Target to pay $18.5M to settle data-breach lawsuit

SHARE Target to pay $18.5M to settle data-breach lawsuit
ap16295564946574.jpg

Target Corp. has reached an $18.5 million settlement over a massive data breach that occurred before Christmas in 2013. | AP file photo

NEW YORK — Target Corp. has reached an $18.5 million settlement over a massive data breach that occurred before Christmas in 2013, New York’s attorney general announced Tuesday.

The agreement involving 47 states and the District of Columbia is the largest multistate data breach settlement to date, Attorney General Eric T. Schneiderman’s office said. The settlement, which stipulates some security measures the retailer must adhere to, resolves the states’ probe into the breach.

Target spokeswoman Jenna Reck said in a statement that the company has been working with state authorities for several years to address claims related to the breach.

“We’re pleased to bring this issue to a resolution for everyone involved,” she said.

Target had announced the breach on Dec. 19, 2013, saying it had occurred between Nov. 27 and Dec. 15 of that year. It affected more than 41 million customer payment card accounts and exposed contact information for more than 60 million customers.

The breach forced Target to overhaul its security system and the company offered free credit reports for potentially affected shoppers. Target’s sales, profit and stock price all suffered months after the disclosure as shoppers were nervous about their security of their credit cards. The breach also contributed to the departure of Target’s then-CEO, chairman and president Gregg Steinhafel, who resigned in May 2014.

An investigation by the states found that in November 2013, scammers got access to Target’s server through credentials stolen from a third-party vendor. They used those credentials to take advantage of holes in Target’s systems, accessing a customer service database and installing malware that was used to capture data, including full customer names, telephone numbers, email and mailing addresses, credit card numbers, expiration dates and encrypted debit PINs.

The settlement requires Target to maintain appropriate encryption policies and take other security steps. Reck said the costs of the settlement are already reflected in the reserves that Target has previously disclosed.

The Latest
Oregonians are understandably troubled by the nuisance of public drug use since the state decriminalized low-level possession of illegal drugs. But reversing Measure 110 is not the answer.
Shame on the moderators for not bringing up Trump’s significant legal woes.
The Clinton, UIC-Halsted and Racine stations will be closed between 10 p.m. Friday and 4 a.m. Monday. The Racine station will reopen Oct. 8.
The Cubs (82-76) handed the third National League wild-card spot to the Marlins (82-76), who split a doubleheader against the Mets. The Marlins hold the tiebreaker over the Cubs.