Skip to contentSkip to content
Knowledge Hub

8 Devastating PCI Data Breaches

Learn from real payment card data breaches — root cause analysis, PCI requirement mapping, timelines, and lessons that could save your organisation.

0M+
Records Compromised
$0B+
Total Fines & Settlements
0
Case Studies

Learn from these breaches — train your team

GRCTrack includes 10 PCI training courses with real breach case studies. Help your team understand how requirement failures lead to data breaches — and how to prevent them.

Start training with GRCTrack

Frequently Asked Questions

What are the biggest PCI data breaches?
Major PCI breaches include Target (2013, 40M cards, $18.5M fine), Home Depot (2014, 56M cards, $17.5M), Equifax (2017, 147M records, $425M), British Airways (2018, 500K customers, £20M fine), and Marriott (2018, 500M records, £18.4M).
What causes PCI DSS breaches?
Common root causes include inadequate network segmentation, unpatched vulnerabilities, weak access controls, lack of monitoring and logging, social engineering attacks, and failure to encrypt stored cardholder data. Most breaches exploit multiple compliance failures.
What are the penalties for PCI non-compliance?
Penalties include fines of $5,000 to $100,000 per month from payment brands, increased transaction fees, mandatory forensic investigations ($50K-$500K), liability for fraudulent charges, and potential loss of the ability to process card payments.