2020–2022 Account Takeover (ATO) waves
Data compromised
Credentials, Payment information
Technical writeup
Credential stuffing attacks using automated bots. Attackers used credentials leaked from other platforms to gain access to Target.com accounts. While not a breach of Target's core database, it resulted in unauthorized access to saved payment methods and Target Circle rewards.
Root cause
Credential stuffing; attackers used credentials from other breaches to access Target.com accounts.