Biggest MasterCard issuers reject $19M settlement with Target over hacked credit-card data
Robin Sidel / Wall Street Journal :
Context & Ripple Effects
Target's 2013 card breach had already cost it a disclosed $162 million through 2013-14, and in April the network agreed to a $19 million payout to MasterCard issuing banks for reissuing compromised cards. The issuers' rejection means that deal dies and negotiations restart from a higher floor — the same dynamic that produced the parallel Visa track, where Target ultimately paid up to $67 million to Visa issuers.
First-order effects
- The April $19 million offer lapses without taking effect, so Target's MasterCard-side liability stays open while its Visa-side exposure is already settling at roughly three times that figure — a benchmark issuers can now point to.
Second-order effects
- With Visa's larger payout on the record, MasterCard issuers gain leverage to hold out for comparable per-card reimbursement, pushing Target's total breach bill well beyond the amounts it had provisioned across the two networks.
Third-order effects
- The pattern that ends in the December $39.4 million bank-and-issuer settlement and the 2017 $18.5 million multi-state accord — which forced Target to segment cardholder data and adopt two-factor authentication — shows breach costs being set by issuer bargaining power rather than retailer offers, with regulators extracting operational security changes on top of cash.
The trend: Retail data breaches are shifting from fixed retailer-proposed payouts to issuer-negotiated settlements whose size ratchets upward as each network's deal sets a floor for the next.