No personal information, debit PIN numbers, email addresses or social security numbers, however, had been gleaned during the episode, which began in early September and was detected on Thursday.
"Our Kmart store payment data systems were infected with a form of malware that was undetectable by current anti-virus systems," department store operator Sears Holdings, which owns retailers Kmart and Sears, said in a statement.
There was no evidence that online customers at kmart.Com had been affected, and the company gave no indication as to how many cards were compromised.
The company added that it had "deployed advanced software to protect our customers' information" and that the store would offer free credit card monitoring to customers who had shopped at the retailer September through Thursday.
More From This Section
Kmart, which has a network of 1,200 stores across the United States, is only the latest US retailer to be hit by a cyberattack.
In mid-September home-improvement retailer Home Depot announced a data breach that affected as many as 56 million customer payment cards between April and September.