Skip to content

Target

Disclosed Dec 19, 201312 years ago41,000,000 affectedSettled

Official notice

2013 breach of 41M payment cards and 60M contacts; USD 18.5M multistate settlement

Target's 2013 data breach affected more than 41 million customer payment card accounts and exposed contact information for more than 60 million customers. In 2017, 47 states and DC reached a USD 18.5M settlement, then the largest multistate data breach settlement.

What is known

People affected41,000,000 (as reported by the organization)
DisclosedDec 19, 2013
DiscoveredDec 2013
HappenedNov 27, 2013
AttackHacking
Data exposedPayment cards, Names, Addresses, Phone numbers, Emails
SectorRetail · US
StatusSettled
Lawsuit or fineUSD 18.5M 47-state AG settlement (May 2017) (about $19M)

Sources

Notices filed

WhereFiledPeople
ResearchtotalDec 19, 201370,000,000
ResearchtotalDec 19, 201341,000,000
Maine AGresidents of MEDec 19, 2013115,000
California AGresidents of CADec 20, 2013
Maine AGresidents of MEMar 20, 20142,871
Maine AGresidents of MEJun 24, 201489
History of this record
  • 2026-09-25 · source: empty to https://www.maine.gov/ag/sites/maine.gov.ag/files/docs/Data%20breach%20spreadsheet%208-1-2021%20through%2012-5-2018%20REDACTED.xlsx · backfill source
  • 2026-09-25 · lawsuit: $18.5M multistate attorneys general settlement (2017) to USD 18.5M 47-state AG settlement (May 2017) · seed source
  • 2026-09-25 · records: 70000000 to 41000000 · seed source
  • 2026-09-25 · summary: Malware on Target's US point-of-sale registers stole payment card data from about 40 million card accounts between November 27 and December 15, 2013, and the intruder also took names, addresses, phone numbers or emails for up to 70 million to Target's 2013 data breach affected more than 41 million customer payment card accounts and exposed contact information for more than 60 million customers. In 2017, 47 states and DC reached a USD 18.5M settlement, then the largest multistate · seed source
  • 2026-09-25 · title: POS malware steals 40 million payment cards and data on 70 million guests to 2013 breach of 41M payment cards and 60M contacts; USD 18.5M multistate settlement · seed source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 18500000 · seed source
  • 2026-09-25 · lawsuit: empty to $18.5M multistate attorneys general settlement (2017) · seed source
  • 2026-09-25 · sector: tech to retail · seed source
  • 2026-09-25 · attack: unknown to hacking · seed source
  • 2026-09-25 · data_types: [] to ["payment-card","names","addresses","phone","emails"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 70000000 · seed source
  • 2026-09-25 · disclosed: 2013-12-20 to 2013-12-19 · seed source
  • 2026-09-25 · discovered: empty to 2013-12 · seed source
  • 2026-09-25 · summary: empty to Malware on Target's US point-of-sale registers stole payment card data from about 40 million card accounts between November 27 and December 15, 2013, and the intruder also took names, addresses, phone numbers or emails for up to 70 million · seed source
  • 2026-09-25 · title: empty to POS malware steals 40 million payment cards and data on 70 million guests · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Target

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.