Choose one of the following case studies to review.(Case study PDF's attached)

profileravikandru81
TargetingTargetwitha100milliondollardatabreach.pdf

TEACHING CASE

Targeting Target with a 100 million dollar data breach

Federico Pigni1 • Marcin Bartosiak2 • Gabriele Piccoli3 • Blake Ives4

Published online: 16 November 2017

� Association for Information Technology Trust 2017

Abstract In January 2014, the CEO of the renowned U.S.

discount retailer Target wrote an open letter to its cus-

tomers apologizing for the massive data breach the com-

pany experienced during the 2013 holiday season.

Attackers were able to steal credit card data of 40 million

customers and more were probably at risk. Share prices,

profits, but above all reputation were all now at stake. How

did it happen? What was really stolen? What happened to

the data? How could Target win consumer confidence

back? While the company managed the consequences of

the attack, and operations were slowly back to normal, in

the aftermath the data breach costs hundreds of million

dollars. Customers, banks, and all the major payment card

companies took legal action against Target. Some of these

litigations remained unsettled 3 years later. The importance

of the breach lays in its far broader consequences, rippling

through the U.S. Congress, and raising consumer and

industry awareness on cyber security. The case provides

substantial data and information, allowing students to step

into the shoes of Target executives as they seek answers to

the above questions.

Keywords Teaching case � Cyber security � Hacking � Data breach � Target � Information systems

Introduction

On January 13th and 14th, 2014, Greg Steinhafel, Chair-

man, President, and CEO of Target, published an open

letter to customers (Steinhafel 2014) in The New York

Times, The Wall Street Journal, USA Today, and The

Washington Post, as well as in local papers of the firm’s 50

largest markets. In the letter, he apologized for the massive

data breach his company experienced during the 2013

holiday season.

Target learned in mid-December that criminals

forced their way into our systems, gaining access to

guest credit and debit card information. As a part of

the ongoing forensic investigation, it was determined

last week that certain guest information, including

names, mailing addresses, phone numbers or email

addresses, was also taken.

I know this breach has had a real impact on you,

creating a great deal of confusion and frustration. I

share those feelings. You expect more from us and

deserve better. We want to earn back your trust and

confidence and ensure that we deliver the Target

experience you know and love.

The breach, announced to the public 6 days before

Christmas, included credit card data from 40 million

customers. It was later discovered that data for another

70 million customers were also at risk.

& Federico Pigni [email protected]

1 Grenoble Ecole de Management, 12, rue Pierre Sémard,

38000 Grenoble, France

2 Department of Economics and Management, University of

Pavia, Pavia, Italy

3 E.J. Ourso College of Business, Lousiana State University,

Baton Rouge, LA, USA

4 C.T. Bauer School of Business, University of Houston,

Houston, TX, USA

J Info Technol Teach Cases (2018) 8:9–23

DOI 10.1057/s41266-017-0028-0

Target Inc.

Target’s chain of discount stores sold low-cost clothing,

items for the home, and—in some stores—groceries. Major

competitors in the U.S. included Walmart, Kmart, CostCo,

Kohl’s, J.C. Penney and, in Target’s still small but growing

online segment, Amazon. The first Target store, a low-cost

subsidiary of the department store chain Dayton Hudson,

opened in 1962; by December of 2014, Target’s 366,000

employees staffed a network of nearly 2000 stores located

in the U.S. (1801) and Canada (133). Target’s stores also

included larger SuperTarget stores, smaller CityTarget

stores, and still smaller Target Express stores. In 2014,

Target reported revenues of USD 73 billion.

Headquartered in Minneapolis, Target differentiated

itself from low-cost competitors by offering Target brands,

exclusive deals with other brands, quality and trendy

goods, as well as fashion items from well-known design-

ers—all at modest prices; Fortune magazine characterized

Targets merchandising focus as ‘‘Cheap and Chic’’ (Wahba

2014).

The breach

Target announced the data breach (see Exhibit 1), one day

after an independent reporter and investigator of Internet

security, Brian Krebs, broke the story on his blog:

…Target is investigating a data breach potentially involving millions of customer credit and debit card

records… According to sources at two different top 10 credit card issuers, the breach extends to nearly all

Target locations nationwide, and involves the theft of

data stored on the magnetic stripe of cards used at the

stores (Krebs 2013).

For several days prior to Kreb’s posting, banks had

witnessed an uptick in illegal card activity, with a

disproportionate number of those transactions traceable to

card numbers recently used by Target customers. The

banks notified the Federal Bureau of Investigation (FBI).

The U.S. Department of Justice (DOJ) alerted Target on the

evening of December 12th. The following day, DOJ and

U.S. Secret Service personnel met with Target executives.

By December 15th, outside experts, hired by Target, helped

to discover and remove malware in Target’s point-of-sale

(POS) terminals and on several of the company’s servers.

On December 16th, Target notified banks and payment

processors (e.g., Visa) that it had been breached.

From November 27th onwards, debit and credit trans-

actions from Target’s U.S. store’s point-of-sale checkout

terminals had been compromised and customer data stolen.

By December 15th, the hemorrhaging had slowed to a

trickle, and by the 18th was stopped. By then the data

contained on magnetic stripes of 40 million debit and

credit cards had been copied and, through a circuitous

route, transmitted to a server in Russia. Almost immedi-

ately, customer credit card data surfaced on the black

market at Internet ‘‘card shops.’’

On December 27th, Target announced that encrypted

personal identification number (PIN) data from some cards

had also been scraped. Then, on January 10th, 2014, Target

reported that non-financial data from as many as 70 million

additional customers had also been stolen from Target

servers; included were names, addresses, phone numbers,

and email addresses. Because of duplicates between the

two sets of data, the total number of customers affected

was approximately 100 million.

Data breaches

The Identity Theft Resource Center (ITRC) defines a data

breach as (ITRC 2015, p. 2):

An incident in which an individual name plus a

Social Security number, driver’s license number,

medical record or financial record (credit/debit cards

included) is potentially put at risk because of

exposure.

Data breaches were classified in several ways. Breaches

could be criminal or accidental, carried out by insiders or

outsiders, computer-based or manual. The external, com-

puter-based, criminal variety often involved changes to, or

tapping into, the network, computer, or terminal hardware

(called skimming). For instance, fake ATM fronts or card

readers were surreptitiously attached to ATM machines; or,

for as little as USD 1000 an ATM could be acquired and set

up as a honey pot for capturing unencrypted data from

legitimate cards (Satanovsky 2011). An alternative

approach, called RAM or Memory Scraping (Zetter

2014), required the use of software tools, either malware

or legitimate software employed in an illegitimate manner

on customer facing devices including ATMs, POS, or even

consumers own computers or phones. Scraping, unlike

skimming, required no physical access; it could be carried

out from anywhere in the world, thus lowering the risk to

the perpetrator, while presenting still greater exposure to

the victims.

