Judge rejects Target's bid to throw out banks' lawsuits; ruling makes clear that banks have right to go after retailers that were negligent in security
Banks' Lawsuits Against Target for Losses Related to Hacking Can Continue — A federal judge on Tuesday handed an early victory …
Context & Ripple Effects
This ruling is the legal turning point in the fallout from Target's 2013 breach. Until now, banks that reissued millions of compromised cards had largely absorbed those costs; by refusing to dismiss their negligence claims, the judge opened the door to retailers being held financially liable to financial institutions — a shift later validated when Target ultimately paid banks and MasterCard issuers a $39.4M settlement after Visa issuers settled for up to $67M. The decision also fed a broader judicial softening, as federal courts began recognizing ongoing harm to data breach victims, fueling class actions.
First-order effects
- Banks' lawsuits against Target proceed past the motion-to-dismiss stage, forcing Target to litigate (and eventually settle) claims for card-reissuance and fraud losses it had assumed were unrecoverable.
- The ruling establishes precedent that retailers negligent in security can be directly sued by banks, not just by consumers or regulators.
Second-order effects
- Target accelerates security remediation — including security-heavy chip cards and, per its later $18.5M multi-state settlement, network segmentation and two-factor authentication — while other retailers face pressure to make similar investments preemptively.
- Banks gain leverage in settlement negotiations: emboldened by the court's stance, major MasterCard issuers later rejected Target's $19M offer as too low, driving the eventual payout higher.
Third-order effects
- If the pattern holds, breach liability becomes a negotiated cost of doing business for retailers, shifting security spending from optional risk management to a defense against litigation from downstream financial partners.
- Standing for third-party breach victims (banks, and later consumers via ongoing-harm theories) hardens into doctrine, raising the expected cost of any large retailer breach industry-wide.
The trend: Courts are progressively dismantling the assumption that data breach costs stop at the breached company, converting cybersecurity failures into direct financial liability toward business partners.