Attackers initially stole 40 million credit and debit card numbers in the 2013 Target data breach.
The breach occurred during the 2013 holiday shopping season after attackers obtained access through credentials associated with an HVAC contractor. They installed malware on point-of-sale systems, where it collected payment-card data as customers made purchases in Target stores.
Target first announced that information from up to 40 million credit and debit cards had been affected. The company later disclosed that personal information connected to as many as 60 million additional customers had also been compromised, including names, addresses, phone numbers, and email addresses. Those figures are why summaries sometimes cite 110 million affected records or customers, but the original payment-card figure was 40 million.
The incident became a major example of third-party risk and point-of-sale compromise. It also led to executive departures, legal settlements, and renewed pressure on retailers to improve network segmentation and payment-data protection.