The Target data breach was but one of an increasingly

common phenomenon. One compilation (ITRC 2015)

identified 781 breaches in the U.S. that exposed 169 mil-

lion records in 2015, a significant increase from 498

reported breaches and 22 million records reported six years

10 F. Pigni et al.

earlier (Fig. 1). In ten years, the ITRC had identified over

6000 breaches exposing more than 850 million records. A

fourfold increase in a decade, affecting financial services,

business, education, government, and healthcare sectors.

As many breaches went unreported, these were conserva-

tive numbers.

U.S. firm’s reported having had more than a million

records exposed in the year following the Target breach;

among them were three retailers: Home Depot, Michael’s

Stores, and Neiman Markus. In each case, the perpetrators

appeared to have employed tools, and taken advantage of

organizational lapses, in ways similar to Target’s Breach.

Among notable, other victims of data breaches in 2014

were AliExpress (owned by Alibaba.com), American

Express, Korean Credit Bureau, JPMorgan, The U.S. Postal

Service, the U.S. Internal Revenue Service, Rumbler.ru

and, perhaps most notoriously, SONY Pictures.

In 2016, data breaches were still increasing 15% year on

year, and the number of stolen record was growing at twice

that peace (31%), with an average of 3 million records

stolen per day. North America (see Fig. 2) was experi-

encing the largest number of data breaches, accounting for

almost 80% of the world total (Breach Level Index, 2016).

The United States led the world in data breaches with over

400 million compromised records (70% of the total).

Europe, the next highest, accounted for 10% of the total

breaches with close to 50 million stolen records. The Asia

and Pacific region was close behind in breaches (8%) but

far outstripped Europe with 110 million compromised

records (20%). U.S. security breach notification laws and

European directives and regulations (e.g., the General Data

Protection Regulation 2016/679) required organizations to

disclose and to inform promptly customers, authorities, and

other parties when personal data were stolen or compro-

mised; an obligation not all countries were under. These

regulations had the double objective of encouraging firms

to improve their practices and consequently reduce con-

sumers’ risk.

Healthcare, government, financial, retail, education, and

technology were the main target sectors for data breaches.

In the U.S., 2016 saw an increase in breaches to POS

systems at several hotel chains and retailers (see Fig. 3).

Senior management’s rising concern regarding com-

puter and network security were on display in the results of

the 2016 PwC Annual Global CEO Survey, where 61%

percent of the executives interviewed described cyber

threats and lack of data security as a threat to both national

and commercial interests (PwC 2016). Moreover, an even

higher proportion (78%) of them considered cyber security

technologies to be strategically important for their firms.

While security became a top priority in CEOs’ agendas

and a prominent topic in boardroom discussions, the data

showed that corporations were losing ground in responding

to the threat.

Payment systems and fraud

The U.S. Federal Reserve Bank reported (Federal Reserve

Board 2014, p. 41) in 2012 that credit cards made up 21%

of the total number of non-cash transactions in the US and

1.4% of the non-cash value; the corresponding numbers for

debit cards were 38% and 1% and for checks, 15% and

14.8%. For Automated Clearing House (ACH) transac-

tions, such as online bill-pay and wire transfers, commonly

used for large, non-retail transactions, the transaction and

value numbers were 18% and 83%. Cash, an essentially

0

100

200

300

400

500

600

700

800

900

2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015

nu m

be r o

f b re

ac he

s

Banking/Credit/Financial

Health/Medical

Government/Military

Educational

Business

Fig. 1 Evolution of data breaches in the U.S. (ITRC

2016)

Targeting Target with a 100 million dollar data breach 11

anonymous payment system, was still the most common

payment method, constituting 40% of transactions in the

U.S. (Bennett et al. 2014, p. 3). An average consumer in the

month of October 2012 used cash for 23 of 59 payments

(Bennett et al. 2014, p. 2). Cash, however, was primarily

used for small dollar value purchases, constituting only

14% of purchases at retail, and averaging USD 21 per

transactions (Bennett et al. 2014, p. 3). At brick & mortar

stores such as Target, a high, and increasing, proportion of

purchases were made with credit or debit cards.

Payment cards, particularly credit and non-pin protected

debit cards and prepaid cash cards, presented tempting, and

still relatively risk-free, opportunities for criminals. The

ability to tap into U.S. payment systems from other coun-

tries, particularly those with weak enforcement or no

extradition treaties with the U.S., further lowered the risk.

In 2012, the Federal Reserve reported over 31 million

fraudulent payment transactions with a value of over USD

6 billion; 26 million of these transactions, and over USD 4

billion of value, were from credit, signature-only debit, or

prepaid cash cards. Pin-protected debit cards were far more

secure, experiencing only 20% of the fraud rates of sig-

nature debit cards (Federal Reserve Board 2014).

The biggest vulnerability in card payment systems in the

U.S. was the card’s magnetic stripe. The data written on the

‘‘magstripe’’ included the primary account number, the

United States

United Kingdom

New Zealand Japan China Israel

South Africa

2016 2015 2014 2013

Canada Australia India

1008 82 55 34 17 12 7 9 8 8 1370 158 65 45 22 23 21 9 5 5 1259 135 65 34 7 13 12 15 17 4 911 86 30 26 12 13 12 5 8 3

1

10

100

1,000

Nu m

be r o

f b re

ac he

s

Fig. 2 Data breaches by country—logarithmic scale

(authors on Gemalto’s data,

October 2016—http://www.

breachlevelindex.com/data-

breach-database)

2016 2015 2014 2013 2623411097165

Healthcare Government Financial Retail Technology Education Hospitality Other 375 197 169 142 133 122 11 195 445 296 276 238 120 165 1 322 446 289 211 194 138 173 274

119342

0

150

300

450

Nu m

be r o

f b re

ac he

s

Fig. 3 Data breaches by industry (authors on Gemalto’s

data, October 2016—http://

www.breachlevelindex.com/

data-breach-database)

12 F. Pigni et al.

account holder’s name, the expiration date, a service code

indicating the types of charges that could be accepted, and

discretionary data, such as a PIN code. Once compromised,

either by scraping or skimming, these data could be used to

make online purchases or to legitimate counterfeit cards,

which could then be used in physical stores. While in-store

use might seem risky, it did not require a mailing address to

collect the ordered merchandise. Moreover, the stolen

merchandise, mostly electronics or gift cards, could often

be immediately resold.

