Target admits PIN numbers were stolen in payment data breach

Target logo
Target is apparently a big target for hackers

Update: Target is now saying that encrypted debit card PIN numbers were in fact stolen, but that the encryption key was not, so shoppers who used debit cards still have nothing to worry about.

The retailer said in a statement sent to CNET, "While we previously shared that encrypted data was obtained, this morning through additional forensics work we were able to confirm that strongly encrypted PIN data was removed. We remain confident that PIN numbers are safe and secure. The PIN information was fully encrypted at the keypad, remained encrypted within our system, and remained encrypted when it was removed from our systems."

The statement continued, "Target does not have access to nor does it store the encryption key within our system. The PIN information is encrypted within Target's systems and can only be decrypted when it is received by our external, independent payment processor. What this means is that the "key" necessary to decrypt that data has never existed within Target's system and could not have been taken during this incident."

So rest easy Target shoppers?

Original story below…

Hackers hit Target hard just before Christmas, stealing an estimated 40 million credit and debit card numbers during the busy holiday shopping season.

But contrary to reports on Christmas eve, there's no evidence that debit card users' PIN numbers were stolen, Target says.

Reuters reported on December 24 that shoppers' PIN numbers had been stolen as well as credit card numbers, citing "a senior payments executive familiar with the situation."

But Target has issued a statement indicating that there are "no indications" of that being the case.

Absence of proof is not proof of absence

"To date, there is no evidence that unencrypted PIN data has been compromised. In addition, based on our communications with financial institutions, they have also seen no indications that any PIN data was compromised," Target said in a statement issued to CBS New York.

It continued, "Our priority continues to be the security of our guests and we are working around the clock to address this issue."

Obviously there being no indication that PINs were stolen is not proof that PINs weren't stolen; but you can't blame Target for wanting to cover its own behind in this situation.

This cyber attack was reportedly the second-largest breach of credit card data in US history, beat only by a 2005 scam involving the retailer TJX that affected an estimated 45.7 million people, according to Fox.

Shoppers who swiped a card in a Target store between November 27 and December 15 might have been affected.

Via Slashgear

Michael Rougeau

Michael Rougeau is a former freelance news writer for TechRadar. Studying at Goldsmiths, University of London, and Northeastern University, Michael has bylines at Kotaku, 1UP, G4, Complex Magazine, Digital Trends, GamesRadar, GameSpot, IFC, Animal New York, @Gamer, Inside the Magic, Comic Book Resources, Zap2It, TabTimes, GameZone, Cheat Code Central, Gameshark, Gameranx, The Industry, Debonair Mag, Kombo, and others.

Micheal also spent time as the Games Editor for Playboy.com, and was the managing editor at GameSpot before becoming an Animal Care Manager for Wags and Walks.

Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead