Skip to main content

Target ignored warnings before hackers stole 70 million credit cards, says new report

During the heat of the 2013 holiday season, retailer Target lost the payment data, addresses, phone numbers, and names of some 70 million customers. As it turns out, the massive data breach was preventable if Target took more proactive steps to combat it, according to a detailed five-page report by Bloomberg Businessweek.

Here’s what happened: Someone installed malware in Target’s security and payments system. So every time someone scanned their credit card, it was sent to a special server, owned by Target, that hackers controlled.

Recommended Videos

Shortly before falling prey to the hack, Target began employing new network monitoring tools, working in concert with FireEye, a firm that specializes in Internet security. A Computerworld report claims that security specialists based in India spotted warning signs prior to the breach and reported their findings to Target’s headquarters in Minnesota.

On November 30, FireEye sent alerts to Target identifying that malware named “malware.binary” was present on the retailer’s networks, and figured out which servers the hackers had taken over. As instances of the malware increased, additional alerts were sent. Each notification was accompanied with the highest rating of severity in accordance with FireEye’s threat scaling system. But Target reportedly did not respond to these alerts.

Because the network monitoring tools used by Target had not been fully tested and configured at the time, an option that would have allowed the security system to automatically terminate the threat was not enabled. Had it been active, the entire threat could have been dealt with while the security system was essentially running on autopilot. The team in charge of Target’s security ignored the warnings.

Molly Snyder, a Target spokeswoman, says the retailer initially investigated signs of the hacks, but failed to act on any of the warning signs they found early on: “Based on their interpretation and evaluation of that activity, the [Target security] team determined that it did not warrant immediate follow up,” she said. “With the benefit of hindsight, we are investigating whether, if different judgments had been made, the outcome may have been different.”

A U.S. Congressional investigation into the matter is currently ongoing.

Topics
Konrad Krawczyk
Former Digital Trends Contributor
Konrad covers desktops, laptops, tablets, sports tech and subjects in between for Digital Trends. Prior to joining DT, he…
It’s not your imagination — ChatGPT models actually do hallucinate more now
Deep Research option for ChatGPT.

OpenAI released a paper last week detailing various internal tests and findings about its o3 and o4-mini models. The main differences between these newer models and the first versions of ChatGPT we saw in 2023 are their advanced reasoning and multimodal capabilities. o3 and o4-mini can generate images, search the web, automate tasks, remember old conversations, and solve complex problems. However, it seems these improvements have also brought unexpected side effects.

What do the tests say?

Read more
Ray-Ban Meta Glasses are my favorite AI gadget, and they keep getting better
Ray-Ban Meta Glasses worn by Prakhar Khanna.

Meta announced its Ray-Ban AI Glasses in October 2023, and while the company hasn’t launched a successor yet, it has steadily expanded the feature set, turning them into my favorite AI gadget. These are all quality-of-life upgrades that would ideally be released with the next-gen product. But Meta has announced the expansion of Ray-Ban Meta Glasses to more regions and new Meta AI features rolling out starting this week.

I bought a pair of Headliner Meta Ray-Bans in January 2024, and they’ve been my travel companion ever since. It's not because I can record videos while on the go, but because they are the first AI device that doesn’t scream AI. The ambient presence of tech is what makes them special, and they’re only improving, even after 18 months since launch.

Read more
Apple’s low-cost Vision Pro headset could land sooner than expected
A person pinches while wearing an Apple Vision Pro.

Apple’s Vision Pro headset, despite being the most advanced XR gear of its kind, wasn’t quite the roaring success the company may have expected. An asking price worth $3,500 was certainly a deterrent for enthusiasts, but the lack of a full-fledged computing ecosystem built around it was also a lackluster show.

The company has, however, no intention of giving up. On the contrary, Apple is working on a more affordable, watered-down version, and it could arrive sooner than expected. According to Bloomberg, there’s a chance the headset might make an appearance later this year, possibly around the same window as the iPhone 17 series.

Read more