‘‘Big Box’’ and discount retailers were particularly

vulnerable to payment card fraud and data breaches due to

the size of their customer population, their high daily

transaction volumes, the liquidity of some of their mer-

chandise, and their customers’ desire for fast and conve-

nient checkout. Moreover, huge past investments in point-

of-sale check-out devices, as well as the typical customer’s

comfort with mag-stripe credit and debit cards, had retar-

ded retailers’ transition to more secure technologies (Geuss

2015).

The complexity of the payment network added further

vulnerability. The observation of a judge in an earlier data

breach case described that complexity and, implicitly, its

consequent vulnerability:

‘‘Every day, merchants swipe millions of customers’

payment cards. In the seconds that pass between the

swipe and approval (or disapproval), the transaction

information goes from the point of sale, to an acquirer

bank, across the credit-card network, to the issuer

bank, and back. Acquirer banks contract with mer-

chants to process their transactions, while issuer

banks provide credit to consumers and issue payment

cards. The acquirer bank receives the transaction

information from the merchant and forwards it over

the network to the issuer bank for approval. If the

issuer bank approves the transaction, that bank sends

money to cover the transaction to the acquirer bank.

The acquirer bank then forwards payment to the

merchant.’’ (Rosenthal, 2011)

The judge described a four-party payment system: A

credit-card network, usually Visa or MasterCard, is a

network intermediary between the merchants’ bank (‘‘ac-

quirer’’), the merchant, and the customer’s bank (‘‘issuer’’).

The alternative, a three-party approach, links three partic-

ipants: the card-carrying customer, the merchant, and the

card issuer (e.g., American Express or Discover). In 2013,

82% of card payments went through the four-party system.

To further the complexity, many merchants relied on

outside payment processors for the link between their POS

devices and acquiring banks. Two of these, Global

Payments and Heartland Payments, had themselves been

major victims of hackers.

Anatomy of the Target breach

The first victim in the heist was not Target, but Fazio

Mechanical Services, a provider of refrigeration services to

Target. Themeans of attackwas uncertain, but likely executed

via a bogus link or attachment as part of an email ‘‘phishing’’

broadcast to multiple Target third-party vendors—a list of

which was openly available on the Internet. To get inside the

supplier’s network, the attackers used a malware package

called Citadel (Olavsrud 2014) and then found and used

Fazio’s credentials to exploit its previously authorized access

to Target’s computer network. Fazio had access to several

Target systems, including contract management, project

management and electronic billing.OnNovember 12th, 2013,

the attackers gained access to Target’s internal network,

probably by uploading an executable file disguised as a

legitimate document attachment through a Web application.

The name of the uploaded file was apparently chosen to be

similar to that of other files commonly seen on the system.

Once inside Target’s internal network, the attackers

sought out logins, passwords, and network diagrams.

Failing to find credit card credentials on Target servers,

they instead, apparently patiently and successfully, pene-

trated Target’s POS terminals. Harnessing a computer

account they had created on Target’s network, they

deployed malware to POS terminals that the investigators

named Kaptoxa (pronounced kar-toe-sha), available for

about USD 2000 on black market Web sites. The software

then scraped each unencrypted card as it was read.

Between November 15th and 28th, the attackers tested the

malware1 on a few of Target’s POS devices. By November

30th, the hack was fully installed on almost all POS devices

and fully operational. That day, the attackers also installed

malware to transfer the stolen data to an internal server. This

data exfiltration malware,2 the file name of which was dis-

guised to look like a legitimate application, was updated

twice: on December 2nd, and again on December 4th. On

December 2nd, the perpetrators began to transfer data to

another Target server, one that was authorized for file

transfers through Target’s firewall. The data were moved

from that server to servers outside the U.S., eventually

ending up on a server in Russia. Data were moved during

business hours to hide the illicit activity within an otherwise

busy network traffic.

1 While not definitively linked to the Target data breach, in August of

2014 the U.S. Secret Service Identified malware called ‘‘backoff’’ that

was first detected in October of 2013 but not detectable by anti-virus

solutions until almost a year later. Backoff was estimated to have already

affected over 1000 U.S. Businesses. https://www.documentcloud.org/

documents/1279345-secret-service-malware-announcement.html. 2 Data exfiltration is the transfer of stolen data from a compromised

system within victims’ network back to the attacker while attempting

to remain undetected.

Targeting Target with a 100 million dollar data breach 13

Stolen card numbers were almost immediately available

on Internet black markets. One market, Rescator, had been

described as ‘‘The Amazon.com of Stolen Credit Cards.’’

(Lawrence 2014) Here batches of credit cards could be

purchased, sometimes for prices exceeding USD 100

(Fig. 4). Cards data contained in the earliest batch released

on Rescator sold for between USD 26.60 and USD 44.80 in

the days before December 19th (Exhibit 3), when Target

went public on the data breach (Krebs 2014).

Failed security measures

Target’s attackers exploited numerous security weaknesses.

Target had publicly posted the names of its suppliers on the

Internet. One of them, FazioMechanical Services, had relied

on a free malware detection package, intended for use by

individuals, rather than for commercial use. The malicious

detection package, installed at Fazio, probably captured

login and password information during transactions. While

two-factor authentication was required by PCI3 for payment

servers, it was not required, and from reports was rarely used,

for non-payment related, externally accessible applications

on Target’s external network. Instead, Target relied on a

scheme required by PCI policy: payment servers were seg-

regated from the rest of the network. Indeed, PCI had

recently given a clean audit of Target’s network segrega-

tion—a segregation that subsequently proved inadequate.

Two different security packages triggered alarms as the

data exfiltration malware was installed on November 30th,

and then again when it was updated. One of these pack-

ages, FireEye, installed at a cost of USD 1.6 million a few

months earlier, recommended to its Target minders in

Bangalore the deletion of the malware—a recommendation

reportedly passed on to, but ignored by, the personnel in

Target’s security operations center in Minneapolis (Riley

et al. 2014). Target also apparently did not maintain a

‘‘white list’’ of authorized processes, often used to ensure

that malware is not allowed to run on a device or server.

Neither did Target adequately monitor the creation of new

Fig. 4 Rescator’s efficient and user friendly web shopping interface

3 The Payment Card Industry Security Standards Council (PCI SSC)

was created in 2006 to develop security standards for the evolving

Payment Card Industry (PCI). The resulting Payment Card Industry

Footnote 3 continued

Data Security Standard (PCI DSS) is intended to ensure participating

companies that process, store, or transmit credit card information do

so in a secure manner.

14 F. Pigni et al.

accounts, nor effectively block access to certain external

file servers (e.g., servers in Russia).

Financial consequences

The breach proved to be immediately costly as reflected in

the CEO’s comments to analysts in a February 2014

earnings conference call.

