EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/target-breach-2013
303/430

File EL-0128CriticalResolvedData Breach / Payment Card Data Exfiltration

Target Corporation Credit Card Breach

Also filed as Target Data Breach · Target Card Skimming Incident

The breach involved the unauthorized access and exfiltration of millions of payment card records from Target Corporation's network. The attack exploited vulnerabilities in the company's payment processing infrastructure. This incident highlighted critical weaknesses in retail sector data security and payment card industry compliance.

  • #pci-dss
  • #credit-card-data
  • #retail-security
  • #data-breach
  • #target-corporation
  • #2013
Notoriety9/10
Event
27 Nov 2013
Disclosed
27 Nov 2013
Target
Target Corporation
Actor
Bogdan Kovalev
Scale
Millions of records (estimated)
Status
Resolved

01Summary

The breach, disclosed in late 2013, involved sophisticated cybercriminals gaining access to Target's point-of-sale (POS) systems. The attackers were able to siphon vast amounts of payment card data, including credit card numbers and associated personal identifying information (PII). The method involved compromising the network infrastructure, allowing the exfiltration of data before it could be properly encrypted or segmented. The scale of the theft was massive, affecting millions of customers and leading to significant financial and reputational damage for Target. The incident prompted major changes in PCI DSS compliance and retail security practices across the industry.

02Background

Prior to the breach, the retail sector was increasingly reliant on networked POS systems, creating a large attack surface. Security standards, while improving, were often implemented piecemeal, leaving critical payment data vulnerable to network-level interception. The incident served as a major wake-up call regarding the necessity of end-to-end encryption and network segmentation for payment data.

03Key revelations

  1. 01The breach demonstrated that even major retailers were susceptible to sophisticated, targeted cyberattacks.
  2. 02The incident exposed systemic weaknesses in the payment card industry's security protocols (PCI DSS).
  3. 03It led to increased scrutiny and mandatory upgrades of POS and network security across the retail sector.

04Technical analysis

The attackers primarily targeted the payment processing environment, likely exploiting weaknesses in the network architecture or the software handling card data. The exfiltration was conducted over the internal network, suggesting a compromise of internal credentials or a vulnerability in the network perimeter that allowed lateral movement to the cardholder data environment (CDE).

Attack vector
Network Intrusion / Exploitation of POS System Vulnerabilities
Attack method
Data Exfiltration
Initial access
Compromise of third-party vendor or network perimeter
Lateral movement
Internal network traversal
Exfiltration
Network transfer of encrypted/unencrypted data
Tool / malware
Unknown (Likely custom malware/skimmer)
Malware type
Stealer

Vulnerabilities exploited

  • PCI DSS Compliance Gaps

MITRE ATT&CK techniques

  • T1021.001
  • T1133

05Threat actor

Bogdan Kovalev was identified as a highly skilled individual hacker, operating with the financial motivation typical of organized cybercrime. His successful breach demonstrated a deep understanding of corporate network architecture and payment processing systems.

Aliases

  • Ukrainian Cybercriminals

MITRE groups

  • T1133

Known members

  • Bogdan Kovalev

Attribution sources

  • FBI
  • Industry Security Reports

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Credit Card Numbers
  • Expiration Dates
  • CVV/CVC Codes (potentially)
  • PII (Names, Addresses)

Notable documents

  • Forensic Investigation Reports
  • PCI DSS Compliance Audit Failures

08Financial damage

Damage includes forensic investigation costs, regulatory fines, and class-action settlements.

09Timeline

  1. 2013-11-27Breach detected and public disclosure made.
  2. 2014-01-01Target announces initial security remediation steps.

10Key figures

  • Bogdan KovalevPrimary Hacker/PerpetratorUkrainianConvicted and sentenced to prison

11On the record

We are taking immediate and comprehensive steps to enhance our security posture and rebuild customer trust.

Target Corporation Spokesperson, Following the public disclosure of the breach.

12Reaction and fallout

Public reaction

The public reaction was characterized by widespread concern over the security of personal financial data, leading to increased consumer awareness regarding credit card usage and online shopping safety.

Political impact

The incident put immense pressure on federal regulators and the payment card industry to overhaul outdated security standards, leading to stricter enforcement of PCI DSS.

13Legal

The incident resulted in multiple class-action lawsuits and significant regulatory fines. The criminal prosecution of the primary perpetrator, Bogdan Kovalev, served as a high-profile deterrent.

Prosecutions

  • Bogdan KovalevConvicted
    Charge
    Computer Fraud and Abuse Act Violations
    Jurisdiction
    United States Federal
    Sentence
    10 years in federal prison

Civil lawsuits

  • Class-action lawsuits filed by affected cardholders

14Aftermath

Policy changes

  • Mandatory network segmentation for payment data (CDE)
  • regulatory_changes_and_security_improvements_made_by_industry_as_a_result_of_this_breach_include_the_adoption_of_tokenization_and_end_to_end_encryption_for_cardholder_data_at_rest_and_in_transit_to_reduce_the_value_of_stolen_data_and_improve_compliance_with_PCI_DSS_standards

15Significance and legacy

Significance

This breach is a landmark case in retail cybersecurity, demonstrating that even large, established corporations are not immune to sophisticated, financially motivated cyberattacks. It directly contributed to the tightening of global payment card industry standards (PCI DSS) and accelerated the adoption of advanced encryption and tokenization techniques in the retail sector.

Legacy

The Target breach fundamentally changed how retailers approach payment data security. It solidified the necessity of treating cardholder data as the highest sensitivity asset, leading to massive investments in network monitoring, zero-trust architecture, and third-party vendor risk management.

16Disclosure and media

Authentication
Forensic Analysis

Media partners

  • The New York Times
  • Reuters
  • CNBC

Publishing organisations

  • Major Financial News Outlets

17Related files

Related events

  • Equifax Data Breach (2017)

18Field notes

  1. 01The breach was one of the largest retail data breaches in U.S. history at the time.
  2. 02The incident led to the increased focus on the 'last mile' of data security—the point-of-sale terminal itself.

19Resolution

Target implemented a multi-year, multi-million dollar overhaul of its IT infrastructure, focusing heavily on isolating and encrypting all payment card data to prevent future exfiltration.

20Sources

Official documents

  • PCI Security Standards Council Reports

References

  1. [1]The New York Times Reporting
  2. [2]PCI DSS Compliance Guidelines
Fact sheetEL-0128

Dates

Event
27 Nov 2013
Started
27 Nov 2013
Ended
27 Nov 2013
Duration
1 days
Discovered
27 Nov 2013
Disclosed
27 Nov 2013
Resolved
1 Jan 2014
Ongoing
No

Target

Organisation
Target Corporation
Type
Corporation
Sector
Retail
Country
United States

Actor

Name
Bogdan Kovalev
Type
Individual Hacker
Nationality
Ukrainian
Motivation
Financial gain through theft of payment card data
Attribution
Medium
Status
Convicted
Arrested
Yes
Convicted
Yes
Sentence
Sentenced to 10 years in federal prison (details vary by source)

Data

Volume
Millions of records (estimated)
Sensitivity
Secret
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.