The story broke on a Wednesday. On 18 December 2013 Brian Krebs, writing at Krebs on Security, reported that Target was investigating a breach involving the card readers in its stores across the United States, and that the exposure appeared to run from just after Thanksgiving to at least 15 December — a window his sources had watched expand by a week while they were describing it to him. Target said nothing that day beyond confirming that it was working with law enforcement. The next morning, 19 December, it issued a statement of its own: unauthorised access to payment card data at its American stores, approximately forty million credit and debit accounts, between 27 November and 15 December. The intrusion had begun earlier and quietly. The disclosure made December.
What had been taken was track data — the contents of the magnetic stripe, enough to encode a working counterfeit onto any blank card with a stripe on the back. It surfaced almost immediately. On 20 December Krebs reported that a card shop trading as rescator[dot]la was selling a fresh batch, the proprietor labelling his consignments Tortuga and numbering them upward as each arrived, at prices from about twenty dollars to more than a hundred. Each record carried the ZIP code and city of the store it came from, so a buyer could shop near where the card had last been used and slip past a geographic check. Banks bought their own customers' cards back from the shop to see what they were looking at, and found the purchases matched Target's window.
By that weekend the breach had left the trade press. Target's call centre and its card website could not carry the volume; customers trying to find out whether their own account was among the forty million met an engaged line and a login page that would not load. On 20 December Gregg Steinhafel, the chief executive, published a message on the company's site apologising for the disruption, offering free credit monitoring, and extending to shoppers in American stores on 21 and 22 December the ten per cent discount Target's own staff receive. The unauthorised access, he wrote, had been "identified and eliminated". A week later, on 27 December, the company added that encrypted debit card PIN data had been taken as well.
How the intruders had got in was not known in December. Krebs published it in February 2014: credentials belonging to Fazio Mechanical Services, a refrigeration and heating contractor in Sharpsburg, Pennsylvania, used to reach a Target system from outside. Fazio said in a statement of 6 February 2014 that its data connection with Target was for electronic billing, contract submission and project management, that it did not remotely monitor heating or cooling equipment, and that it too was a victim. The count did not hold either. On 10 January 2014 Target revised the disclosure to add names, postal addresses, telephone numbers and email addresses for up to seventy million people — a separate set, and a larger one. That revision belongs to January 2014.
Eleven days, two answers
Two federal district judges considered the National Security Agency's bulk collection of American telephone metadata within eleven days of each other and reached opposite conclusions. On 16 December 2013, in Klayman v. Obama, Judge Richard Leon of the District of Columbia held the programme likely unconstitutional under the Fourth Amendment, wrote that James Madison would be aghast at the sweep of the order, and called what the government had built "almost-Orwellian technology"; he granted an injunction and then stayed it pending appeal, so nothing actually stopped. On 18 December the President's Review Group on Intelligence and Communications Technologies published Liberty and Security in a Changing World, forty-six recommendations, among them that the government give up holding the bulk telephone records itself. On 27 December, in ACLU v. Clapper, Judge William Pauley of the Southern District of New York dismissed the complaint, reasoning from Smith v. Maryland that records handed to a telephone company carry no reasonable expectation of privacy. Both were overtaken. The Second Circuit reversed Pauley on 7 May 2015, holding the programme exceeded what Section 215 authorised; the D.C. Circuit vacated Leon's injunction on 28 August 2015 on standing.
A botnet, a contract and a catalogue
Three stories about equipment that could not be trusted. On 5 December Microsoft's Digital Crimes Unit, Europol's European Cybercrime Centre, the FBI and A10 Networks moved against ZeroAccess, a click-fraud botnet which Microsoft said had infected more than two million machines and cost advertisers about $2.7 million a month; eighteen IP addresses were blocked. Microsoft said it did not expect to eliminate the botnet, and it did not — the peer-to-peer layer went untouched, and Dell SecureWorks watched the click fraud restart on 21 March 2014. On 20 December Reuters reported that the National Security Agency had paid RSA Security $10 million to make Dual_EC_DRBG the default random number generator in BSAFE; RSA answered on 22 December that it had never entered a "secret contract" to weaken its products, a denial about intent, not money. And on 29 and 30 December Der Spiegel published the catalogue of the agency's Tailored Access Operations unit — forty-nine pages dated 2008 and 2009, implants priced from nothing to $250,000, several fitted into hardware intercepted in transit. Jacob Appelbaum presented it in Hamburg on 30 December. The agency declined to comment; the named manufacturers denied any collaboration.
The stripe and the filter
The forty million cards were American; the argument about magnetic stripes was not. India's regulator had already moved against the stripe before Target's window opened. The Reserve Bank's circular of 28 February 2013 on security and risk mitigation measures for electronic payment transactions told banks to convert to chip and PIN any magnetic-stripe card whose holder had used it abroad, to place threshold limits on the international transactions still permitted on the remaining stripe cards, and to have merchant terminals and acquiring infrastructure certified to the payment card industry data security standards — all by 30 June 2013. What no Indian rule required in 2013 was the other half of the Target story: nothing obliged a bank or a retailer to tell a customer that their card details had gone, or to tell anyone at all.