Target’s fourth quarter financial results reflect better

than expected US segments performance through the

first three weeks of the holiday season, followed by

meaningfully softer results following our December

19 [data breach announcement] … fourth quarter comparable sales decreased 2.5%, consistent with our

updated guidance in January. (Target 2014c, p. 3)

Target’s cumulative stock return had beaten both the S&P

500 and Target’s peer comparison group in February of 2013

but, by the following February, 2 months after the breach,

had fallen precipitously behind both groups. Earnings per

share had also fallen (Target 2014a, pp. 15–16). Profits in the

4th quarter of 2013 were off 47% from the previous year,

though the decline was partially attributed to poor perfor-

mance at Target’s Canadian stores.

Costs piled up. Eight months after the breach, the com-

pany reported USD 236 million in breach-related costs, of

which USD 90 million were covered by insurance (Target

2014e, p. 9). One big expense was the cost to provide Tar-

get’s customers with a year of credit screening services.

Those reported expenses, coupled with a drop in expected

earnings from 85 to 78 cents a share, stunned Wall Street;

Target’s stock price fell 4.4% the next day (Abrams 2014).

John Kindervag, a Vice President and principal analyst

at Forrester Research, predicted that the eventual costs of

the breach would be much higher:

I don’t see how they’re getting out of this for under a

billion, over time… One hundred fifty million in a quarter seems almost like a bargain. (Abrams 2014)

Legal consequences

In its 2014s quarter earnings conference call (Target 2014e,

p. 9), Target trumpeted ‘‘dramatically lower’’ breach-re-

lated costs as compared to post-breach external estimates

that had been more in line with Kindevag’s billion dollar

estimate. But, 3 months later, in the risk assessment section

of Target’s November 2014 10-Q filing to the SEC (Target

2014b, p. 9), Target identified many, still unresolved

potential sources for further costs and legal uncertainties.

… more than 100 actions have been filed in courts in many states, along with one action in Canada, and other

claimshave been ormaybe asserted against us on behalf

of guests, payment card issuing banks, shareholders or

others seeking damages or other related relief allegedly

arising out of the Data Breach. State and federal agen-

cies, including State Attorneys General, the Federal

Trade Commission and the SEC, are investigating

events related to the Data Breach, including how it

occurred, its consequences and our responses…

Target customers’ numerous lawsuits were combined into a

single class action suit, to be adjudicated in a Federal District

Court in Minnesota. One of nearly 100 customer reports

included in the lawsuit described the damages and inconve-

niences suffered by one misfortunate Target customer:

[A Target customer] used her Savannah State Bank

Visa debit card to purchase goods at a Target store in

Georgia during the period of the Target data breach.

[The customer’s] personal information associated

with her debit card was compromised in and as a

result of the Target data breach. [The customer] was

harmed by having her financial and personal infor-

mation compromised. She incurred multiple unau-

thorized charges totaling approximately $1900 in

December 2013. [The customer] also experienced a

loss of access to her funds, paid a replacement card

fee for which she remains unreimbursed, and incurred

late payment fees due to failed automatic payments.

She also paid for credit monitoring services as a

result of the Target data breach. (United States Dis-

trict Court: District of Minnesota 2014, p. 23)

Estimates of the eventual total cost of fraudulent charges to

customer cards ranged from USD 240 million to USD 2.2

billion (Weiss and Miller 2015). Among the numerous

damages enumerated by customers’ lawyers were: unau-

thorized charges to debit and credit card accounts; theft of

personal and financial information; costs of detecting and

protecting against identity theft and unauthorized use of

accounts; lack of access to account funds; costs associated

with that lack of access (e.g., late charges and fees, credit

rating harm); time and loss of productivity stemming from

the need to deal with the challenges faced.

The customers’ lawyers accused Target of:

… failing to take adequate and reasonable measures to ensure its data systems were protected, failing to take

available steps to prevent and stop the breach from ever

happening, failing to disclose to its customers the

material facts that it did not have adequate computer

systems and security practices to safeguard customers’

financial account and personal data, and failing to

provide timely and adequate notice of the Target data

breach (United States District Court: District of Min-

nesota 2014, p. 4)

Targeting Target with a 100 million dollar data breach 15

That sameU.S.District Court inMinnesotawould adjudicate

another set of class action lawsuits, this time brought by

banking institutions adversely impacted by their own

customers’ misfortune. Because of contracts with payment

networks like Visa, historically the banks had shouldered the

bulk of the losses for credit card breaches. This time they

hoped, because of the retailers’ alleged negligence, more of

the responsibility would be assigned to Target. Estimates of

the potential fines thatmight be levied on Target ranged from

USD 71 million to USD 1.1 billion, numbers that repre-

sented anywhere from 2 to 37% of Target’s net income for

2013 (Weiss and Miller 2015). The American Bankers

Association estimated that the data breach affected more

than 8% of debit cards and nearly 4% of credit cards

countrywide, with the average loss to banks of USD 331 per

debit card and USD 530 per credit card (ABA 2014).

Targeting Target with a 100 million dollar data

breach (B)

Everyone in this industry right now has to come

together to make sure we’re putting the right defense

plans in place.

[Brian Cornell, CEO Target Stores] (CBS News

2014)

In May 2014, Greg Steinhafel resigned as Target’s

Chairman, President and CEO, a resignation partially

attributed (Abrams 2014) to a massive, criminal data

breach suffered by Target during the 2013 holiday season.

The breach had exposed over 100 million customer

records; it depressed Target’s holiday shopping revenues,

increased administrative costs, and triggered legal liabili-

ties. Moreover, the breach was a clear threat to Target’s

brand and reputation. In parallel with Steinhafel’s May

resignation, Institutional Shareholder Services, an overseer

of corporate governance for institutional investors, recom-

mended that shareholders reject the re-election of seven

members of the board who served on Target’s audit and

corporate responsibility committee.

Following Steinhafel’s resignation, John Mulligan,

Target’s CFO took on the position of interim CEO. Three

months later, in mid-August of 2014, Brian Cornell was

named Chairman and CEO. A previous CEO of PepsiCo

Americas’ Foods Division, Cornell brought extensive retail

experience to Target; his impressive resume included CEO

at Sam’s Club, CEO at Michael’s Craft Stores, and CMO at

Safeway.

The breach foreshadowed a further shakeup in Target’s

management team. Prior to Steinhafel’s resignation, and

3 months after the breach, Target’s CIO resigned. The Vice

President of Assurance Risk and Compliance, in keeping

with his previously announced intention, also resigned.

