# Attention Target Shoppers: Credit Card Data Stolen

**URL:** <https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 19, 2013, 8:53pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761 "2013-12-19T20:53:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Heart\_of\_Dorkness](https://avatars.discourse-cdn.com/v4/letter/h/4bbf92/32.png) [@Heart\_of\_Dorkness](https://boards.straightdope.com/u/Heart_of_Dorkness)\
**Post date:** [December 19, 2013, 8:53pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/1 "2013-12-19T20:53:12Z")

</div>

If you shopped at a Target store between November 27th and December 15th (which of _course_ you did) and used a credit or debit card of any kind (which of _course_ you did), then [your card data](https://corporate.target.com/discover/article/Important-Notice-Unauthorized-access-to-payment-ca) [may have been compromised](http://www.washingtonpost.com/business/technology/target-data-breach-affects-40-million-accounts-payment-info-compromised/2013/12/19/5cc71f22-68b1-11e3-ae56-22de072140a2_story.html), and you should check your accounts for suspicious activity.

Happy Holidays!

---

<div class="post-metadata">

**Author:** ![Tastes\_of\_Chocolate](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tastes_of_chocolate/32/3232_2.png) [@Tastes\_of\_Chocolate](https://boards.straightdope.com/u/Tastes_of_Chocolate)\
**Post date:** [December 19, 2013, 11:45pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/2 "2013-12-19T23:45:18Z")

</div>

I’m trying to decide if I proactively ask for a new card, or if I just keep watching my account (for how long?) for suspicious activity. I’m leaning towards the first, after the New Year.

---

<div class="post-metadata">

**Author:** ![bobot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bobot/32/21622_2.png) [@bobot](https://boards.straightdope.com/u/bobot)\
**Post date:** [December 20, 2013, 12:19am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/3 "2013-12-20T00:19:50Z")

</div>

I stopped at the bank after work to speak with a banker. When I was told that _if_ my card was used illegally, that my account could be overdrawn, my mind was made up. My new debit card will arrive in 7-10 days. Until then, I montor my account, and try to remember the places that I’ve allowed access to automatic debits. ( gas company, etc…)  
Also, I’m glad I made an old-fashioned visit to the bank, as the banker mentioned I-pass as an example of someone that may need to be notified. I do indeed need to notify I-pass and would have completely forgotten that one!

---

<div class="post-metadata">

**Author:** ![Edward\_The\_Head](https://avatars.discourse-cdn.com/v4/letter/e/ce73a5/32.png) [@Edward\_The\_Head](https://boards.straightdope.com/u/Edward_The_Head)\
**Post date:** [December 20, 2013, 1:52am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/4 "2013-12-20T01:52:07Z")

</div>

Well son of a bitch, that’s probably how my card number was stolen a couple of weeks ago.

I had the worst luck two weeks ago, I hit a deer with my car, too it to get fixed and tried to rent a car. My credit card was declined, they started asking me if I had tried to buy $1700 worth of stuff from Sweden! Since they had already shut down my card I had no way to rent a car. I’ve been wondering how my card got compromised like that, that’s the most likely answer.

---

<div class="post-metadata">

**Author:** ![Ruken](https://avatars.discourse-cdn.com/v4/letter/r/f475e1/32.png) [@Ruken](https://boards.straightdope.com/u/Ruken)\
**Post date:** [December 20, 2013, 3:10am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/5 "2013-12-20T03:10:30Z")

</div>

All the more reason to never ever use a debit card if you have access to credit cards.

---

<div class="post-metadata">

**Author:** ![TBG](https://avatars.discourse-cdn.com/v4/letter/t/c89c15/32.png) [@TBG](https://boards.straightdope.com/u/TBG)\
**Post date:** [December 20, 2013, 3:14am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/6 "2013-12-20T03:14:36Z")

</div>

I’m just glad it’s not Walmart or we’d never hear the end of it from the haters.

---

<div class="post-metadata">

**Author:** ![SantaMan](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@SantaMan](https://boards.straightdope.com/u/SantaMan)\
**Post date:** [December 20, 2013, 7:23am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/7 "2013-12-20T07:23:45Z")

</div>

…and today I got a phishing email ostensibly from Target… except all the links in the email went to some other site…

---

<div class="post-metadata">

**Author:** ![Heart\_of\_Dorkness](https://avatars.discourse-cdn.com/v4/letter/h/4bbf92/32.png) [@Heart\_of\_Dorkness](https://boards.straightdope.com/u/Heart_of_Dorkness)\
**Post date:** [December 20, 2013, 3:47pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/8 "2013-12-20T15:47:43Z")

</div>

> [@SantaMan](#):
>
> …and today I got a phishing email ostensibly from Target… except all the links in the email went to some other site…

Were the links to “[target.bfi0.com](http://target.bfi0.com)”, with really long strings of characters afterward? That appears to be a legitimate email, and the links do indeed go to [target.com](http://target.com). I recently signed up for their discount notifications and got a confirmation email right after, so I was fairly certain it was legit, and I went ahead and clicked through. But I checked the links just now, and they do look weird, as I described.

