Ideally it’s not even stored…
How it was discovered was some dumb luck when an auditor asked what seems like a dumb question. When you type dir or ls at a command prompt, it says something like "X files using Y bytes, Z bytes free". How do you know those numbers are true/correct? It turns out that the malware changed how the OS reported those numbers (falsely as it turned out).
Heartland - #19, Target - #20 at:
https://www.upguard.com/blog/biggest-data-breaches-us
You may notice that the poster of the comment you are responding to is mentioned a lot on that page.