Customer communication

From its initial announcement of the breach on the 19th

through January 15th, Target sent six emails to its ‘‘guests’’

and a seventh to the holders of Target’s proprietary

REDcard payment card. Included among these were

descriptions of what had happened, apologies, reassurances

that the problem was being well taken care of and that the

customer risk was small, advice about how the recipient

could protect themselves or what actions the customer

should take (e.g., ‘‘Be wary of emails that ask for money or

send you to suspicious websites.’’) or should not take (e.g.,

‘‘Never share information with anyone over the phone,

email or text, even if they claim to be someone you know

or do business with.’’), and explained how to take advan-

tage of the year of free credit monitoring Target was pro-

viding. The Company also quickly established, and

continued to update, several web resources. One web page

included links to the seven emails, related press

announcements, and to transcripts of CFO Mulligan’s

February 4th and March 26th testimony to Congressional

committees. A second web page included responses to 48

‘‘frequently asked questions.’’ The initial versions of these

web resources were prominently displayed and accessible

from Target’s home page as of the announcement on

December 19th.

Rebuilding the organization and consumer confidence

In April of 2014, Target hired a new CIO, Bob DeRoddes,

who had served in a security advisory capacity to the U.S.

Department of Homeland Security, the U.S. Secretary of

Defense, the U.S. Department of Justice, and numerous

multi-national firms.

In the CIO announcement, Target also described its

intention to move Target’s ‘‘Red’’ branded credit and debit

cards to a ‘‘chip-and-pin enabled technology,’’ as well as

accelerating a plan to install new payment devices in close

to 1800 stores (see Exhibit 4). Further, it identified a

number of security enhancements already implemented

(Target 2014d). Among them were the following:

1. Enhancing monitoring and logging [including] addi-

tional rules, alerts, centralizing log feeds and enabling

additional logging capabilities.

2. Installation of application whitelisting point-of-sale

systems [including] deploying to all registers, point-of-

sale servers and development of whitelisting rules.

3. Implementation of enhanced segmentation [including]

development of point-of-sale management tools,

review and streamlining of network firewall rules and

16 F. Pigni et al.

development of a comprehensive firewall governance

process.

4. Reviewing and limiting vendor access [including]

decommissioning vendor access to the server impacted

in the breach and disabling select vendor access points

including FTP and telnet protocols.

5. Enhanced security of accounts coordinated reset of

445,000 Target team member and contractor pass-

words, broadening the use of two-factor authentication,

expansion of password vaults, disabled multiple ven-

dor accounts, reduced privileges for certain accounts,

and developing additional training related to password

rotation.

In June of 2014, Brad Maiorino was appointed to a newly

created position, that of Senior VP and Chief Information

Security Officer. Maiorino was previously with General

Motors and, prior to that, General Electric. In those roles,

his responsibilities focused on information security. He

would report to the CIO. Six months later, Target

announced the appointment of Jacqueline Hourigan Rice,

to fill the role of Senior VP and Chief Risk and Compliance

Officer. Hourigan Rice also came from GM where she had

spent 17 years, most recently as GM’s chief compliance

officer. According to the announcement, she would report

to CEO Cornell. Her responsibilities would include the

following: ‘‘centralized oversight of enterprise risk man-

agement, compliance, vendor management and corporate

security under her leadership’’ (Target 2014f).

A year later

In a televised interview in November of 2014, a year after

the breach and two days before ‘‘Black Friday4,’’ the semi-

official start of the crucial holiday sales season, Cornell

reassured customers, shareholders, and business partners

that the Target leadership team was taking data security

very seriously:

We focus every day, every single day, not just during

the holidays, but 52 weeks a year, on data security.

Making sure we’ve the right team in place, to mon-

itor, detect, contain. (CBS News 2014)

Confidence building words, but even as he spoke, the

perpetrator(s) had not been apprehended, the stolen credit

card credentials were still for sale on Internet black

markets, and a growing number of breach-related lawsuits

still hung over Target.

Yet, the mood at Target seemed considerably more

upbeat than a year earlier. So too were Target’s financials.

The 2014 fiscal year closed with sales up 1.3% and with

digital channel sales growth exceeding 30 percent (Target

2015a) and by the first quarter of 2015, sales grew 2.3%

from the same period in the prior year (Target 2015b).

Target’s stock price, which had fallen to a low of USD

54.66 in February of 2014, had rebounded to over USD 75

in late January of 2015 (Exhibit 2). Target was confident

that the data breach would not impact their reputation in

the long term:

… we experienced weaker than expected sales immediately following the announcement of the Data

Breach that occurred in the fourth quarter of 2013,

and while we now believe the incident will not have a

long-term impact to our relationship with our guests,

it is an example of an incident that affected our

reputation and negatively impacted our sales for a

period of time. (Target 2015a, p. 4)

The Target Web site, which had, until recently, promi-

nently displayed links to information on the data breach,

had returned to business as usual (Exhibit 5). By the end of

2015, the major lawsuits initiated by customers and credit

card issuers were finally being settled. In March, Target

agreed to pay USD 10 million to settle individual victims’

damages up to USD 10,000 (Reuters and Fortune, 2015). In

August, Visa issuers settled on up to $67 million in costs

related to the data breach (Whipp 2015). In December, an

agreement was reached with MasterCard issuers for USD

19.11 million, and banks and credit unions not covered in

the other actions for up to USD 20.25 million (Stempel and

Bose 2015).

While the situation was increasingly back to normal, the

company was still facing shareholder lawsuits, as well

probes by the Federal Trade Commission and State

Attorneys General, regarding the breach (Stempel and Bose

2015).

The broader threat

Executives at other multi-national companies were con-

siderably more pessimistic than Cornell appeared to be, at

least in his public pronouncements. Speaking at a panel at

the 2015 World Economic Forum in Davos, Switzerland,

several CEOs (Gelles 2015) had expressed their appre-

hensions about data breaches. John Chambers, CEO of

Cisco, predicted, ‘‘The number of security incidents this

year will be exponentially greater than last year.’’ Simi-

larly, the CEO of Infosys, Visha Sikka, predicted ‘‘five

times as many incidents as we did last year.’’ (Figure 1) As

vendors of IT and security solutions, Chambers and Sikka

4 The first shopping day after Thanksgiving in the U.S.: allegedly,

named because it was often the day when a retailer’s profitability for

the year went from red to black.

Targeting Target with a 100 million dollar data breach 17

were perhaps predictably alarmist in their assessments. The

comments of the CEO of IMax, Richard Gelfond, probably

better reflected the trepidation of many of Chambers’ and

Sikka’s customers:

The one thing that really scares me is that if someone

wants to get into your system, they can get in. Almost

no amount of money will keep them out.

Another vendor’s study supported their pessimism (Riley

et al. 2014) reporting that only 31 percent of companies

had identified data breaches through their own monitoring.

