Target's own CFO told the Senate the government warned the company first. So the story of the retailer that came clean fast has a problem: it never came clean first.

Pairs with the Crisis Response Playbook — a ready-to-use strategy tool. Included in the Crisis Response Casebook →

The retail world found out that Target had been hacked from a one-man security blog. On December 18, 2013, Brian Krebs posted that Target was investigating a breach potentially involving millions of card records.1 Target had said nothing. It scrambled a statement out the next morning, December 19, confirming that hackers had reached as many as 40 million credit and debit card accounts from shoppers between late November and mid-December, complete with card numbers, expiration dates, and the security codes on the back.2 The company that is now taught as a model of fast crisis disclosure did not go first. It went second — a day behind a blogger, and, as its own sworn testimony would later show, about a week behind the U.S. government.

The tidy version says Target got hacked, told everyone quickly, and paid a fair price for a mistake. Almost every beat of that is off. Target didn't discover the breach on its own. It didn't announce it on its own timing. And the CEO who lost his job seventeen months later didn't lose it for slow notification. He lost it for everything that happened after the notification.

The government called first, and the blogger called second: the 'fast disclosure' story leaves out who actually rang the alarm, and when

Target's own CFO laid out the real sequence under oath. In February 2014 testimony to the Senate Judiciary Committee, John Mulligan said the Department of Justice notified Target of suspicious card activity on the evening of December 12, 2013. Target met with the DOJ and Secret Service on the 13th, hired outside forensic experts on the 14th, and confirmed malware on its point-of-sale network on the 15th — pulling it from virtually all U.S. registers that same day. Only after quietly notifying processors and card networks did it go public on December 19.3 Read that timeline the way the market did and the flattering label falls away. The breach wasn't detected by Target; it was reported to Target. The public statement came not on a schedule of the company's choosing but on the morning after it was scooped. This isn't a story of a company running toward the fire. It's a company that got there because two alarms outside the building went off first.

The Department of Justice notified Target of suspicious activity involving payment cards used at Target stores... on the evening of December 12.3
John MulliganCFO of Target, in sworn testimony to the Senate Judiciary Committee, February 2014

Why the CEO fell in May, not December: a breach you announce fast is survivable; a recovery that keeps getting worse is not

If disclosure speed were the crime, Gregg Steinhafel would have been gone by January. He wasn't. He resigned as president, CEO, and director effective May 5, 2014 — five full months after the December statement.5 The gap is the whole point. A breach disclosed in December is an event. What killed the CEO was the slow-motion aftermath: the story got bigger, not smaller, the longer it ran. On January 10, 2014, Target had to make a second, separate disclosure — that personal information for up to 70 million customers had also been stolen in the same intrusion.4 For the customer watching, the sequence read as a company that kept discovering how bad it was in public installments. That is the poison in crisis response: not the first bad number, but the second one, because the second one means you didn't understand the first.

Dec 12, 2013
The DOJ makes the call3
The Department of Justice notifies Target of suspicious payment-card activity — the breach is reported to the company, not found by it.
Dec 15, 2013
Malware confirmed and removed3
Target confirms malware on its point-of-sale network and pulls it from nearly all U.S. registers that day.
Dec 18, 2013
Krebs breaks the story1
A security blogger reports Target is investigating a breach — before the company says anything public.
Dec 19, 2013
Target confirms 40 million cards2
The company's public statement lands the morning after the leak, covering up to 40 million card accounts.
Jan 10, 2014
The second, bigger number4
Target discloses personal data for up to 70 million customers was also stolen — the crisis grows instead of closing.
May 5, 2014
The CEO steps down5
Steinhafel resigns as CEO and director, five months after disclosure — long after any 'slow notification' argument.

The exit itself is the third thing the popular account gets wrong. Steinhafel is usually described as fired. Target's own Form 8-K/A tells a more negotiated story: he stepped down and resigned from the board effective May 5, and on May 14 the board approved severance under the company's existing Income Continuance Policy, conditioned on a non-solicitation agreement and a release of claims.5 That is not a summary termination; it's a managed departure. But the market read it as historic anyway — reporting at the time noted experts calling it the first time the chief executive of a major corporation had resigned in the wake of a data breach, an incident described as having hurt Target's reputation with customers and hammered its business.6 Whether the paperwork said 'fired' or 'agreed to step down,' the signal was the same: the board needed a body, and only the top one would do.

5 months
between Target's December disclosure and the CEO's May resignation — the gap that proves he fell for the slow recovery, not the fast announcement5

The bill nobody adds up correctly: the famous $18.5 million figure is the smallest of several, and it arrived years after the CEO was gone

The number people cite as 'the cost of the Target breach' is $18.5 million — the multistate attorney-general settlement with 47 states and the District of Columbia, reached in May 2017 and, at the time, the largest such settlement on record.7 It's the wrong number to anchor on, in two directions. It's too small: by Target's own Form 10-K, cumulative gross breach expenses hit $292 million by the end of fiscal 2016, offset by roughly $90 million in insurance for net cumulative costs near $202 million — before the AG settlement is even added.8 And it's too late: the settlement landed three years after Steinhafel had already left. The financial reckoning trailed the reputational one by years. The board didn't wait for the invoice. It acted on the trajectory.