---

<div class="post-metadata">

**Author:** ![muldoonthief](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/muldoonthief/32/3188_2.png) [@muldoonthief](https://boards.straightdope.com/u/muldoonthief)\
**Post date:** [December 20, 2013, 3:50pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/9 "2013-12-20T15:50:28Z")

</div>

Amazingly, the local Target was still pretty crowded this morning - I thought it would be a ghost town. Lots of people paying with cash though.

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [December 20, 2013, 7:44pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/10 "2013-12-20T19:44:46Z")

</div>

I found another article on this theft:

> **[Cards Stolen in Target Breach Flood Underground Markets – Krebs on Security](https://krebsonsecurity.com/2013/12/cards-stolen-in-target-breach-flood-underground-markets/)**
>
> Cards stolen in a recent data breach at retail giant Target have been flooding underground black markets in recent weeks, selling in batches of one million cards and going for anywhere from $20 to more than $100 per card, KrebsOnSecurity…

Previous articles had said credit card information was stolen; this article makes clear those numbers are for sale at online markets dealing in stolen credit cards. So very definitely if you purchased anything at a Target store using a credit card from Nov. 27 and Dec. 15 you need to monitor your credit card account for suspicious activity.

I think it likely that after the holidays a lot of these cards will be replaced.

---

<div class="post-metadata">

**Author:** ![SurrenderDorothy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/surrenderdorothy/32/1221_2.png) [@SurrenderDorothy](https://boards.straightdope.com/u/SurrenderDorothy)\
**Post date:** [December 20, 2013, 8:41pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/11 "2013-12-20T20:41:46Z")

</div>

The same damn thing happened at Schnucks like not even a year ago. What the fuck. And there was some stupid confusion because I went and got a new card from my bank, but somehow didn’t do it the way they wanted, so they canceled my card out of the blue a little bit later and I had to get ANOTHER new card. Looks like I get to do it again.

---

<div class="post-metadata">

**Author:** ![Machine\_Elf](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@Machine\_Elf](https://boards.straightdope.com/u/Machine_Elf)\
**Post date:** [December 20, 2013, 9:16pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/12 "2013-12-20T21:16:48Z")

</div>

> [@Tastes\_of\_Chocolate](#):
>
> I’m trying to decide if I proactively ask for a new card, or if I just keep watching my account (for how long?) for suspicious activity. I’m leaning towards the first, after the New Year.

Why bother? If it’s a credit card, you won’t be responsible for any fraud on it. Well, technically you could be asked to pay the first $50 of it, but if you tell the bank you’ll cancel the card if they make you pay, then generally the bank will even take care of that $50 for you; they’d rather have your continued business.

Skip the hassle. Just keep an eye on your monthly statement (which you always should be doing anyway), and on the off-chance that something weird pops up, give your bank a call.

The news piece I saw said that although several million card numbers were stolen, only a small percentage of them will ever be used for fraudulent purposes. So if there’s only a 5% chance your card will get used, and you won’t be responsible for the mess anyway, why give yourself all that work?

OTOH, if you used a debit card, you probably ought to check with your bank to see what their fraud policy is. If they say it’s gonna be on you, then yes, change your card ASAP.

---

<div class="post-metadata">

**Author:** ![VinylTurnip](https://avatars.discourse-cdn.com/v4/letter/v/b2d939/32.png) [@VinylTurnip](https://boards.straightdope.com/u/VinylTurnip)\
**Post date:** [December 20, 2013, 9:41pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/13 "2013-12-20T21:41:04Z")

</div>

> [@Machine\_Elf](#):
>
> Why bother? If it’s a credit card, you won’t be responsible for any fraud on it. Well, technically you could be asked to pay the first $50 of it, but if you tell the bank you’ll cancel the card if they make you pay, then generally the bank will even take care of that $50 for you; they’d rather have your continued business.

It would render the old number unusable, so if you feel like doing your civic duty— the cost of fraudulent charges does get spread around to consumers, ultimately— or just feel like sticking it to the dickhead hackers, it’s a tactic to consider.

My wife and I have three cards that were used during the period in question. No suspicious charges so far; still considering whether to get new cards or take your approach.

---

<div class="post-metadata">

**Author:** ![DummyGladHands](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@DummyGladHands](https://boards.straightdope.com/u/DummyGladHands)\
**Post date:** [December 21, 2013, 3:10am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/14 "2013-12-21T03:10:47Z")

</div>

So they’re giving a whopping 10% this weekend, and I haven’t seen the restrictions–are there any? Or many?

10% is just a crap move, IMHO. Hell, they could have sucked every bit of last minute money out of the hands of the late shoppers if they’d made it even 20%. And be ahead.

