MisusePrivilege AbuseCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Target Corporation
bd_a9fe26c3d0802016 · schema v1 · pii pii-v1
Full breach record for Target Corporation →Target notified the New Hampshire Attorney General on January 22, 2008, regarding an insider threat incident involving three call center employees who accessed Target Visa account information and placed fraudulent charges. Approximately 3 New Hampshire residents were affected. Data compromised included names, addresses, account numbers, SSNs, and phone numbers. Target terminated the employees, renumbered affected accounts, removed fraudulent charges, and provided one year of credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed3 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/target-20080122.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 22, 2008
- Raw hash
- 93ab339e2b8dcc6f6aa1b3aaea430aba358dc49c86124afe75f02617687adc50
Reporting entity
- Name
- Target Corporationnorm: target
Victim entity
- Name
- Target Corporationnorm: target
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jan 23, 2008
- Affected individuals
- 3
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Regulator citations
- Filed notification with New Hampshire Office of the Attorney General pursuant to New Hampshire Rev. Stat. § 359-C:20
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.