New York, November 29, 2013. — Reuters Photo
Shoppers are seen at a Target store during Black Friday sales in the Brooklyn borough of New York, November 29, 2013. — Reuters Photo

Payment card data was stolen from an unknown number of Target Corp customers starting on the busy Black Friday weekend in a major breach at the US retailer, according to a person familiar with the matter.

The Secret Service is investigating, according to a spokesman for the agency, which safeguards the nation's payment systems. Target officials did not respond to requests for comment.

Investigators believe the data was obtained via software installed on machines that customers use to swipe magnetic strips on their cards when paying for merchandise at Target stores, according to the person who was not authorized to discuss the matter and declined to provide further details.

Krebs on Security, a closely watched security industry blog that broke the news, said the breach involved nearly all of Target's 1,797 stores in the United States, citing sources at two credit card issuers. The report said that "track data" from at least 1 million payment cards was thought to have been stolen before Target uncovered the operation, but that the number could be significantly higher.

"When all is said and done, this one will put its mark up there with some of the largest retail breaches to date," the report cited an unnamed source as saying.

The biggest credit card breach at a US retailer reported to date was an attack against TJX Cos, the parent of TJ Maxx and Marshalls. The company disclosed in March 2007 that data from 45.7 million payment cards had been stolen by hackers over 18 months. Banks later asserted in court documents the hackers could have obtained more than 94 million account numbers.

The data breach at Target could have extended from just after Thanksgiving to December 15, Krebs said, citing evidence from investigators.

It is not yet clear how the attackers were able to compromise point-of-sales terminals at so many Target stores across the country. Doing so would have required careful planning by sophisticated cyber criminals.

An American Express spokeswoman said the company is aware of the incident and is putting fraud controls in place.

Opinion

Editorial

Hasty transition
Updated 05 May, 2024

Hasty transition

Ostensibly, the aim is to exert greater control over social media and to gain more power to crack down on activists, dissidents and journalists.
One small step…
05 May, 2024

One small step…

THERE is some good news for the nation from the heavens above. On Friday, Pakistan managed to dispatch a lunar...
Not out of the woods
05 May, 2024

Not out of the woods

PAKISTAN’S economic vitals might be showing some signs of improvement, but the country is not yet out of danger....
Rigging claims
Updated 04 May, 2024

Rigging claims

The PTI’s allegations are not new; most elections in Pakistan have been controversial, and it is almost a given that results will be challenged by the losing side.
Gaza’s wasteland
04 May, 2024

Gaza’s wasteland

SINCE the start of hostilities on Oct 7, Israel has put in ceaseless efforts to depopulate Gaza, and make the Strip...
Housing scams
04 May, 2024

Housing scams

THE story of illegal housing schemes in Punjab is the story of greed, corruption and plunder. Major players in these...