Q&A about the Target data breach

  • Associated Press
  • Thursday, December 19, 2013 1:31pm
  • Business

NEW YORK — With less than a week until Christmas, a real-life Grinch has stolen the credit and debit card information of about 40 million Target shoppers.

Target says anyone who made purchases by swiping cards at terminals in its U.S. stores between Nov. 27 and Dec. 15 may have had their accounts exposed. The stolen data includes customer names, credit and debit card numbers, card expiration dates and the three-digit security codes located on the backs of cards.

The stolen information included Target store brand cards and major card brands such as Visa and MasterCard.

The data breach did not affect online purchases, the company said.

Here are some answers to the most common questions about the theft:

Q: I shopped at Target during that time. What should I do?

A: Check your credit card statements carefully. If you see suspicious charges, report the activity to your credit card companies and call Target at 866-852-8680. You can report cases of identity theft to law enforcement or the Federal Trade Commission.

You can get more information about identity theft on the FTC’s website at www.consumer.gov/idtheft, or by calling the FTC, at (877) IDTHEFT (438-4338).

Q: How did the breach occur?

A: Target isn’t saying how it happened. Industry experts note that companies such as Target spend millions of dollars each year on credit card security, making a theft of this magnitude particularly alarming.

Experts disagree about how the breach might have happened.

Avivah Litan, a security analyst with Gartner Research, says given all the security, she believes the breach may have been an inside job.

But thefts of this size are too big to be the work of company employees, says Ken Stasiak, founder and CEO of Secure State, a Cleveland-based information security firm that investigates data breaches like this one. Stasiak says that such breaches are generally perpetrated by organized crime or an overseas, state-sponsored hacker group.

Stasiak’s theory is that the hackers were able to breach Target’s main information hub and then wrote a code that gave them access to the company’s point of sale system and all of its cash registers. That access allowed the hackers to capture the data from shoppers’ cards as they were swiped.

James Lyne, global head of security research for the computer security firm Sophos, says something clearly went wrong with Target’s security measures.

“Forty million cards stolen really shows a substantial security failure,” he says. “This shouldn’t have happened.”

Q: Who pays if there are fraudulent charges on my account?

A: The good news is in most cases consumers aren’t on the hook for fraudulent charges.

Credit card companies are often able to flag the charges before they go through and shutdown your card. If that doesn’t happen, the card issuer will generally strip charges you claim are fraudulent off your card immediately.

And since the fraud has been tied to Target, it’ll be the retailer that ultimately compensates the banks and credit card companies.

Q: How can I protect myself?

A: Like they say, cash is king. You can only lose what you’re carrying, though admittedly many people may not feel safe walking around with a wad of bills in their pocket.

As stated before, credit card companies don’t hold consumers liable for charges they don’t make. Usually the worst thing consumers have to deal with is the hassle of getting a new credit card.

And the paper trail generated through credit card transactions can often make it easier do things such as return items you’ve purchased, or keep track of work-related expenses.

It’s worth noting that while debit cards offer many of the same perks as credit cards, without the worry that you’ll spend more than what’s in your bank account, they often don’t come with the same kind fraud protections.

As a result, those card holders may have a tougher time getting their money back if their number is stolen.

Q: How much is this going to cost Target?

A: It’s too soon to tell. In addition to the fraud-related losses, banks may start charging Target a higher merchant discount rate, which is the amount retailers pay banks for providing debit and credit card services. While the percentage difference may be tiny, it could result in steep costs given the volume of transactions Target does, Litan says.

Litan added that the company could also face class action lawsuits from consumers, though most of them will be meritless, and fines from federal agencies. When combined, the costs of the breach could be so steep that they actually prompt Target to raise prices, she says.

“The real winner in this is Wal-Mart,” she says.

Q: Can the bad guys be caught?

A: Stasiak says that given the sophistication of this attack, there’s only about a 5 percent chance that the perpetrators will eventually be caught and prosecuted.

He notes that in cases like this, it’s hard to determine where the attack originated and given the large mass of information involved it’s not going to be found housed on someone’s home computer.

Q: How can future breaches be prevented?