---

<div class="post-metadata">

**Author:** ![Rachellelogram](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rachellelogram/32/8689_2.png) [@Rachellelogram](https://boards.straightdope.com/u/Rachellelogram)\
**Post date:** [December 21, 2013, 3:34am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/15 "2013-12-21T03:34:25Z")

</div>

> [@Ruken](#):
>
> All the more reason to never ever use a debit card if you have access to credit cards.

Not sure what your reasoning is, here. You aren’t responsible for fraudulent charges if you report them quickly. And debit/credit card numbers are equally easy to steal and use.

> [@VinylTurnip](#):
>
> It would render the old number unusable, so if you feel like doing your civic duty— the cost of fraudulent charges does get spread around to consumers, ultimately— or just feel like sticking it to the dickhead hackers, it’s a tactic to consider.
> 
> My wife and I have three cards that were used during the period in question. No suspicious charges so far; still considering whether to get new cards or take your approach.

Just get new cards. The threat of having your card numbers used “sometime” will never go away until they expire and are reissued. I work at a bank, and we’ve been told to advise customers to watch and wait,\*\* only \*\*because it makes less work for us. Waiting on new cards to arrive is a minor inconvenience compared to the thought of watching your statement like a hawk for the next few years. Nobody wants the worry hanging over their heads of a scammer possibly running up a huge bill at their expense.

I don’t shop at Target, so luckily I don’t have to worry about this. But if you did, get a new card whether you notice any suspicious activity or not. I sure as shit would.

---

<div class="post-metadata">

**Author:** ![DummyGladHands](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@DummyGladHands](https://boards.straightdope.com/u/DummyGladHands)\
**Post date:** [December 21, 2013, 3:38am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/16 "2013-12-21T03:38:52Z")

</div>

And ask Experian or one of the other credit reporting sites to put a fraud alert on your account. Experian. in my case, is advising the other 2 credit bureau automatically, so it was quick and easy.

---

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [December 21, 2013, 4:41am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/17 "2013-12-21T04:41:19Z")

</div>

> [@Machine\_Elf](#):
>
> Why bother? If it’s a credit card, you won’t be responsible for any fraud on it.

The problem is if you only have one payment method available in your wallet/purse and suddenly out of the blue that payment method is shut down because of credit card theft problems, you have problems.

---

<div class="post-metadata">

**Author:** ![Tastes\_of\_Chocolate](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tastes_of_chocolate/32/3232_2.png) [@Tastes\_of\_Chocolate](https://boards.straightdope.com/u/Tastes_of_Chocolate)\
**Post date:** [December 21, 2013, 10:14am UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/18 "2013-12-21T10:14:36Z")

</div>

> [@PastTense](#):
>
> The problem is if you only have one payment method available in your wallet/purse and suddenly out of the blue that payment method is shut down because of credit card theft problems, you have problems.

Plus, my current card doesn’t expire for 2 years. Do I really want to spend the next 2 years worrying that I might have my card number used by someone else? I’d rather ask for a new card in 2 weeks, switch over all my autobill stuff, and be done with it.

---

<div class="post-metadata">

**Author:** ![Ruken](https://avatars.discourse-cdn.com/v4/letter/r/f475e1/32.png) [@Ruken](https://boards.straightdope.com/u/Ruken)\
**Post date:** [December 21, 2013, 2:25pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/19 "2013-12-21T14:25:37Z")

</div>

> [@Rachellelogram](#):
>
> Not sure what your reasoning is, here. You aren’t responsible for fraudulent charges if you report them quickly. And debit/credit card numbers are equally easy to steal and use.

While you’re getting things sorted out with the bank, do you want your money screwed up and potentially inaccessible, or someone else’s money screwed up?

---

<div class="post-metadata">

**Author:** ![jacobsta811](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jacobsta811/32/2893_2.png) [@jacobsta811](https://boards.straightdope.com/u/jacobsta811)\
**Post date:** [December 21, 2013, 2:39pm UTC](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761/20 "2013-12-21T14:39:57Z")

</div>

> [@DummyGladHands](#):
>
> And ask Experian or one of the other credit reporting sites to put a fraud alert on your account. Experian. in my case, is advising the other 2 credit bureau automatically, so it was quick and easy.

Why ? Your identity hasn’t been stolen, they don’t have the information to apply for a new credit account. Just the information physically on your credit card. Which is Name, Number, CVV (not CVV2 - that is on the back). The Krebs article says the card #'s are being sold with the Target store location as well, so they have your state and your/a nearby zip code as well. Not enough to apply for a credit card, so the credit bureau fraud alert won’t help you at all. The places who should be livid about this breach and the fact that they aren’t replacing all the cards immediately are someplace like Walmart, Best Buy, etc, who are going to get hit with huge fraud from clones of stolen cards.

[Next page](https://boards.straightdope.com/t/attention-target-shoppers-credit-card-data-stolen/676761.md?page=2)
