← Target

2020–2022 Account Takeover (ATO) waves

2020 5.0K records affected Share on X

Data compromised

Credentials, Payment information

Technical writeup

Credential stuffing attacks using automated bots. Attackers used credentials leaked from other platforms to gain access to Target.com accounts. While not a breach of Target's core database, it resulted in unauthorized access to saved payment methods and Target Circle rewards.

Root cause

Credential stuffing; attackers used credentials from other breaches to access Target.com accounts.

References