|
Data Breach
|9 Months Ended
Oct. 31, 2015
|Commitments and Contingencies Disclosure [Abstract]
|Data Breach
|
Data Breach
In the fourth quarter of 2013, we experienced a data breach in which an intruder stole certain payment card and other guest information from our network (the Data Breach). Based on our investigation, we believe that the intruder installed malware on our point-of-sale system in our U.S. stores and stole payment card data from up to approximately 40 million credit and debit card accounts of guests who shopped at our U.S. stores between November 27 and December 17, 2013. In addition, the intruder stole certain guest information, including names, mailing addresses, phone numbers or email addresses, for up to 70 million individuals.
Data Breach Related Accruals
Each of the four major payment card networks made a written claim against us regarding the Data Breach, either directly or through our acquiring banks. During the third quarter we entered into settlement agreements with two of the four payment card networks. We have resolved a claim from a third network and expect to resolve the remaining claim in the fourth quarter, both on terms consistent with our accrual.
As previously reported, we entered into a Settlement Agreement to resolve and dismiss the claims asserted on behalf of a class of guests whose information was compromised in the Data Breach. Pursuant to the Settlement Agreement, Target has agreed to pay $10 million to class member guests, certain administrative costs associated with the settlement, and attorneys’ fees and expenses to class counsel as the Court may award. That settlement received Court approval on November 17, 2015.
Actions related to the Data Breach that remain pending are: (1) a class action brought on behalf of financial institutions; (2)
one action previously filed in Canada; (3) several putative class action suits brought on behalf of shareholders; and (4) ongoing investigations by State Attorneys General and the Federal Trade Commission.
Our accrual for estimated probable losses is based on actual settlements reached to date, discussions with the remaining two payment card networks and the expectation of negotiated settlements in the pending actions.We have not based our accrual on any determination that it is probable we would be found liable for the losses we have accrued were these claims to be litigated. While our estimates may change as new information becomes available, we do not believe any adjustments will be material.
Expenses Incurred and Amounts Accrued
(a) Includes expenditures and accruals for Data Breach-related costs and expected insurance recoveries as described below.
We recorded $26 million and $38 million of pretax Data Breach-related expenses during the three and nine months ended October 31, 2015, respectively. Along with legal and other professional services, expenses include an adjustment to the accrual in the third quarter of 2015 based on refined estimates of our probable exposure. We recorded $12 million of pretax Data Breach-related expenses during the three months ended November 1, 2014. We recorded $186 million of pretax Data Breach-related expenses, partially offset by expected insurance proceeds of $46 million, for net expenses of $140 million during the nine months ended November 1, 2014. These expenses were included in our Consolidated Statements of Operations as SG&A, but were not part of our segment results.
Since the Data Breach, we have incurred $290 million of cumulative expenses, partially offset by expected insurance recoveries of $90 million, for net cumulative expenses of $200 million.
Insurance Coverage
To limit our exposure to losses relating to Data Breach and other claims, we maintained $100 million of network-security insurance coverage during the period that the Data Breach occurred, above a $10 million deductible and with a $50 million sublimit for settlements with the payment card networks. This coverage, and certain other customary business-insurance coverage, has reduced our exposure related to the Data Breach. We will pursue recoveries to the maximum extent available under the policies. Since the Data Breach, we have received $35 million from our network-security insurance carriers of the $90 million accrued.
|X
- References
+ Details
No definition available.
|X
- Definition
+ References
The entire disclosure for commitments and contingencies.
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef