Exclusive: More well-known U.S. retailers victims of cyber attacks - sources
(Reuters) - Target Corp and Neiman Marcus are not the only U.S. retailers whose networks were breached over the holiday shopping season last year, according to sources familiar with attacks on other merchants that have yet to be publicly disclosed.
Context & Ripple Effects
Krebs on Security first reported Target was investigating a data breach on December 18, 2013, and the story widened when Neiman Marcus was confirmed among the retailers whose networks were hit over the holiday shopping season. Reuters' sourcing now pushes the frame past two named victims: other well-known merchants are said to have been breached but have yet to disclose.
The pickup breadth itself is the signal — SecurityWeek, the Wall Street Journal, TechCrunch, VentureBeat, Gizmodo and others all carried the story within days, turning what began as a single-retailer investigation into a sector-wide question of who else is holding an unannounced breach.
First-order effects
- The unnamed breached merchants face a compressed disclosure decision: once Target's and Neiman Marcus's incidents are public, staying quiet becomes harder to sustain, while their card-issuing banks absorb fraud losses and card-reissuance costs on compromised accounts.
- Target and Neiman Marcus move from isolated incidents to reference cases — every new revelation about the attack pattern raises the cost of their own response and remediation.
Second-order effects
- Other large U.S. retailers are pushed into forensic sweeps of their own point-of-sale environments ahead of any external disclosure, since the rumor that the attacks share a pattern makes every merchant a potential victim until proven otherwise.
- Card networks and payment processors come under renewed pressure from retailers and issuers over transaction authentication, because repeated magnetic-stripe data theft shifts the liability argument toward whoever controls card technology standards.
Third-order effects
- If a pattern of undisclosed retail breaches holds, expect regulators and state attorneys general to press for shorter, mandatory breach-notification timelines, ending the current window in which companies can investigate quietly for weeks.
- Retail security budgets structurally shift from network perimeter defense toward transaction-layer monitoring, as the demonstrated threat lives inside point-of-sale systems rather than at the firewall.
The trend: The 2013-14 holiday breach cluster is accelerating U.S. retail from isolated incident response toward industry-wide point-of-sale forensics and a fight over who bears breach liability and disclosure obligations.