Target (TGT) Says Encrypted PIN Data Stolen But Safe

December 27, 2013 12:27 PM EST
Following up on its massive 40 million credit card and debt card breach, Target (NYSE: TGT) said Friday that while encrypted data was obtained in the heist, additional forensics work confirmed that strongly encrypted PIN data was removed.

The company remains confident that PIN numbers are safe and secure, saying the PIN data was fully encrypted at the keypad, remained encrypted within the system, and remained encrypted when it was removed from the systems.

Target explains that when a guest uses a debit card in their stores and enters a PIN, the PIN is encrypted at the keypad with what is known as Triple DES. Triple DES encryption is a highly secure encryption standard used broadly throughout the U.S.

"Target does not have access to nor does it store the encryption key within our system," the company said. "The PIN information is encrypted within Target’s systems and can only be decrypted when it is received by our external, independent payment processor. What this means is that the “key” necessary to decrypt that data has never existed within Target’s system and could not have been taken during this incident."

"The most important thing for our guests to know is that their debit card accounts have not been compromised due to the encrypted PIN numbers being taken," it was added.


Serious News for Serious Traders! Try StreetInsider.com Premium Free!

You May Also Be Interested In





Related Categories

Corporate News, Insiders' Blog