First reportedDecember 19, 2013
ActivityActivity date not specified
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Target shoppers in the United States during the affected period
  • Target Corporation

Initial access

  • unknown

Impact

  • data_theft
  • financial_loss

Attribution

unknown low confidence

Target’s public disclosures describe unauthorized access but do not provide definitive public attribution in the cited primary filings.

CVEs and ATT&CK

No CVE or ATT&CK association is captured in this curated record.

Mitigations

Now

  • Segment POS networks from corporate IT and restrict outbound egress from POS devicesLimits exposure of payment environments and makes data exfiltration from POS systems harder.

Soon

  • Require MFA and strong controls for third-party/vendor remote access into payment environmentsReduces risk from compromised vendor credentials being used to reach sensitive payment systems.

Later

  • Deploy point-to-point encryption (P2PE) and tokenization for card dataReduces value of card data if in-store systems are compromised.

Detection ideas

Monitor POS systems for unusual outbound connections and data transfer patterns

Alert on POS subnets initiating new outbound destinations, high-volume transfers, or connections to rare domains/IPs.

Data sources: Proxy logs, Firewall logs, NetFlow/flow logs

Detect unauthorized access to payment processing systems and credential reuse

Alert on logins to POS management systems from unusual hosts/accounts, especially outside change windows or from vendor VPNs.

Data sources: Windows Security Event Logs, VPN logs, EDR telemetry

Sources