Exclusive: Target hackers stole encrypted bank PINs - source
(Reuters) - The hackers who attacked Target Corp (TGT.N) and compromised up to 40 million credit cards and debit cards also managed to steal encrypted personal identification numbers (PINs), according to a senior payments executive familiar with the situation.
Context & Ripple Effects
The PIN report escalates what began six days earlier, when Target confirmed a breach affecting 40 million credit and debit card accounts. A senior payments executive tells Reuters the attackers also took encrypted PINs — a claim Target denies the same day, per CBS New York, leaving shoppers and issuers with two contradictory accounts from the company and its sources.
The story has traveled unusually fast and wide for a holiday-week retail breach: Krebs on Security, TIME, Fox News, The Verge, Computerworld and Business Insider all carried versions on or about December 25, and Krebs separately reported that the Rescator.la marketplace where cards from the hack surfaced was linked to a Ukrainian individual.
First-order effects
- Banks and debit-card issuers now have to decide whether to treat customer PINs as exposed — reissuing cards and resetting PINs at scale — even while Target insists no PINs were compromised.
- Target faces a credibility problem in real time: its own denial directly contradicts a named senior payments executive, and every hour of ambiguity raises fraud liability questions for the retailer and the card networks.
Second-order effects
- Payment processors and card networks will be pushed to show whether the PIN encryption keys stayed segregated from the stolen encrypted data, since encrypted PINs are only as safe as the separation of those keys — a question that shifts scrutiny from Target alone to the entire retail payments chain.
- Rival retailers should expect the same forensic and press scrutiny applied to their own point-of-sale environments, as issuers and networks reassess how PIN data is handled at checkout terminals industry-wide.
Third-order effects
- If the pattern holds — large US retailers storing or transmitting PINs in ways attackers can reach — the episode strengthens the case for moving US debit authentication toward architectures like chip-and-PIN, and for regulators and PCI standard-setters to tighten rules on PIN handling at merchant terminals rather than treating card numbers as the only crown jewels.
The trend: US retail data breaches are shifting from card-number theft toward full payment-credential compromise, dragging PIN security and merchant terminal standards into the regulatory spotlight.