NEW YORK (CBSDC/AP) — Target’s December security breach was significantly more extensive and affected millions more shoppers than the company reported last month.
The nation’s second largest discounter said Friday that personal information — including names, phone numbers as well as email and mailing addresses — was stolen from as many as 70 million customers as part of a pre-Christmas data breach.
Target Corp. announced in December that about 40 million credit and debit cards may have been affected by a data breach that happened between Nov. 27 and Dec. 15 — just as the holiday shopping season was getting into gear.
According to the company’s investigation, criminals also took non-credit card related data for some 70 million shoppers who could have made purchases at Target stores outside the late Nov. to mid-Dec. timeframe. Some overlap exists between the two data sets, the company said Friday.
“I know that it is frustrating for our guests to learn that this information was taken and we are truly sorry they are having to endure this,” said Gregg Steinhafel, Target chairman, president and CEO, in a statement.
The chain also indicated that holiday sales were hurt by the breach. Target cut its forecast for fourth-quarter earnings, a key sales barometer.
Target’s stock slipped just 67 cents, or 1 percent, to $62.67 in morning trading Friday.
The theft from Target’s databases is still the second largest data breach on record, rivaling an incident uncovered in 2007 that saw more than 90 million credit card accounts pilfered from TJX Cos. Inc.
Target said in December that customers’ names, credit and debit card numbers, card expiration dates, debit-card PINs and the embedded code on the magnetic strip on the back of cards had been stolen.
The company said late last month that it has been working with the Secret Service and the Department of Justice on an investigation into the breach, and customers won’t be liable for the cost of any fraudulent charges that stemmed from the breach.
Target said it will try to contact customers it has email addresses for to provide tips on how to safeguard against consumer scams. The company won’t ask customers for any personal information during its email communications.