Data Breaches Targeting Retailers Affect Millions of Customers
The arts-and-crafts retailer Michaels announced Thursday that a malware attack may have compromised the data of some 2.6 million customers between last May and January — the latest in a string of major retail data breaches that has kept Congress scrambling for months to figure out what, if anything, it should do about it.
A Breach That Keeps Growing
Michaels’ announcement wasn’t limited to its own stores. The company’s subsidiary, Aaron Brothers, also experienced a malware attack over several months, with the credit card data of an estimated 400,000 additional customers potentially intercepted. Combined, the two breaches make this the largest U.S. retailer data breach since Target’s announcement the previous December first exposed the scale of the problem, when the retail giant revealed hackers had stolen the credit and debit card numbers of millions of shoppers during the height of the holiday shopping season. Target’s breach would eventually grow to encompass some 40 million payment card records and 70 million additional customer records containing names, addresses, and other personal information.
Neiman Marcus, Bloomingdale’s, and other retailers disclosed their own breaches in the weeks that followed, establishing a pattern that consumer advocates found troubling well beyond the sheer number of records compromised. Consumer advocate Holober was particularly critical of the timeline in Neiman Marcus and Bloomingdale’s case: “In the case of Neiman Marcus, Bloomingdale’s and other affiliated stores, it would appear that a breach that occurred early in December, was kept quiet until after the Christmas shopping season was over.” Holober argued the delay in notifying customers “would have been for clear corporate purposes that are, in this case, at odds with the public interest” — suggesting retailers had a direct financial incentive to avoid disclosing a breach during their most profitable shopping weeks of the year, even if that meant leaving customers unaware their financial data may have already been compromised.
Congress Responds, Slowly and From Multiple Directions
The scale of the breaches drew rapid, if scattered, attention on Capitol Hill. Beginning with a Senate Banking subcommittee hearing on February 3, Congress held seven separate hearings across six different committees between early February and early April alone, according to the Congressional Research Service’s tracking of the legislative response. Target’s chief financial officer John Mulligan and Neiman Marcus’s chief information officer Michael Kingston both testified before the Senate Judiciary Committee, with Mulligan telling lawmakers the company was “deeply sorry” for the breach’s impact on customers, even as he acknowledged Target’s own confidence with consumers had been badly shaken.
That flurry of hearings has yet to translate into a single, unified federal response. Several competing bills currently sit before Congress, each proposing its own approach to establishing federal data breach notification standards and security protocols — reflecting genuine disagreement not just between industry and consumer advocates, but among lawmakers themselves about how prescriptive any new federal standard should be. Federal Trade Commission Chairwoman Edith Ramirez has pushed for one of the more consequential proposals under consideration: expanding the FTC’s own regulatory and enforcement authority over data security specifically, rather than relying solely on notification requirements after a breach has already occurred.
Industry Points the Finger at Outdated Card Technology
Retail industry representatives have pushed back against the implication that retailers alone bear responsibility for the wave of breaches. Steve Schatz of the National Retail Federation argued the industry already spends billions of dollars annually fighting cybercrime, and that the more fundamental vulnerability lies in the payment card technology itself. “Private financial information is located on the magnetic strip of your card,” Schatz said. “Criminals know that they can get all the information they need by simply swiping that magnetic strip and basically monetizing your account.” Schatz called for the U.S. to adopt chip-and-PIN card technology already standard across the European Union, Canada, and other countries — a shift he argued would render the kind of magnetic-strip data theft behind the Target and Michaels breaches largely obsolete.
A Debate That Would Outlast This Particular Wave of Breaches
The tension between Schatz’s technology-focused argument and Holober’s call for stronger notification accountability captures a divide that would continue shaping data breach policy debates for years after this particular wave of retail hacks faded from headlines. The U.S. payment card industry would go on to begin a broader, if slow, transition toward chip-enabled cards in the years following these hearings — but the federal notification standard that Congress’s seven hearings seemed poised to produce back in early 2014 remained, even years later, a patchwork of state-level requirements rather than the single national law lawmakers on both sides of the aisle had spent the spring publicly calling for.
For related coverage of consumer protection and corporate accountability, see our piece on California’s SB 588 wage theft enforcement law, or browse our full Policy & Rights archive.
