A First Look at the Target Intrusion, Malware
Last weekend, Target finally disclosed at least one cause of the massive data breach that exposed personal and financial information on more than 110 million customers: Malicious software that infected point-of-sale systems at Target checkout counters.
Context & Ripple Effects
This is the technical follow-through on a story Krebs on Security started with its December 18 report that Target was investigating a breach. Since then the numbers have only grown: Target confirmed stolen PIN data in late December, disclosed that personal information for up to 70 million customers was also taken on January 10, and CEO Gregg Steinhafel confirmed on January 12 that point-of-sale malware was used in the attack.
Today's piece is the first detailed look at the malware itself — the software planted on checkout terminals at one of America's largest retailers during the holiday shopping season. The breadth of pickup matters here: the same-day syndication across the New York Times, Reuters, Forbes, Ars Technica, ZDNet, CNET, Business Insider and Poynter shows this has moved from a security trade story to a mainstream consumer-trust event.
First-order effects
- Card-issuing banks and credit unions face immediate reissuance costs as they replace compromised credit and debit cards for millions of customers whose account numbers were captured between late November and early December.
- Target's disclosure that the intrusion reached checkout counters puts every major US retailer's point-of-sale environment under board-level scrutiny, since the attack hit encrypted PIN data as well as card numbers.
Second-order effects
- POS terminal vendors and payment processors will be pressed by retail customers to demonstrate how memory-scraping malware evaded their defenses, shifting procurement conversations toward endpoint hardening rather than network perimeter claims.
- Competing retailers must now weigh accelerated migration to chip-and-PIN style card authentication in the US market, where the magnetic-stripe architecture Target's attackers exploited remains standard.
Third-order effects
- If in-memory card capture at the terminal proves repeatable across large chains, liability for card-present fraud shifts structurally — pushing issuers, networks and merchants into renegotiating who pays when the point of sale itself is compromised.
- The episode strengthens the case for regulators and card networks to mandate stronger authentication at US checkouts, turning what was an optional upgrade path into a competitive and compliance necessity.
The trend: US retail payments are being pushed off magnetic-stripe swipes toward authenticated chip transactions, as point-of-sale malware turns the checkout terminal from a trusted endpoint into the industry's primary attack surface.