The percentage was far lower for retailers. As with Target,

95% of retail data breaches were not discovered by the

retailer; one observer described retailers as ‘‘the wilde-

beests of the digital savannah.’’

Congressional reactions to target breach

Compared to their European counterparts, U.S. retailers

were particularly vulnerable as Seth Berman, head of the

London office of a risk management firm, observed:

There’s a fundamental flaw in the US credit card

system in that they do not use chip and pin… The US is doing everyone a favor by acting as a honeypot for

criminals, and in addition the country has more credit

cards per head than anywhere else.

The growing, still seemingly uncontrollable, threat to U.S.

firms posed by hackers was a growing concern in

Washington D.C. Between Feb 3rd and April 2nd, 2014,

six Congressional Committees held seven different hear-

ings related (Weiss and Miller 2015, p. 2) to data breaches

in general and the Target breach in particular. Among the

options discussed were:

Federal legislation to require notification to con-

sumers when their data have been breached; legisla-

tion to potentially increase Federal Trade

Commission (FTC) powers and authorities over

companies’ data security; and legislation that could

create a federal standard for the general quality or

reasonableness of companies’ data security.

Study questions

1. How was the attack on Target perpetrated? Can you

identify its main phases?

2. Which weaknesses in Target security did hackers

exploited?

3. Would you consider Target data breach an information

system failure? Why?

4. Who do you believe is to blame for the incident? Why?

How did Target manage the situation when the breach

was detected? Do you consider their reaction

appropriate?

5. Do you believe it was the CEO’s responsibility to

inform customers about the data breach? What would

you have done?

6. What lessons should a CEO learn from Target?

7. What lessons should a CIO learn?

8. What should Target do next?

9. Do you believe consumers are becoming tolerant of

breeches?

Appendix

Exhibit 1: Initial notification to target customers

on December 19th, 2013

Important notice: unauthorized access to payment card

data in U.S. stores

We wanted to make you aware of unauthorized access to

Target payment card data. The unauthorized access may

impact guests who made credit or debit card purchases in

our U.S. stores from Nov. 27 to Dec. 15, 2013. Your trust is

a top priority for Target, and we deeply regret the incon-

venience this may cause. The privacy and protection of our

guests’ information is a matter we take very seriously and

we have worked swiftly to resolve the incident.

We began investigating the incident as soon as we

learned of it. We have determined that the information

involved in this incident included customer name, credit or

debit card number, and the card’s expiration date and CVV.

We are partnering with a leading third-party forensics

firm to conduct a thorough investigation of the incident and

to examine additional measures we can take that would be

designed to help prevent incidents of this kind in the future.

Additionally, Target alerted authorities and financial

institutions immediately after we discovered and confirmed

the unauthorized access, and we are putting our full

resources behind these efforts.

We recommend that you closely review the information

provided in this letter for some steps that you may take to

protect yourself against potential misuse of your credit and

debit information. You should remain vigilant for incidents

of fraud and identity theft by regularly reviewing your

account statements and monitoring free credit reports. If

you discover any suspicious or unusual activity on your

accounts or suspect fraud, be sure to report it immediately

to your financial institutions. In addition, you may contact

the Federal Trade Commission (‘‘FTC’’) or law

18 F. Pigni et al.

enforcement to report incidents of identity theft or to learn

about steps you can take to protect yourself from identity

theft. To learn more, you can go to the FTC’s Web site, at

www.consumer.gov/idtheft, or call the FTC, at (877)

IDTHEFT (438-4338) or write to Federal Trade Commis-

sion, Consumer Response Center, 600 Pennsylvania Ave-

nue, NW, Washington, DC 20,580.

You may also periodically obtain credit reports from

each nationwide credit reporting agency. If you discover

information on your credit report arising from a fraudulent

transaction, you should request that the credit reporting

agency delete that information from your credit report file.

In addition, under federal law, you are entitled to one free

copy of your credit report every 12 months from each of

the three nationwide credit reporting agencies.

Again, we want to stress that we regret any inconve-

nience or concern this incident may cause you. Be assured

that we place a top priority on protecting the security of our

guests’ personal information. Please do not hesitate to

contact us at 866-852-8680 or visit Target’s website if you

have any questions or concerns. If you used a non-Target

credit or debit card at Target between Nov. 27 and Dec. 15

and have questions or concerns about activity on your card,

please contact the issuing bank by calling the number on

the back of your card.

$50

$55

$60

$65

$70

December January February

Nov.27 - Dec.18 Hackers were stealing the numbers from credit and debit cards swiped at POS registers.

Dec.18 Target says ‘strong start to its holiday season has continued through the first part of December.

Dec.19 Target says the card numbers of 40 million customers were stolen between Nov. 27 and Dec.18.

Dec.27 Target says PIN data also were stolen.

Jan.10 Target says up to 70 million more customers had personal information such as names and email addresses stolen.

Jan.10 CEO Gregg Steinhafel offers apology in full-page newspaper ads.

Jan.29 Target confirms that hackers gained network access through an outside vendor.

Feb.4 CFO John Mulligan testifies before Congress about need to convert cards from magnetic strips to chip-enabled technology.

Feb.18 Stock closes at $56.4, down 11.3% since Target revealed that card numbers were stolen.

Exhibit 2: Target data breach timeline (adapted Langley 2014)

Targeting Target with a 100 million dollar data breach 19

Exhibit 3: From hacking to monetization

Exhibit 4: New MasterCard Initiative

and commitment to chip-and-PIN

Today, Target also announced a significant new initiative

as part of the company’s accelerated transition to chip-and-

PIN-enabled REDcards. Beginning in early 2015, the entire

REDcard portfolio, including all Target-branded credit and

debit cards, will be enabled with MasterCard’s chip-and-

PIN solution. Existing co-branded cards will be reissued as

MasterCard co-branded chip-and-PIN cards. Ultimately,

through this initiative, all of Target’s REDcard products

will be chip-and-PIN secured.

Earlier this year, Target announced an accelerated $100

million plan to move its REDcard portfolio to chip-and-

PIN-enabled technology and to install supporting software

and next-generation payment devices in stores. The new

payment terminals will be in all 1797 U.S. stores by this

September, 6 months ahead of schedule. In addition, by

early next year, Target will enable all REDcards with chip-

and-PIN technology and begin accepting payments from all

chip-enabled cards in its stores.

20 F. Pigni et al.

‘‘Target has long been an advocate for the widespread

adoption of chip-and-PIN card technology,’’ said John Mul-

ligan, executive vice president, chief financial officer for

Target. ‘‘As we aggressivelymove forward to bring enhanced

technology to Target, we believe it is critical that we provide

our REDcard guests with the most secure payment product

available. This new initiative satisfies that goal.’’

