In the Heartland data breach, the custom malware that hackers wrote copied the mag stripe as it passed through the payment system. I got a new credit card after that broke (also after Target's breach was reported). Heartland did not store the card details at all.
How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).
Heartland - #19, Target - #20 at:
https://www.upguard.com/blog/biggest-data-breaches-us
You may notice that the poster of the comment you are responding to is mentioned a lot on that page.