TARGET BREACH: PIN Data Was Stolen

target

(CNNMoney) — Target confirmed Friday that debit card PIN data was stolen in its recent massive breach, reversing its earlier stance that the codes were not part of the hack.

However, the retailer believes the PINs remain “safe and secure.” In a statement, Target spokeswoman Molly Snyder said the PINs are “strongly encrypted” and were never stored on Target’s systems in plain text.

In other words, from the moment a customer entered a PIN after swiping a debit card, Target’s payment system translated that number into an indecipherable string of code. Target claims that the PINs remained encrypted after they were stolen.

Not only are the PINs encrypted, Target says the numbers can only be decrypted by the independent payment processor, which holds the decryption key. That key is necessary to translate the unintelligible code back into the PIN. Target said the key was not stolen as part of the breach, because it never existed within the company’s systems.

Target says it uses the Triple Data Encryption Standard to encrypt its PIN codes. Per Thorsheim, an Independent password security consultant, said the PINs encrypted with the Triple DES algorithm would be “difficult or impossible to decrypt,” if the payment processor’s decryption key was robust enough. Target declined to comment on the identity of its payments processor.

That means it is very unlikely that thieves would be able to withdraw money from ATMs using stolen debit card information. Consumers are protected from certain instances of debit card fraud, but cash withdrawals and purchases made with a PIN can be tricky to reverse.

As a precaution, Target customers who shopped at Target when the breach occurred should contact their banks to request a replacement card and change their PIN.

The PIN theft revelation means that Target’s payment systems breach was larger than initially thought. That is common in credit card breaches. When Marshalls’ and TJ Maxx’s parent company TJX was hit with a massive breach in 2009, the company initially said 45 million accounts were hacked but upped that number to 94 million weeks later.

Target says that its breach, which took place between Black Friday and Dec. 15, compromised 40 million customers’ payment information.

2 comments

  • Mike Cee

    A month ago the retailer believed the credit and debit card numbers were safe and secure. When the story first broke, the retailer believed that no debit card PIN numbers were stolen. Now they acknowledge that debit card PIN numbers were stolen, but they’re “safe and secure” even though they’re encrypted and in the hands of the criminals.

    I wonder what they’ll believe next week.

  • Scott Spiker

    This story is a little misleading. PINs are encrypted at the point of entry so they are secure. What was “stolen” were cryptograms of PINs. which are not useful to commit fraud. This is why data is encrypted, the encrypted data can processed in open networks without risk of the data being revealed. Target devices use the same algorithm and key strength as any other compliance PIN entry device, including ATMs. So when Target announced that PINs were not stolen, that is technically correct, the PIN values were not exposed, only the encrypted values.

    It is sad that we live in an era of data breaches, but they will continue to occur as long as the card brands keep using technology that can be easily counterfeited (the magnetic stripe). The card products are weak yet we hold the merchant accountable for the protection of the data.

Comments are closed.

Follow

Get every new post delivered to your Inbox.

Join 1,069 other followers