The month's Indian surveillance story arrived on 16 December, when the Economic Times reported that the government intended to deploy NETRA — network traffic analysis — a system built by the Centre for Artificial Intelligence and Robotics, a Defence Research and Development Organisation laboratory, to sift internet traffic in real time for words including attack, bomb, blast and kill, with the Intelligence Bureau and the Research and Analysis Wing among the agencies using it. It arrived alongside the Central Monitoring System, then being rolled out to automate the interception of telephone and internet traffic, and it arrived into a country with no data protection statute and no privacy law to set against either. Both gaps closed late. Breach reporting became a direction in 2022, in CERT-In's six-hour rule, and a statute in 2023, in the DPDP Act.
Seven Games, and a New Lab
Both of the month's artificial-intelligence stories ran through the Neural Information Processing Systems conference at Lake Tahoe. On 9 December 2013 Facebook said it was building a research group in artificial intelligence under Yann LeCun, the New York University professor whose convolutional networks dated to the 1980s, with sites in Menlo Park, London and a floor a block from NYU; Mark Zuckerberg gave the details at its deep-learning workshop. The same workshop heard a paper from DeepMind, a small London company — a convolutional network trained by Q-learning on raw screen pixels, posted to arXiv on 19 December as Playing Atari with Deep Reinforcement Learning. It played seven Atari 2600 games with no adjustment between them, beat every prior method on six and a human expert on three, and learned, in the paper's words, "directly from high-dimensional sensory input". Google bought DeepMind the next month; the fuller result reached Nature in February 2015. The group Facebook started that week became Facebook AI Research, and outlasted LeCun, who left Meta at the end of 2025 to start his own company.
Half a Takedown, and a Count
December's operation against ZeroAccess showed what a takedown cannot do. A coalition led by Microsoft's Digital Crimes Unit moved against the click-fraud botnet's command infrastructure, and the seizure was real but partial: not every command server was taken, and the peer-to-peer layer through which the network updated itself was untouched, so the machines remained reachable by their operators. It followed Symantec's sinkholing of about half a million bots in September and left the same conclusion — that a botnet designed without a centre cannot be decapitated, only starved. The lesson was applied properly eighteen months later against GameOver Zeus, where the peer-to-peer network itself was the target. The month's other endpoint story was arithmetic. Dell SecureWorks' Counter Threat Unit, publishing in the closing weeks of December, estimated that CryptoLocker had reached between 200,000 and 250,000 machines in its first hundred days — a figure that was the vendor's estimate, not a count, and the first serious attempt to size what ransomware had become.
⏳ Time capsule — December 2013
- On 5 December Nelson Mandela died at his home in Houghton, Johannesburg, aged 95; President Jacob Zuma announced it on national television later that night. The memorial service was held at FNB Stadium on 10 December, and he was buried at Qunu in the Eastern Cape on 15 December.
- On 13 December Beyoncé released her fifth album on the iTunes Store without announcement or advance promotion; it sold 828,773 digital copies worldwide in three days.
- On 14 December China's Chang'e 3 spacecraft, launched on 1 December, set down in Mare Imbrium and released the Yutu rover — the first soft landing on the Moon since the Soviet Luna 24 mission in 1976.
- On 28 December Arvind Kejriwal was sworn in as Chief Minister of Delhi at Ramlila Maidan, having travelled to his own swearing-in on the Metro.
What the queue paid for
Target's ending is the most thoroughly documented in this archive. Beth Jacob, the chief information officer, resigned on 5 March 2014; Gregg Steinhafel left on 5 May 2014. The company settled with consumers for $10 million in 2015, with card-issuing banks for $39.4 million that December, and with forty-seven states and the District of Columbia for $18.5 million in May 2017 — then the largest multi-state settlement of a data breach. Its own filings put cumulative expenses at about $292 million gross, roughly $202 million after insurance: the cost of the incident, not the trade the queues cost it that Christmas. What ended the market in stripe data was none of that. It was the liability shift of October 2015, moving counterfeit-card losses onto whichever party had not gone to chip.
The surveillance argument was settled by legislation rather than by either judge. The Second Circuit reversed Pauley in May 2015; the USA Freedom Act, signed on 2 June 2015, ended the government's own bulk holding of American telephone records and left them with the carriers, close to what the Review Group had recommended eighteen months earlier. The catalogue proved harder to legislate away. Interdiction — hardware taken out of a shipment, altered, put back — became a procurement assumption rather than a disclosure, and by 2026 a server's provenance and whether it can attest to its own firmware are asked before purchase. The card shop outlasted all of it: the same Rescator storefront sold the Home Depot cards in September 2014, and Krebs reported signs of the same group behind both.