Target confirms PIN data was stolen in breach 13 years ago
That was exactly my thought: you can't say "triple-DES encryption" and "we don't have the key." Saying that they delete it afterwords gives little comfort, especially considering that their infrastructure has been compromised.