Essay Undergraduate 1,182 words

Target Data Breach: Internal Controls and Information Security

~6 min read
Abstract

This paper examines the December 2012 Target data breach that exposed 40 million customer payment card details and 70 million personal records. The analysis focuses on how internal control failures—particularly the delayed response to detected malware—enabled the theft. The paper explores the technical aspects of the BlackPOS malware attack, considers the social and criminological motivations behind cybercrime, and proposes comprehensive data protection policies that address detection, response protocols, and employee accountability. The discussion extends to credit management and receivables, emphasizing the need for integrated corporate policies that protect sensitive customer information throughout its lifecycle.

📝 How to Write This Type of Paper Writing guide — click to expand

What makes this paper effective

  • Uses a concrete, well-documented case study (Target breach) to ground abstract concepts about internal controls and information security
  • Distinguishes between detection and response failures, showing that technology investment alone is insufficient without operational protocols
  • Integrates cybersecurity with traditional accounting topics (receivables, credit assessment) to show holistic risk management
  • Addresses root causes of cybercrime from multiple angles—technical, social, and motivational—rather than treating it as purely technical

Key academic technique demonstrated

This paper employs case-study analysis paired with policy synthesis. It uses the Target breach as an exemplar to extract lessons about failed internal controls, then broadens the discussion to propose generalizable frameworks (data protection policies, response protocols, credit assessment procedures). This approach moves from specific evidence to applicable best practices, which is typical of accounting and business policy writing.

Structure breakdown

The paper is organized in two main movements. Part 1 presents the Target case, dissecting the malware attack and internal response failure, then pivots to credit and receivables fundamentals. Part 2 shifts focus to the criminological and social context of hacking, then concludes with prescriptive policies for data protection and employee accountability. This structure—concrete problem, theoretical context, generalized solution—mirrors applied accounting scholarship.

The Target Data Breach and Detection Failures

On December 19th, Target publicly acknowledged that it had suffered a data breach resulting in the loss of 40 million customer payment card details, along with their names, expiry dates, and encrypted security codes (Munson, 2013). At the time, this was one of the largest security breaches in retail history. The firm suffered not only from being targeted by criminals but also from the failure of its internal controls to respond effectively to a detected threat.

The problem began in the run-up to Thanksgiving, when malware was installed on Target's payment system. The malware—detected by Target's own security specialists on November 30th, 2012—represented an active threat that had already begun compromising customer data. Despite investing $1.6 million in malware detection software from security specialist FireEye (an organization that also serves the CIA), Target had a critical vulnerability: not in detection, but in response. When the breach was discovered, Target failed to take immediate action or escalate the threat appropriately (Krebs, 2014; Riley, 2013). This delay allowed hackers to continue extracting payment card information for weeks after the initial alarm was raised.

The failure resulted in severe consequences. Target suffered a 46 percent drop in profit in the last quarter of 2012, and the costs to the community and banks associated with stopping and reissuing cards are estimated at approximately $200 million (Krebs, 2014). The breach demonstrated that internal controls require more than technology investment; they demand clear protocols, defined responsibilities, and swift action when threats are detected.

To overcome such failures, organizations must establish detection systems alongside a strict protocol defining what actions should be taken, by whom, and within what time scales when a security breach occurs. This includes specific responsibilities, escalation procedures, and accountability mechanisms.

Understanding the BlackPOS Malware Attack

BlackPOS, also known as Kaptoxa, is malware specifically designed for point-of-sale systems operating on Microsoft Windows. The malware's operation is straightforward but devastating: when a customer's card is swiped on an infected point-of-sale terminal, the malware activates and captures the card details, sending them to a server within Target's network that had been commandeered by the criminals (Riley, 2014).

Once the payment card data is gathered on the compromised server, hackers must upload exfiltration malware to extract the details for their own use. The data extraction process involves multiple intermediary steps designed to obscure the hackers' digital footprints. The stolen information is sent first to staging points—temporary servers used to disguise the trail of the breach—before being forwarded to its final destination in Russia (Riley, 2013).

This multi-stage approach reflects a sophisticated attack chain. Rather than extracting data directly to their own servers, the attackers used intermediate locations to create distance between the theft location and their operational base, making forensic investigation and attribution more difficult. The use of encryption and multiple data hops is standard practice in advanced cybercriminal operations, demonstrating the level of technical sophistication involved in large-scale breaches.

Credit Risk Assessment and Receivables Management

When firms consider extending credit to customers, they evaluate multiple factors. The first consideration is the firm's own internal position and resources—whether the organization has sufficient capital and operational capacity to support extended credit. When credit is extended, it increases accounts receivable outstanding and ties up significant capital in working capital and inventory. Firms must also account for the potential for bad debts (Howells & Bain, 2007). To manage cash flow, firms may use factoring services or develop other internal resources, including staff and systems, to manage credit operations effectively.

Assessing potential customers is equally critical. Firms prefer to grant credit only to those they believe will repay their debts. Risk assessment of customers typically includes evaluating their overall income (or profit if they are a business) to ensure sufficient funds flow to meet debt obligations (Howells & Bain, 2007). The ability to pay must be accompanied by the willingness to pay; therefore, payment history is invaluable. A customer's previous default behavior is often predictive of future defaults.

Creditworthy customers demonstrate both the ability and willingness to repay. Those with a history of timely payments, stable income, and positive payment history are more likely to receive credit than those whose ability or willingness to pay is questionable. This two-dimensional assessment—capacity plus character—remains fundamental to sound receivables management.

2 Locked Sections · 590 words remaining
58% of this paper shown

Motivations Behind Cybercrime · 305 words

"Social and economic factors driving cybercriminal behavior"

Building Effective Data Protection Policies · 285 words

"Comprehensive corporate frameworks for securing customer information"

Sign Up Now — Instant AccessAlready a member? Log in
130,000+ paper examplesAI writing assistantCitation generatorCancel anytime
Key Concepts in This Paper
Internal Controls Data Breach Response BlackPOS Malware Incident Detection Credit Risk Assessment Accounts Receivable Cybercrime Motivation Information Protection Corporate Policy Encryption and Access Control
Cite This Paper
PaperDue. (2026). Target Data Breach: Internal Controls and Information Security. PaperDue. https://www.paperdue.com/study-guide/target-data-breach-internal-controls-195864

Always verify citation format against your institution’s current style guide requirements.