A: Litan says an easy way to prevent fraud would be to eliminate the use of easily cloned magnetic strip cards and upgrade to the kind of microchip technology used in most other parts of the world.

But she says banks have pushed back against the idea, because the microchip cards cost significantly more than the magnetic strip version and changing over all the country’s ATMs could drive the total costs into the billions of dollars.

Lyne says it’s unclear if the use of microchip cards would have prevented the Target breach, since it’s unclear how it happened, but that it certainly wouldn’t hurt.

Q: Why is the Secret Service investigating?

A: While it’s most famous for protecting the president, the Secret Service also is responsible for protecting the nation’s financial infrastructure and payment systems. As a result, it has broad jurisdiction over a wide variety of financial crimes. It isn’t uncommon for the agency to investigate major thefts involving credit card information.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Szabella Psaztor is an Emerging Leader. (Olivia Vanni / The Herald)
Szabella Pasztor: Change begins at a grassroots level

As development director at Farmer Frog, Pasztor supports social justice, equity and community empowerment.

Owner and founder of Moe's Coffee in Arlington Kaitlyn Davis poses for a photo at the Everett Herald on March 22, 2024 in Everett, Washington. (Annie Barker / The Herald)
Kaitlyn Davis: Bringing economic vitality to Arlington

More than just coffee, Davis has created community gathering spaces where all can feel welcome.

Simreet Dhaliwal is an Emerging Leader. (Olivia Vanni / The Herald)
Simreet Dhaliwal: A deep-seated commitment to justice

The Snohomish County tourism and economic specialist is determined to steer change and make a meaningful impact.

Emerging Leader John Michael Graves. (Ryan Berry / The Herald)
John Michael Graves: Champion for diversity and inclusion

Graves leads training sessions on Israel, Jewish history and the Holocaust and identifying antisemitic hate crimes.

Gracelynn Shibayama, the events coordinator at the Edmonds Center for the Arts, is an Emerging Leader. (Olivia Vanni / The Herald)
Gracelynn Shibayama: Connecting people through the arts and culture

The Edmonds Center for the Arts coordinator strives to create a more connected and empathetic community.

Eric Jimenez, a supervisor at Cocoon House, is an Emerging Leader. (Olivia Vanni / The Herald)
Eric Jimenez: Team player and advocate for youth

As an advocate for the Latino community, sharing and preserving its traditions is central to Jimenez’ identity.

Nathanael Engen, founder of Black Forest Mushrooms, an Everett gourmet mushroom growing operation is an Emerging Leader. (Olivia Vanni / The Herald)
Nathanael Engen: Growing and sharing gourmet mushrooms

More than just providing nutritious food, the owner of Black Forest Mushrooms aims to uplift and educate the community.

Molbak's Garden + Home in Woodinville, Washington closed on Jan. 28 2024. (Photo courtesy of Molbak's)
Molbak’s, former Woodinville garden store, hopes for a comeback

Molbak’s wants to create a “hub” for retailers and community groups at its former Woodinville store. But first it must raise $2.5 million.

DJ Lockwood, a Unit Director at the Arlington Boys & Girls Club, is an Emerging Leader. (Olivia Vanni / The Herald)
DJ Lockwood: Helping the community care for its kids

As director of the Arlington Boys & Girls Club, Lockwood has extended the club’s programs to more locations and more kids.

Alex Tadio, the admissions director at WSU Everett, is an Emerging Leader. (Olivia Vanni / The Herald)
Alex Tadio: A passion for education and equality

As admissions director at WSU Everett, he hopes to give more local students the chance to attend college.

Dr. Baljinder Gill and Lavleen Samra-Gill are the recipients of a new Emerging Business award. Together they run Symmetria Integrative Medical. (Olivia Vanni / The Herald)
Emerging Business: The new category honors Symmetria Integrative Medical

Run by a husband and wife team, the chiropractic and rehabilitation clinic has locations in Arlington, Marysville and Lake Stevens.

People walk along the waterfront in front of South Fork Bakery at the Port of Everett on Thursday, April 11, 2024 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett inks deal with longtime Bothell restaurant

The port will break ground on two new buildings this summer. Slated for completion next year, Alexa’s Cafe will open in one of them.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.