The Target data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with Target, it's worth checking whether your data was involved.
What Happened
Target suffered one of the most well-known retail data breaches in history during the 2013 holiday shopping season. Attackers gained access using stolen credentials from an HVAC vendor with remote access to Target's network, then installed malware on point-of-sale systems across nearly all US stores. The breach was active from late November to mid-December 2013 and was disclosed on 19 December 2013.
What Data Was Exposed
Approximately 40 million payment card numbers, expiration dates, and CVV codes were stolen from card swipes during the breach window, along with a separate set of about 70 million customer records containing names, addresses, phone numbers, and email addresses.
Why This Still Matters
Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial accounts closely if payment or banking data was involved.
- Watch for phishing — breach data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the Target data breach happen?
The breach was active from around 27 November to 15 December 2013 — the peak of the holiday shopping season. Target publicly disclosed the breach on 19 December 2013.
What data was stolen in the Target breach?
Approximately 40 million payment card numbers, expiration dates, and CVV codes were stolen from in-store card swipes, along with a separate dataset of about 70 million customer records containing names, addresses, phone numbers, and email addresses.
How did the Target breach happen?
Attackers first compromised an HVAC vendor with remote network access to Target's systems using a phishing email, then used those stolen credentials to move through Target's network and install custom malware on point-of-sale terminals nationwide.
How do I check if I was affected by the Target breach?
If you shopped at a US Target store with a payment card during the 2013 holiday season, you were very likely affected. You can also check your email at Scan My Shadow.
What was the outcome of the Target breach?
Target paid a $18.5 million multistate settlement, plus separate settlements with Visa and Mastercard totaling tens of millions more. The breach also led to the resignation of Target's CEO and CIO and prompted the retail industry's broader shift to chip-based payment cards.