‘‘Target and MasterCard are taking an important step

forward in providing consumers with a secure shopping

experience, and the latest in payments technology,’’ said

Chris McWilton, president, North American Markets for

MasterCard. ‘‘Our focus, together with Target, is on safety

and security.’’

Quarterly results (millions, except per share data) First quarter Second quarter Third quarter Fourth quarter Total year

2013 2012 2013 2012 2013 2012 2013 2012a 2013 2012a

Sales 16,706 16,537 17,117 16,451 17,258 16,601 21,516 22,370 72,596 71,960

Credit card revenues – 330 – 328 – 328 – 356 – 1341

Total revenues 16,706 16,867 17,117 16,779 17,258 16,929 21,516 22,726 72,596 73,301

Cost of sales 11,563 11,541 11,745 11,297 12,133 11,569 15,719 16,160 51,160 50,568

Selling, general and administrative expenses 3590 3392 3698 3588 3853 3704 4235 4229 15,375 14,914

Credit card expenses – 120 – 108 – 106 – 135 – 467

Depreciation and amortization 536 529 542 531 569 542 576 539 2223 2142

Gain on receivables transaction 391 – – – – 156 – 5 391 161

Earnings before interest expense and income taxes 1408 1285 1132 1255 703 1164 986 1668 4229 5371

Net interest expense 629 184 171 184 165 192 161 204 1126 762

Earnings before income taxes 779 1101 961 1071 538 972 825 1464 3103 4609

Provision for income taxes 281 404 350 367 197 335 305 503 1132 1610

Net earnings 498 697 611 704 341 637 520 961 1971 2999

Basic earnings per share 0.78 1.05 0.96 1.07 0.54 0.97 0.82 1.48 3.10 4.57

Diluted earnings per share 0.77 1.04 0.95 1.06 0.54 0.96 0.81 1.47 3.07 4.52

Dividends declared per share 0.36 0.30 0.43 0.36 0.43 0.36 0.43 0.36 1.65 1.38

Closing common stock price

High 70.67 58.86 73.32 61.95 71.99 65.44 66.89 64.48 73.32 65.44

Low 60.85 50.33 68.29 54.81 62.13 60.62 56.64 58.57 56.64 50.33

Per share amounts are computed independently for each of the quarters presented. The sum of the quarters may not equal the total year amount

due to the impact of changes in average quarterly shares outstanding and all other quarterly amounts may not equal the total year due to rounding a The fourth quarter and total year 2013 consisted of 13 and 52 weeks, respectively, compared with 14 and 53 weeks in the comparable prior-

year periods

Exhibit 5: Target income statement (adapted Target 2014a, p. 63)

Targeting Target with a 100 million dollar data breach 21

References

ABA. 2014. Target Breach Bank Impact. American Bankers Asso-

ciation. Retrieved from http://www.aba.com/Tools/Function/

Payments/Documents/TargetBreachBankImpact.pdf.

Abrams, R. 2014. Target Puts Data Breach Costs at $148 Million, and

Forecasts Profit Drop, The New York Times, August 5, 2014,

http://www.nytimes.com/2014/08/06/business/target-puts-data-

breach-costs-at-148-million.html.

Bennett, B., D. Conover, S. O’Brien, and R. Advincula. 2014. Cash

Continues to Play a Key Role in Consumer Spending: Evidence

from the Diary of Consumer Payment Choice. Federal Reserve

Bank of San Francisco Fednotes (April 2014). Retrieved from

http://www.bheesty.com/cracker/1450697937_f3ce6ff546/fed

notes_evidence_from_dcpc.pdf.

Breach Level Index. 2016. 2016 It’s All About Identity Theft—First

Half Findings from the 2016. Gemalto. Retrieved from http://

www.breachlevelindex.com/assets/Breach-Level-Index-Report-

H12016.pdf.

CBS News. 2014. Target CEO on Black Friday: ‘We have to Win that

Big Playoff Game’. CBS News, November 26, 2014. http://www.

cbsnews.com/news/target-ceo-brian-cornell-on-black-friday-

data-security-free-shipping/. Retrieved 23 June 2016.

Federal Reserve Board. 2014. The 2013 Federal Reserve Payments

Study—Recent and Long-Term Payment Trends in the United

States: 2003–2012—Summary Report and Initial Data Release.

Federal Reserve System, p. 43. Retrieved from https://www.

frbservices.org/files/communications/pdf/general/2013_fed_res_

paymt_study_summary_rpt.pdf.

Gelles, D. 2015. Executives in Davos Express Worries Over More

Disruptive Cyberattacks. The New York Times’ DealBook,

January 22, 2015. http://dealbook.nytimes.com/2015/01/22/in-

davos-executives-express-worries-over-more-disruptive-cyberat

tacks/. Retrieved 23 June 2016.

Geuss, M. 2015. Chip-Based Credit Cards are Old News; Why is the

US only Rolling Them Out Now? Ars Technica, November 26,

2015. http://arstechnica.com/business/2015/11/chip-based-credit-

cards-are-old-news-why-is-the-us-only-rolling-them-out-now/.

Retrieved 13 May 2016.

ITRC. 2015. Data Breach Reports. Identity Theft Resource Center,

p. 197.

ITRC. 2016. ITRC Breach Statistics 2005–2015, January 25, 2016.

http://www.idtheftcenter.org/images/breach/2005to2015multiyear.

pdf. Retrieved 13 May 2016.

Krebs, B. 2013. Sources: Target Investigating Data Breach—Krebs on

Security. Krebs on Security, March 18, 2013. Retrieved from

http://krebsonsecurity.com/2013/12/sources-target-investigating-

data-breach/.

Krebs, B. 2014. Fire Sale on Cards Stolen in Target Breach, Krebs on

Security, February 19, 2014. Retrieved from http://krebsonsecur

ity.com/2014/02/fire-sale-on-cards-stolen-in-target-breach/.

Langley, M. 2014. Inside Target, CEO Gregg Steinhafel Struggles to

Contain Giant Cybertheft. Wall Street Journal, February 19,

2014. Retrieved from http://www.wsj.com/articles/

SB10001424052702304703804579382941509180758.

Lawrence, D. 2014. The Amazon.com of Stolen Credit Cards Makes

It All So Easy. Bloomberg.com, September 4, 2014. http://www.

bloomberg.com/news/articles/2014-09-04/the-amazon-dot-com-

of-stolen-credit-cards-makes-it-all-so-easy. Retrieved 13 May

2016.

Olavsrud, T. 2014. 11 Steps Attackers Took to Crack Target. CIO,

September 2, 2014. http://www.cio.com/article/2600345/secur

ity0/11-steps-attackers-took-to-crack-target.html. Retrieved 13

May 2016.

