Target agrees to $10M settlement in class-action suit for 2013 data breach, up to $10K/person
Target agrees to pay $10 million to data breach victims — MINNEAPOLIS — Target has agreed to pay $10 million under a proposed settlement in a class-action lawsuit stemming from a massive 2013 data breach …
Context & Ripple Effects
This $10 million consumer settlement opens the consumer-facing front of Target's long reckoning with the 2013 breach, weeks after Target disclosed that the incident had cost it $162M across 2013-14. The bigger money has always been on the financial-institution side: MasterCard issuers had just secured an earlier $19M settlement in April, with Visa still pending.
What makes this filing notable as an early marker is how the payout structure — up to $10K per person — later became one strand in a multi-front resolution that eventually included an $18.5M multistate settlement requiring Target to segment cardholder data and adopt two-factor authentication.
First-order effects
- Breach victims gain a claims route worth up to $10K each from the proposed $10M fund, while Target adds a consumer-liability line to a bill already dominated by its disclosed $162M in direct costs.
Second-order effects
- Card-issuing banks read these consumer terms as a floor-setter: Target's parallel negotiations with MasterCard and Visa over issuer reimbursements proceed against a public benchmark of what breach victims themselves receive.
Third-order effects
- The sequence — consumers first, then banks, then states demanding structural fixes like network segmentation and two-factor authentication — establishes the playbook that later breaches such as T-Mobile's $350M consumer settlement would follow at larger scale.
The trend: Major retailer breaches are settling across every affected constituency — shoppers, issuing banks, state attorneys general — with each successive layer converting litigation payouts into mandated security architecture.