Nothing about November 2013 looked like a crisis while it was happening. The intrusion that became the Target breach began with credentials belonging to Fazio Mechanical Services, a refrigeration and heating contractor in Sharpsburg, Pennsylvania, whose connection to the retailer, the company said afterwards, "was exclusively for electronic billing, contract submission and project management" — not, as was first assumed, remote monitoring of shop-floor equipment. When the attackers used that access is one of the few points on which the record diverges. The Senate Commerce Committee's staff analysis of 26 March 2014 put the first entry into Target's internal network at 12 November 2013; Brian Krebs, reporting in February 2014, gave 15 November. Both accounts agree the way in was a supplier's login to a vendor portal.

What followed took the rest of the month. Target's chief financial officer, John Mulligan, told the Senate that malware was first placed on a small number of point-of-sale terminals between 15 and 28 November, and that the majority of the estate was infected by 30 November. Card capture began on 27 November — the Wednesday before Thanksgiving, the start of the American retail year. The software was a memory scraper of a commodity kind, reading track data out of the register's RAM in the instant between the swipe and the encryption; a report issued in January 2014 by the Department of Homeland Security, the Secret Service, the FS-ISAC and iSight Partners gave it the name KAPTOXA. The take was collected on a commandeered internal server and moved out by FTP.

The alarms worked. Target had installed a malware detection system from FireEye some six months earlier — Bloomberg Businessweek, reporting the following March, put its cost at $1.6 million — and staffed a team of security specialists in Bangalore to watch its computers around the clock. On Saturday 30 November, as the exfiltration tooling went up, the system raised an alert of the plainest possible kind, "malware.binary", and then raised more, each at the top of its graded scale. Bangalore passed them to the security operations centre in Minneapolis. According to the Businessweek account, nothing then happened. The software's option to delete suspicious code automatically had been left switched off. Target's own Symantec product, the same reporting said, had flagged unusual activity too. Target's answer, when the story ran, was that a small amount of the activity had been logged and surfaced to its team, which evaluated it and "determined that it did not warrant immediate follow up".

So November ended with no announcement, no card reissue and no reason for anyone outside a handful of buildings to think about it. Cards kept going into infected registers until 15 December. The Department of Justice contacted Target on 12 December; Krebs published on 18 December; the company confirmed the following day that about 40 million credit and debit card accounts had been exposed between 27 November and 15 December. On 10 January 2014 it added that names, addresses, telephone numbers or email addresses for up to 70 million more people had gone as well — the revision that gives January 2014 its title. The whole of it had been visible, in an alert queue, on the last Saturday of November.

Also that month · 1–6 November

A payment desk for extortion

CryptoLocker had been encrypting documents since mid-September 2013 behind a seventy-two-hour countdown, and on 1 November its operators added what made it a business rather than a stunt: a service on Tor where a victim who had missed the deadline could upload one encrypted file, find an order number and buy the key back. Lawrence Abrams of BleepingComputer, quoted by Brian Krebs on 6 November, noted that the criminals had styled it as an order, "as if victims posted an order at Amazon.com". The late price was 10 bitcoin — about $2,232 at the rates Krebs quoted that week, against the 2 bitcoin, or roughly $200 by MoneyPak, asked of victims still inside the deadline; on about 25 November, with bitcoin climbing towards $1,000, the crew cut that standing ransom from 2 bitcoin to 0.5 to keep the dollar price where it had been. On 5 November US-CERT issued alert TA13-309A, warning that some victims said they had paid and received no key. Scale came later: Dell SecureWorks' Counter Threat Unit, publishing Keith Jarvis's analysis on 18 December, counted 31,866 unique infected systems calling its sinkhole between 22 October and 1 November, 22,360 of them American, and estimated at least 200,000 to 250,000 infections worldwide in the first hundred days. The network distributing it survived until June 2014.

Also that month · 12–20 November

One password, several doors

On about 12 November the Apple site MacRumors told members its forums had been entered and more than 860,000 account records taken — usernames, email addresses and salted MD5 password hashes. The route in was mundane: a moderator's login, then JavaScript in an announcement to take an administrator's session. Days later vBulletin's own site reset customer passwords, its support lead Wayne Luke saying the attackers had reached "customer IDs and encrypted passwords". A user calling himself Inj3ct0r claimed a zero-day in vBulletin 4.x and 5.x; the company said it knew of no such bug, and the claim went unsubstantiated. Krebs reported the connecting detail on 18 November: that moderator had used identical credentials on both sites. Two days later he disclosed 42 million records from the dating service Cupid Media, passwords in plain text, on the same server as the stolen Adobe data; managing director Andrew Bolton said the activity had been detected in January 2013 and many accounts were old or deleted. Ireland's Data Protection Commissioner had disclosed on 12 November that the marketing firm LoyaltyBuild lost card details for over 376,000 people and contact details for 1.12 million.