The breach, by the numbers
40M
Card accounts exposed (Dec 2013 disclosure)2
70M
Customers with personal data stolen (Jan 2014)4
$292M
Cumulative gross breach expenses through FY20168
$18.5M
Multistate AG settlement, May 20177

Wasn't Target actually competent here?: the fair objection is that the company moved fast on the technical fix, and it did

The honest counter is that Target's operational response was genuinely quick. From the DOJ tip on December 12 to malware confirmed and scrubbed from nearly every U.S. register, only three days passed.3 Most breached companies would envy that reflex. And on disclosure timing, being a day behind a blogger who was clearly about to publish is not the same as covering things up for months. So the technical crisis was handled with real speed. But that's exactly why the episode is instructive: competence on the mechanics didn't save the CEO, because the thing customers judged was never the forensics. It was the story — and the story kept getting worse in public, from 40 million to 70 million, from a card problem to a personal-data problem. You can win the containment and still lose the narrative, and the narrative is what the board was ultimately forced to answer for. A fast fix inside a slow, compounding disclosure reads to the outside world as a company that doesn't know its own damage.

The second number decides your fate, not the first

In a crisis, the market forgives the initial bad news — a breach, a recall, a miss — far more readily than it forgives the revision. A first disclosure says 'something went wrong.' A second, larger disclosure a few weeks later says 'we didn't understand the first one,' and that is the sentence that ends careers. The strategic move is not to announce fast; it's to announce once. Overscope the initial disclosure, count the full damage before you speak, and accept a rougher first headline to avoid a worse second one. Target announced early and still bled for five months, because it announced in installments. If you can't yet size the damage, say that plainly — but never let the number climb in public. The trajectory is the story, and a rising trajectory is the one thing no crisis team can spin.

Target's breach is remembered as the case where a company came clean and paid for it. The record is stranger and more useful than that. It was told about the breach by the government, scooped on it by a blogger, and forced into a disclosure that grew larger the longer anyone looked. The CEO didn't fall because Target was slow to speak. He fell because, five months on, the company was still explaining a wound it hadn't finished measuring. Speed was never the currency. Certainty was — and Target ran out of it in public, one revised number at a time.

Take it with you — Crisis Response
Playbook

Crisis Response Playbook

A playbook for a crisis already in motion: who decides, which plays fire on which trigger, and what gets said to whom. It replaces panic and the all-hands meeting with a pre-agreed sequence each person can run alone. Blank to pre-load before a crisis hits; filled as the worked example reconstructing the plays the story's team ran — and the ones they should have.

Blank template

Included, filled and blank, in the Crisis Response Casebook. See the set → · Preview the blank →

Sources

Where this comes from — the filings, records, and reporting behind it.

  1. 1
    Primary · ArchivalDocumented
    Brian Krebs of KrebsOnSecurity first reported on December 18, 2013 that Target was investigating a data breach potentially involving millions of customer credit and debit card records, before Target itself said anything publicly.
  2. 2
    PublishedWidely reported
    Target confirmed on December 19, 2013 that hackers had accessed as many as 40 million credit and debit card accounts of customers who shopped in its U.S. stores between November 27 and December 15, 2013, with stolen data including names, card numbers, expiration dates and security codes.
  3. 3
    Primary · Company recordDocumented
    Target's own account, given in sworn Senate Judiciary Committee testimony by CFO John Mulligan, establishes the internal timeline: DOJ notified Target of suspicious card activity on the evening of December 12, 2013; Target met with DOJ and the Secret Service on December 13; hired outside forensic experts on December 14; confirmed on December 15 that malware had been installed on its point-of-sale network and removed it from virtually all U.S. registers that day; and over the following days notified payment processors and card networks before the December 19 public disclosure.
  4. 4
    PublishedWidely reported
    On January 10, 2014, Target announced that personal information — including names, addresses, phone numbers, and email addresses — of up to 70 million customers had also been stolen in the same breach, a disclosure separate from and in addition to the 40-million-card figure announced in December.
  5. 5
    Primary · SEC filingDocumented
    Target's Form 8-K/A confirms that Gregg W. Steinhafel stepped down as President and CEO and resigned as a director effective May 5, 2014, and that on May 14, 2014 the board approved his severance under the company's Income Continuance Policy, conditioned on a non-solicitation agreement and release of claims.
  6. 6
    PublishedAttributed to source
    Reporting on Steinhafel's May 5, 2014 resignation noted that experts said his departure marked the first time the CEO of a major corporation had resigned in the wake of a data breach, underscoring how the incident, not a single misstep, was described as having 'hurt its reputation among customers and hammered its business.'
  7. 7
    Primary · Court recordDocumented
    On May 23, 2017, Target agreed to pay $18.5 million to settle a multistate investigation by 47 states and the District of Columbia into the 2013 data breach — the largest multistate data breach settlement reached to that date — in addition to requirements to build a comprehensive information security program.
  8. 8
    PublishedWidely reported
    According to Target's own Form 10-K, by the end of fiscal 2016 the company had incurred $292 million in cumulative gross expenses related to the data breach, which after $90 million in insurance recoveries left net cumulative expenses of about $202 million from 2013-2016 — a total pushed past $220 million once the $18.5 million multistate settlement is added, separate from a pending multi-district consumer class action.

More like this — beyond Target

New Strategically analyses as they publish: the defining moves in business, checked against the record. No noise, and one click to leave.