(Yes, this adds cost to the transaction. But as long as people want to take each other's money without permission, there is always going to be a cost to using money, whether it's an interchange fee, higher taxes, or just getting $500 bucks stolen on the subway from time to time.)
Just because its not a line item somewhere on your bank statement doesn't mean you're not paying for it.
If an attacker intercepts that, they can get the account number from it and potentially use it for online purchases. But they wouldn't have the postal code or security code, which most but not all ecommerce merchants require.
It's a rather flawed system - there are strict protections around certain cardholder data like PINs, but none of that really prevents fraud since just the account number is enough to make certain purchases.
The question is whether the chip-and-PIN technology would have revealed less information (i.e. insufficiently much to allow online purchases, etc.).
What always weirded me out about Target is that they used the credit card number (or name, or something on the card) as the key into their "loyalty program". If you bought some generic drug last time, this time their machine will print out a coupon for the name-brand version. This always weirded me out a little bit, though there is nothing preventing them from just storing a hash. Of course, the average developer never stores just a hash, and here we are.
At least in the Minneapolis store I shopped at during the breach, it was a simple swipe terminal.
The shop was selling data stolen from the magnetic stripe of each card, which thieves can re-encode onto new, counterfeit cards and use to go shopping in bricks-and-mortar stores for items than can easily be fenced or resold.
Is that possible to do with a chip and PIN card? Most of the focus from these articles seems to have to do with replicating the cards and using the replicas in stores, not online.
I remember maybe a decade ago there was a kind of scare (well, at least the TV news talked about it) about YesCards, some kind of fraudulent EMV cards, but according to Wikipedia[0] it doesn't look like they would still work today.
[0] https://fr.wikipedia.org/wiki/Yescard (for some reason, the English article is deleted).
Chip-and-pin won't help you with online sales, but for any card-present sale (brick-and-mortar) it should ensure counterfeits cannot be used, and the PIN of course is the second factor to ensure only you can use the card.
When I buy something online using my CC, and if the payment processor supports that (mostly local/european shops), I get redirected to a page on my bank for verification. Some banks require the PIN to be entered, some others to enter your login credentials, some coordinates from your code card or even verify with a SMS code.
Not exactly using the chip, but it involves the PIN surely.