India desk · November 2013

The alert went through Bangalore

India sat inside the decade's biggest retail breach, and did its part. The team watching Target's systems around the clock was in Bangalore; when the detection software fired on 30 November 2013 the alert landed there, and there the decision to flag Minneapolis was taken (Bloomberg Businessweek, 13 March 2014). India's own card estate stood differently. The Reserve Bank's circular of 28 February 2013, RBI/2012-13/424, had told banks to issue new cards for domestic use only unless a customer asked otherwise, to convert to EMV chip-and-PIN any card used abroad, and to certify acquiring infrastructure, all by 30 June 2013; a second factor for card-not-present transactions had been directed in February 2009 and compulsory from that August. Track data lifted from an American till was worth less against a card issued in India.

The month's Indian argument, though, was about being watched, not robbed. On 15 November 2013 the investigative sites Cobrapost and Gulail published intercepted telephone recordings which, they said, showed the Gujarat police keeping a young woman architect under surveillance in 2009, following her through shopping centres and restaurants and to the hospital where her mother lay, on instructions the sites attributed to the state's then home minister. The state appointed an inquiry under a retired judge; the party denied wrongdoing; in 2016 the woman herself asked the Supreme Court to stop the investigations. Behind it sat the Central Monitoring System, then being rolled out, and no privacy statute to set against it. Nothing in Indian law that month obliged a bank, a retailer or a website to say records had gone; that came by direction in 2022, in CERT-In's six-hour rule, and by statute in 2023, in the DPDP Act.

AI Tech desk · November 2013

Two papers, eleven days in

The month's real machine-learning news went up on a preprint server rather than a stage. On 11 November 2013 four researchers at the University of California, Berkeley — Ross Girshick, Jeff Donahue, Trevor Darrell and Jitendra Malik — posted a method they called R-CNN, which fed region proposals from an image into a convolutional network pre-trained on ImageNet and then fine-tuned for detection. They reported 53.3 per cent mean average precision on the 2012 PASCAL VOC set, ahead of the previous best by more than thirty per cent in relative terms. A day later Matthew Zeiler and Rob Fergus of New York University posted "Visualizing and Understanding Convolutional Networks", a technique for seeing what a network's intermediate layers respond to; the architecture chosen with its help took that year's ImageNet classification task. Neither was a product and neither was announced. R-CNN became Fast R-CNN in April 2015, Faster R-CNN that June and Mask R-CNN in 2017, and that line sits under most of the object detection built since.

Digital Guard desk · November 2013

The Digital Crimes Unit gets a building

On 14 November 2013 Microsoft opened the Microsoft Cybercrime Center at Redmond — a building rather than a product, and the point was the seating plan. The Digital Crimes Unit, about a hundred people worldwide, put lawyers, investigators, forensic analysts and engineers in one place, on the reasoning that a botnet comes apart only when a court order and a technical seizure land together. It held the unit's own tools, among them PhotoDNA for child exploitation images and SitePrint for mapping criminal networks, and kept secured space for outside industry, academic and police investigators. David Finn, associate general counsel of the unit, described the aim as combining "sophisticated tools and technology with the right skills and new perspectives". Three weeks later it moved against the ZeroAccess click-fraud botnet alongside Europol and the FBI, in December 2013. The method the building was designed around — a software vendor suing botnet operators in civil court to take their domains — is ordinary practice by 2026, and the question of how much policing a software company should do is still open.

⏳ Time capsule — November 2013

  • On 5 November a PSLV-XL lifted off from Sriharikota at 14:38 Indian time carrying ISRO's Mars Orbiter Mission; it reached Martian orbit on 24 September 2014, making India the first Asian nation to get there and, after the European Space Agency, only the second to succeed at the first attempt.
  • Before dawn on 8 November local time, Typhoon Haiyan came ashore at Guiuan in Eastern Samar, the Philippines; the national disaster council's confirmed toll for the country eventually reached 6,300 dead, with more than a thousand never found.
  • From 14 to 16 November Sachin Tendulkar played his two hundredth and last Test match, against the West Indies in Mumbai, making 74 in his final innings.
  • On 27 November bitcoin traded above $1,000 for the first time on Mt. Gox, reaching about $1,030, nine days after a United States Senate hearing on virtual currencies had treated them as something other than a criminal curiosity.
Where it stands today — 2026

What November set moving

Target's chief information officer, Beth Jacob, resigned on 5 March 2014, and its chief executive, Gregg Steinhafel, on 5 May — the first head of a major retailer to go over a security failure, and the reason boards started asking who owned the risk. Target's filings put cumulative breach expenses at $292 million before tax, $202 million net of insurance; in May 2017 it settled with 47 state attorneys general for $18.5 million, then the largest such settlement in the United States. The most visible legacy is on the counter: the American liability shift of 1 October 2015 finally pushed chip readers into shops that had spent a decade calling them unaffordable. The less visible one is the alert queue. Detection was never the problem in November 2013; response was.

The rest of the month aged into ordinary practice. CryptoLocker's payment desk — a hidden service, tiered pricing, a way to pay late — became the template every crew has used since, outliving the network that carried it, taken apart by court order in June 2014, and running on into May 2017. November's password cluster settled the argument about reuse: one moderator's credentials, shared between a forum and its supplier, are still the case taught, and by 2026 the answer is not a better hash but a passkey that cannot be typed into the wrong site. What has changed least is the gap between the day a breach begins and the day anyone is told: in November 2013 it ran to five weeks, and no law required otherwise.