Target logoClosed to new claimsData breach

Target Data Breach Settlement: What It Paid and Where It Stands

Last updated: July 25, 2026

The Target data breach settlement is closed and fully paid out — there is nothing left to claim. Target Corporation, the national retail chain, established a $10 million fund for shoppers affected by its 2013 holiday-season breach. Claimants who documented real losses were reimbursed up to $10,000 each, and everyone else who filed split the remainder, which worked out to roughly $40 per person. The claim deadline was July 31, 2015, and by 2021 the fund had been distributed to claimants or turned over to state unclaimed-property offices.

The breach itself remains one of the largest in U.S. retail history. Between late November and mid-December 2013, attackers who entered through a third-party vendor's credentials installed malware on Target's point-of-sale systems and stole payment-card data for about 40 million credit and debit cards, along with names, addresses, phone numbers, and email addresses for up to 110 million customers.

The consumer case was In re: Target Corporation Customer Data Security Breach Litigation, MDL No. 2522 (No. 0:14-md-02522) in the U.S. District Court for the District of Minnesota, before Senior Judge Paul A. Magnuson. He granted final approval on November 17, 2015. Objectors then appealed: the Eighth Circuit reversed class certification on February 1, 2017 and sent the case back, the district court re-certified the class, and the Eighth Circuit affirmed on June 13, 2018 — finding no conflict between class members who could document losses and those who could not. The litigation is now closed with prejudice.

Key facts

Consumer fund
$10 million
Payout with documented losses
Up to $10,000 per person
Payout without documentation
~$40 (equal share of the remainder)
Claim deadline
Closed July 31, 2015
People affected
Up to 110 million; ~40 million payment cards
Breach period
2013 holiday shopping season
Case
In re Target Corp. Customer Data Security Breach Litig., MDL 2522 (D. Minn.)
Judge
Sr. Judge Paul A. Magnuson
Final approval
November 17, 2015; affirmed on appeal June 13, 2018
Current status
Fund distributed; case closed with prejudice

Official settlement administrator: U.S. District Court, District of Minnesota — MDL 2522

Who qualifies

  • The class covered U.S. consumers whose credit or debit card information, or whose personal information such as name, address, phone number, or email address, was compromised in Target's 2013 data breach.
  • Claimants with documentation — unreimbursed fraudulent charges, bank fees, credit-monitoring costs, replacement card fees, lost time, or costs from identity theft traced to the breach — could recover up to $10,000 each.
  • Claimants without documentation received an equal share of whatever remained after documented claims, attorneys' fees, and administration costs were paid. That worked out to roughly $40 per person.
  • Only claims filed by the July 31, 2015 deadline were eligible. No late claims were accepted and the window was never reopened.
  • Shoppers who were not customers during the 2013 breach window, and later Target customers, were never covered by this settlement.

Target settlement status — what happened to the money

  1. 1

    The fund is distributed and the case is closed

    Payments went to claimants after the Eighth Circuit affirmed the settlement on June 13, 2018. By 2021 the $10 million consumer fund had been fully distributed or escheated — turned over to state unclaimed-property offices for checks that were never cashed — and the multidistrict litigation was closed with prejudice.

  2. 2

    Why documented claims got so much more

    The settlement paid proven losses first, up to $10,000 per person, then divided what was left equally among everyone else who filed. Relatively few people could document breach-related losses, so those claims were paid in full while the much larger group of undocumented claimants received roughly $40 apiece.

  3. 3

    There is no late claim to file

    The July 31, 2015 deadline passed more than a decade ago and the fund no longer exists. Any website inviting you to file a Target data breach claim today is not an official settlement site. Never enter your Social Security number or card details to "claim" it.

  4. 4

    If you think a 2015 check was never cashed

    Uncashed settlement checks are escheated to the state where the claimant last lived. If you filed a claim in 2015 and believe you never received payment, search your state's unclaimed-property database — that is where the money would now sit, not with Target or the administrator.

  5. 5

    The other Target settlements paid institutions, not shoppers

    Target also paid $18.5 million in May 2017 to settle with 47 state attorneys general and the District of Columbia — the largest multistate breach settlement at the time — plus separate deals with banks, credit unions, and card networks to cover reissuing cards. All of that money went to governments and financial institutions. Only the $10 million consumer fund paid individual shoppers.

  6. 6

    Breach settlements now pay far more — if you file

    Later breach settlements have paid substantially better than $40. ClaimBee scans your email for the breach-notification letters companies send, matches them to open settlements, and reminds you before the deadline, so a $40 residual is not the best you can do next time.

Missed this one? Don't miss the next.

ClaimBee matches your profile against 2,000+ active settlements, shows payout and proof requirements up front, and tracks every deadline for you.

Check your matches

Frequently asked questions

Can I still file a Target data breach claim?

No. The claim deadline was July 31, 2015, the $10 million consumer fund has been fully distributed or escheated to state unclaimed-property offices, and the case is closed with prejudice. There is no active Target breach claim, and any site offering one is not legitimate.

How much did people get from the Target settlement?

Claimants who documented losses from the breach were reimbursed up to $10,000 each. Everyone else who filed split the remainder of the $10 million fund equally, which came to roughly $40 per person.

How many people were affected by the Target data breach?

Payment-card data for about 40 million credit and debit cards was stolen, and personal information such as names, addresses, phone numbers, and email addresses was exposed for up to 110 million customers. It remains one of the largest retail breaches in U.S. history.

When did the Target data breach happen?

During the 2013 holiday shopping season, roughly from late November to mid-December 2013. Attackers used a third-party vendor's stolen credentials to reach Target's network and installed malware on its in-store point-of-sale systems to capture card data as customers checked out.

Why did the Target settlement take so long to pay?

Judge Magnuson granted final approval on November 17, 2015, but objectors appealed. The Eighth Circuit reversed class certification on February 1, 2017 and remanded the case; the district court re-certified the class; and the Eighth Circuit affirmed on June 13, 2018. Payments could only go out after that, nearly three years after approval.

What was the $18.5 million Target settlement?

That was a separate May 2017 settlement with 47 state attorneys general and the District of Columbia — the largest multistate data breach settlement at the time. That money went to state governments, not to shoppers. Only the $10 million consumer class action fund paid individuals.

I filed a Target claim in 2015 but never got a check. Where is it?

Uncashed settlement checks are escheated to the state where you last lived, so the money would now be held by that state's unclaimed-property office rather than by Target or the settlement administrator. Search your state's unclaimed-property database by name to check.

Is my information from the Target breach still at risk?

The payment cards exposed in 2013 were reissued long ago, so those card numbers are no longer usable. The personal details that were exposed — name, address, phone number, email — do not expire, so they can still surface in phishing attempts and in data sold from other breaches. Freezing your credit remains the strongest free protection.

Related settlements

More settlements people are checking

Payout status for other settlements we track, updated as administrators publish new information.