Target Says Hackers Stole Encrypted PIN Numbers

Latest Videos FromTom's Hardware
TOPICS
Kevin Parrish
Contributor

Kevin Parrish has over a decade of experience as a writer, editor, and product tester. His work focused on computer hardware, networking equipment, smartphones, tablets, gaming consoles, and other internet-connected devices. His work has appeared in Tom's Hardware, Tom's Guide, Maximum PC, Digital Trends, Android Authority, How-To Geek, Lifewire, and others.

  • dextermat
    Epic facepalm... Target just got in Sherbrooke(canada) and nothing on the shelves, with a big mistake like that, they should stay in the US!
    Reply
  • COLGeek
    To quote the great Homer (Simpson)...."Doh!!!"
    Reply
  • jacobdrj
    PIN numbers and ATM machines in the same article... Shame on toms hardware editors...
    Reply
  • osamabinrobot
    next week when we find out whoever pulled this also got into their payment processor shits really gonna hit the fan huh
    Reply
  • rantoc
    Another day, another cloud disaster.... gotta love the logic to collect all the eggs in one spot...
    Reply
  • Rhinofart
    @Jacobdrj
    Why is it shame on Tom's Hardware editors? You do know that the PIN you use at the till is the same one you use at the ATM right?
    Reply
  • ddpruitt
    PIN numbers and ATM machines in the same article... Shame on toms hardware editors...

    And yet another moron. The PIN can be used to easily take money out of an ATM. There is more than video on youtube of someone using something as innocuous as a prepaid phone card to program as a debit card to withdraw money from an ATM. With the PIN number it wouldn't take long to clean out an account.

    Now for those who don't know STORING the PIN numbers is a major PCI compliance violation, for the very obvious reasons here. No merchant is ever allowed to store the PIN number or the CVV/CVN number on the back of your card. If the Payment Processing Industry is serious about security they'll ban Target from accepting their debit/credit cards. I'm interested to see what happens here.
    Reply
  • techguy911
    This article is WRONG they got the pin numbers unencrypted it was posted on targets website seems the malware was in the card terminal and prob keylogged the pin pad as well as get stripe info.
    http://money.cnn.com/2013/12/27/technology/target-pin/index.html?hpt=hp_c2
    Reply
  • techguy911
    I don't think Target was storing the pin numbers for what i have read the malware reads memory locations in the POS and possibly the pin pad.

    http://storefrontbacktalk.com/securityfraud/thousands-of-cards-compromised-at-retailers%E2%80%99-pos/
    Reply
  • rogue3542
    Rhinofart and ddpruitt,

    PIN is an acronym for "personal identification number;" likewise, ATM is an acronym for "automated teller machine." Thus, when the author writes "PIN number," it actually means personal identification number number, and "ATM machine" is automated teller machine machine. Perhaps you should leave the hyperbole and epithets by the wayside.
    Reply