Target
Disclosed Dec 19, 201312 years ago41,000,000 affectedSettled
2013 breach of 41M payment cards and 60M contacts; USD 18.5M multistate settlement
Target's 2013 data breach affected more than 41 million customer payment card accounts and exposed contact information for more than 60 million customers. In 2017, 47 states and DC reached a USD 18.5M settlement, then the largest multistate data breach settlement.
What is known
| People affected | 41,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Dec 19, 2013 |
| Discovered | Dec 2013 |
| Happened | Nov 27, 2013 |
| Attack | Hacking |
| Data exposed | Payment cards, Names, Addresses, Phone numbers, Emails |
| Sector | Retail · US |
| Status | Settled |
| Lawsuit or fine | USD 18.5M 47-state AG settlement (May 2017) (about $19M) |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Targetoag.ca.gov · Official notice | Official notice |
| Attorney General Becerra: Target Settles Record $18.5 Million Credit Card Data Breach Caseoag.ca.gov · Regulator | Regulator |
| Target Corp Form 10-K for fiscal 2013sec.gov · SEC filing | SEC filing |
| Target confirms encrypted PIN data stolenusatoday.com · News | News |
| NY AG: Letter to Target regarding data breachag.ny.gov · Regulator | Regulator |
| NY AG: USD 18.5 Million Multi-State Settlement With Targetag.ny.gov · Regulator | Regulator |
| Maine Attorney General breach notice archive: Targetmaine.gov · Official notice | Official notice |
Notices filed
History of this record
- 2026-09-25 · source: empty to https://www.maine.gov/ag/sites/maine.gov.ag/files/docs/Data%20breach%20spreadsheet%208-1-2021%20through%2012-5-2018%20REDACTED.xlsx · backfill source
- 2026-09-25 · lawsuit: $18.5M multistate attorneys general settlement (2017) to USD 18.5M 47-state AG settlement (May 2017) · seed source
- 2026-09-25 · records: 70000000 to 41000000 · seed source
- 2026-09-25 · summary: Malware on Target's US point-of-sale registers stole payment card data from about 40 million card accounts between November 27 and December 15, 2013, and the intruder also took names, addresses, phone numbers or emails for up to 70 million to Target's 2013 data breach affected more than 41 million customer payment card accounts and exposed contact information for more than 60 million customers. In 2017, 47 states and DC reached a USD 18.5M settlement, then the largest multistate · seed source
- 2026-09-25 · title: POS malware steals 40 million payment cards and data on 70 million guests to 2013 breach of 41M payment cards and 60M contacts; USD 18.5M multistate settlement · seed source
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · fine_usd: empty to 18500000 · seed source
- 2026-09-25 · lawsuit: empty to $18.5M multistate attorneys general settlement (2017) · seed source
- 2026-09-25 · sector: tech to retail · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · data_types: [] to ["payment-card","names","addresses","phone","emails"] · seed source
- 2026-09-25 · records_basis: empty to organization · seed source
- 2026-09-25 · records: empty to 70000000 · seed source
- 2026-09-25 · disclosed: 2013-12-20 to 2013-12-19 · seed source
- 2026-09-25 · discovered: empty to 2013-12 · seed source
- 2026-09-25 · summary: empty to Malware on Target's US point-of-sale registers stole payment card data from about 40 million card accounts between November 27 and December 15, 2013, and the intruder also took names, addresses, phone numbers or emails for up to 70 million · seed source
- 2026-09-25 · title: empty to POS malware steals 40 million payment cards and data on 70 million guests · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.