Sources: Target to pay Visa up to $67M over 2013 data breach, is working with MasterCard on similar deal after earlier $19M settlement rejected
Robin Sidel / Wall Street Journal :
Context & Ripple Effects
The 2013 breach has been an accumulating bill for Target: it disclosed $162M in direct costs across 2013-14 and settled a customer class action for up to $10K per person. The financial-institution side stalled when the biggest MasterCard issuers rejected the $19M settlement, leaving that channel open.
First-order effects
- Visa issuers stand to receive up to $67M from Target, more than triple the amount the MasterCard banks refused, resolving the largest outstanding claim from the breach.
- Target must now negotiate a fresh MasterCard deal with the same large issuers whose rejection forced the higher price point.
Second-order effects
- The rejection tactic worked: by holding out, the biggest MasterCard issuers established that Target's per-network payouts scale with issuer leverage, strengthening their hand in the follow-on negotiation.
- Other breached retailers face a repriced template — issuing banks now have a demonstrated playbook of rejecting lowball settlements and waiting for the next network to set a higher floor.
Third-order effects
- If the pattern holds, card networks consolidate into the de facto collectors of breach liability, with settlement size determined by issuer bargaining rather than the retailer's own cost disclosures — pushing retailers toward the kind of security commitments (network segmentation, two-factor authentication) regulators later demanded of Target.
- Breach remediation increasingly becomes a standing line item negotiated across multiple constituencies — customers, states, and each card network separately — rather than a single legal resolution.
The trend: Payment-card breach liability is migrating from retailer-settlement discretion to issuer-driven price discovery, with the card networks as the toll booths through which every payout passes.