PwC. 2016. 19th Annual Global CEO Survey. PricewaterhouseCoop-

ers, p. 44. Retrieved from http://www.pwc.com/gx/en/ceo-survey/

2016/landing-page/pwc-19th-annual-global-ceo-survey.pdf.

Reuters and Fortune. 2015. Target will pay $10 million to settle data

breach lawsuit. Fortune, March 19, 2015. Retrieved from http://

fortune.com/2015/03/19/target-10-million-settle-data-breach/.

Riley, M., B. Elgin, D. Lawrence, and C. Matlack. 2014. Missed

Alarms and 40 Million Stolen Credit Card Numbers: How Target

Blew It. Bloomberg.com, March 17, 2014. http://www.bloom

berg.com/news/articles/2014-03-13/target-missed-warnings-in-

epic-hack-of-credit-card-data. Retrieved 13 May 2016.

Rosenthal, L.H. 2011. n re: Heartland Payment Systems, Inc.

Customer Data Security Breach Litigation, No. 834 F.Supp.2d

573 (United States District Court, S.D. Texas, Houston Division

Dec. 1, 2011). Retrieved from http://www.leagle.com/decision/

In%20FDCO%2020111202937/IN%20RE%20HEARTLAND%

20PAYMENT%20SYSTEMS,%20INC.

Satanovsky, G. 2011. How Counterfeit Credit Cards are Created From

ATM Skimmers. Fraud Fighter–Fraud Prevention Blog,

January 17, 2011. http://blog.fraudfighter.com/bid/52994/How-

Counterfeit-Credit-Cards-are-Created-From-ATM-Skimmers.

Retrieved 12 May 2016.

Steinhafel, G. 2014. An Open Letter from CEO Gregg Steinhafel,

Target Corporate, January 12, 2014. http://corporate.target.com/

article/2014/01/target-ceo-gregg-steinhafel-open-letter-guests.

Retrieved 26 April 2016.

Stempel, J., and N. Bose. 2015. Target in $39.4 million settlement

with banks over data breach, Reuters, December 3, 2015.

Retrieved from http://www.reuters.com/article/us-target-breach-

settlement-idUSKBN0TL20Y20151203.

Target. 2014a. 2013 Annual Report, Target.com. Retrieved May 13,

2016, from https://corporate.target.com/annual-reports/pdf-

viewer-2013?cover=6725&parts=6724-6726-6727-6730-6728.

Target. 2014b. Quarterly Report 10-Q, For the quarterly period

ended November 1, 2014 (SEC filing No. Commission File

Number 1-6049). Retrieved from http://investors.target.com/

phoenix.zhtml?c=65828&p=irol-secText&TEXT=aHR0cDovL2

FwaS50ZW5rd2l6YXJkLmNvbS9maWxpbmcueG1sP2lwYWdl

PTk5MjM5MTgmRFNFUT0xJlNFUT0mU1FERVNDPVNFQ1

RJT05fQk9EWSZleHA9JnN1YnNpZD01Nw%3D%3D.

Target. 2014c. Edited Transcript: TGT-Q4 2013 Target Corporation

Earnings Conference Call. Target.com, February 26, 2014. http://

phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9M

jIyNTE0fENoaWxkSUQ9LTF8VHlwZT0z&t=1. Retrieved 13

May 2016.

Target. 2014d. Target Appoints New Chief Information Officer,

Outlines Updates on Security Enhancements. Target Corporate,

April 29, 2014. http://corporate.target.com/press/releases/2014/

04/target-appoints-new-chief-information-officer-outl. Retrieved

23 June 2016.

Target. 2014e. Edited Transcript: TGT—Q2 2014 Target Corporation

Earnings Conference Call. Target.com, August 20, 2014. http://

phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9M

jY0NDkzfENoaWxkSUQ9LTF8VHlwZT0z&t=1. Retrieved 13

May 2016.

Target. 2014f. Target Names Jacqueline Hourigan Rice as Senior Vice

President, Chief Risk and Compliance Officer. Target Corporate,

November 6, 2014. http://corporate.target.com/press/releases/2014/

11/target-names-jacqueline-hourigan-rice-as-senior-vi. Retrieved 23

June 2016.

Target. 2015a. Quarterly Report 10-Q, For the Fiscal Year Ended

January 31, 2015 (No. Commission File Number 1-6049).

Retrieved from http://investors.target.com/phoenix.zhtml?c=

65828&p=irol-SECText&TEXT=aHR0cDovL2FwaS50ZW5r

d2l6YXJkLmNvbS9maWxpbmcueG1sP2lwYWdlPTEwMTQ2Njc

22 F. Pigni et al.

4JkRTRVE9MCZTRVE9MCZTUURFU0M9U0VDVElPTl9FT

lRJUkUmc3Vic2lkPTU3.

Target. 2015b. Quarterly Report 10-Q, For the Quarterly Period

Ended May 2, 2015 (No. Commission File Number 1-6049).

Retrieved from http://investors.target.com/phoenix.zhtml?c=

65828&p=irol-SECText&TEXT=aHR0cDovL2FwaS50ZW5r

d2l6YXJkLmNvbS9maWxpbmcueG1sP2lwYWdlPTEwMzA

0MDY0JkRTRVE9MCZTRVE9MCZTUURFU0M9U0VDVE

lPTl9FTlRJUkUmc3Vic2lkPTU3.

United States District Court: District of Minnesota. 2014. In re: Target

Corporation Customer Data Security Breach Litigation, No.

14-2522 (PAM/JJK), January 12, 2014. Retrieved from http://

cdn.arstechnica.net/wp-content/uploads/2014/12/document4.pdf.

Wahba, P. 2014. Target puts focus back on ‘cheap-chic’ with eye on

winning back holiday shoppers, October 21, 2014. http://fortune.

com/2014/10/21/target-holiday/. Retrieved 26 April 2016.

Weiss, N.E., and R.S. Miller. 2015. The Target and Other Financial

Data Breaches: Frequently Asked Questions. In Congressional

Research Service, Prepared for Members and Committees of

Congress February, Vol. 4, p. 2015.

Whipp, L. 2015. Target to pay $67 m over Visa data breach. FT.com,

August 18, 2015. https://www.ft.com/content/a6b571d8-45c8-

11e5-af2f-4d6e0e5eda22. Retrieved 31 July 2016.

Zetter, K. 2014. How RAM Scrapers Work: The Sneaky Tools

Behind the Latest Credit Card Hacks. WIRED, September 30,

2014. https://www.wired.com/2014/09/ram-scrapers-how-they-

work/. Retrieved 12 May 2016.

Targeting Target with a 100 million dollar data breach 23