Target Got Hacked Hard in 2005. Here's Why They Let It Happen Again
A gang of shadowy hackers tears through the systems of big-box retailers, making off with millions of credit and debit card numbers in a matter of weeks and generating headlines around the country. — Target and Neiman Marcus in 2013?
Context & Ripple Effects
Target's breach has been unfolding in confirmations through January: first that encrypted debit PIN data was swept up in the theft in late December, then that point-of-sale malware was the attack vector. Wired's added wrinkle is historical: hackers hit Target hard once before, in 2005, making the 2013 campaign a repeat rather than a first strike.
The story also widens beyond one retailer — Neiman Marcus was hit in what the reporting frames as the same 2013 campaign against big-box merchants, which turns two isolated incidents into a pattern question: why did large retailers with known exposure fail to stop an attack type they had already survived?
First-order effects
- Target and Neiman Marcus are absorbing direct breach fallout — millions of stolen card numbers force issuers to reissue cards and both retailers face eroding customer trust during their highest-stakes season.
Second-order effects
- Other big-box retailers now face pressure to audit their own point-of-sale environments for the same malware family, since the campaign demonstrably scaled across multiple chains rather than targeting one victim.
Third-order effects
- If repeat breaches persist despite known precedents, expect regulators and card networks to push structural fixes in US retail payments — shifting responsibility for point-of-sale security from consumers' cards to merchants' terminals.
The trend: US retail is entering an era where payment-card breaches recur across chains faster than defenses harden, forcing the industry toward merchant-side terminal security.