Is this a result of not using chip and PIN, relying on offline transaction processing or some weird subscription plan?
I understand that there would be a cost involved in implementing chip and PIN across the entire US and it may not solve the issue if they insist on having the card on file. Online credit card processing has been pretty much standard for the last ten years here in Denmark. Terminals are connecting to the credit card processor, either via an ISDN/ADSL/phone/GSM connection, everything is encryptet and the store never has anything expect the cardmask.
So why do companies like Target have the card information of their customers?