Target Data Breach (Nov 27 - Dec 18 2013)
Introduction
The Target data breach of 2013 is a landmark case in corporate cybersecurity history — not because it involved novel attack techniques, but because it demonstrated how a large, security-conscious organisation could be compromised through a third-party vendor with minimal network privileges. Over 21 days during the peak of the US holiday shopping season, attackers stole 40 million payment-card numbers and the personal information of 70 million customers.
The breach was first disclosed publicly not by Target but by cybersecurity journalist Brian Krebs, who reported it on 18 December 2013 based on information from banking industry sources. Target confirmed the breach the same day.
The Attack Vector: Third-Party Vendor Credentials
Entry to Target's network was not achieved by breaching Target's perimeter directly. Attackers obtained network credentials belonging to Fazio Mechanical Services, a Pennsylvania-based refrigeration, heating, and air-conditioning contractor that maintained systems in Target stores. Fazio had been granted remote access to Target's network for billing, contract submission, and project management purposes.
The credentials were obtained via a phishing email targeting Fazio employees, which installed the Citadel malware — a banking trojan variant. Fazio reportedly used a free version of Malwarebytes as its primary endpoint security software, which did not provide real-time protection against the Citadel infection.
Using the stolen Fazio credentials, attackers accessed Target's network and moved laterally to find the point-of-sale infrastructure. Security researchers and subsequent investigations noted that Target's network segmentation between vendor systems and payment systems was inadequate — the vendor portal should not have had a pathway to POS systems.
The BlackPOS Malware
Once inside Target's payment network, attackers deployed BlackPOS (also known as Kaptoxa), a RAM-scraping malware designed specifically to harvest payment card data from POS terminal memory. At the point of sale, card data is briefly unencrypted in system memory between swipe and encryption for transmission. BlackPOS captured this data in transit. The malware was installed on a significant fraction of Target's approximately 1,800 US store POS systems.
The stolen card data was staged on a server within Target's network before being exfiltrated to external servers. Security researchers later noted that Target's FireEye intrusion detection system had triggered alerts during the malware installation phase — alerts that were not acted upon.
Detection and Disclosure
The US Department of Justice notified Target of the breach on 12 December 2013. Target confirmed and publicly disclosed the breach on 18 December 2013, the same day Brian Krebs published his report. The initial disclosure covered 40 million payment cards; Target disclosed in January 2014 that an additional 70 million records of personal information — names, addresses, phone numbers, email addresses — had also been stolen.
Executive Accountability
CEO Gregg Steinhafel, who had been with Target for 35 years and served as CEO since 2008, resigned on 5 May 2014. The board stated that the resignation was "a mutual decision." CIO Beth Jacob resigned in March 2014. Both departures were widely attributed to the breach and the company's handling of it.
The breach also prompted Target to accelerate its adoption of chip-and-PIN (EMV) payment technology. The US retail industry as a whole accelerated its EMV migration timeline following the breach, with the 2015 liability shift deadline becoming a major industry milestone.
Financial and Legal Consequences
Target estimated the total cost of the breach at approximately $300 million over subsequent years, accounting for fraud costs, legal settlements, security upgrades, and operational changes. In May 2017, Target agreed to an $18.5 million settlement with the attorneys general of 47 states and the District of Columbia — one of the largest multi-state data breach settlements at the time.
A class action by financial institutions recovered $67 million. A separate consumer class action was settled for $10 million. Visa and MasterCard issued separate assessments against Target under their operating rules.
Industry Impact
The Target breach became a defining case study in third-party vendor risk management. It accelerated PCI DSS revisions regarding vendor access controls, network segmentation requirements, and the management of third-party credentials. It also catalysed industry adoption of chip payment cards and contributed to the 2015 EMV liability shift that pushed US merchants to upgrade payment terminals.
Verdict
Confirmed. The breach is documented in exhaustive detail across congressional testimony, court records, security research publications, and regulatory filings. The attack vector (stolen vendor credentials), the malware (BlackPOS), the timeline, the volume of stolen data, and the financial consequences are all matters of public record.
The Senate "Kill Chain" Analysis
In March 2014, the Senate Committee on Commerce, Science and Transportation, then chaired by Senator Jay Rockefeller (D-WV), released a staff report titled "A 'Kill Chain' Analysis of the 2013 Target Data Breach." The report applied a military-derived "intrusion kill chain" framework — the idea that an attack is a chain of discrete stages, any one of which, if broken, stops the whole operation — to reconstruct exactly where Target's defenses could have stopped the intrusion and did not. The committee concluded that Target had missed multiple distinct opportunities along that chain, not just the single, oft-cited failure to act on FireEye alerts. According to congressional and press summaries of the report, Target's own anti-intrusion software generated automated warnings as the malware was installed and as it was configured to stage stolen data for exfiltration, and those warnings went unanswered at more than one stage of the operation.
Why the Alerts Went Unanswered
The popular shorthand for the Target breach — "they had the alarm and ignored it" — is broadly true but flattens a more specific and more uncomfortable fact. Target had installed a roughly $1.6 million FireEye malware-detection system about six months before the breach. FireEye's monitoring was partly handled by a security operations team in Bangalore, which on 30 November 2013 flagged the malware and notified Target's Minneapolis headquarters; a second alert followed on 2 December. Both were passed along and neither triggered a response for close to two weeks, until the U.S. Department of Justice contacted Target directly in mid-December.
What is less frequently reported is why the alerts didn't trigger automatic action. FireEye's platform included an option to automatically delete detected malware on sight. Target's security team had turned that feature off. Security professionals who reviewed the incident afterward noted this wasn't laziness or incompetence in the abstract — it reflected a deliberate, common security posture: keeping a human in the loop before software is allowed to auto-remediate on a live, revenue-critical retail network during the holiday season, precisely so that a false positive doesn't take down store payment systems. That is a defensible policy in isolation. In Target's case, the humans in that loop did not act on the information the policy required them to review, and the result was catastrophic. The nuance matters for how the case is used as a lesson: the failure was organizational responsiveness to a working detection system, not the absence of detection technology or reckless disregard for having any alerting at all.
The PCI Compliance Paradox
One detail that complicates any simple narrative of corporate negligence is that Target had been certified as compliant with the Payment Card Industry Data Security Standard (PCI DSS) not long before the breach. Its qualified security assessor, Trustwave, had reportedly scanned Target's network about two months before the intrusion and found no vulnerabilities requiring correction. Two banks, Trustmark National Bank and Green Bank, later filed a class-action suit against both Target and Trustwave in federal court in Chicago, alleging that Trustwave's monitoring services failed to detect the intrusion for roughly three weeks despite promising round-the-clock coverage. The banks voluntarily dismissed the suit without prejudice, meaning it was dropped rather than resolved on the merits, and no court ever ruled on whether Trustwave's certification or monitoring was deficient. The episode is a caution against over-reading the case: a company can hold a valid third-party security certification and still be breached, but that fact alone does not prove the certifying auditor was negligent — that specific allegation was never adjudicated.
A Number That Kept Changing
Target's public disclosures evolved over about six weeks. The initial 19 December 2013 disclosure covered roughly 40 million payment card accounts. On 10 January 2014, Target added that a separate set of records — names, mailing addresses, phone numbers, and email addresses for as many as 70 million individuals — had also been exposed. Media coverage at the time frequently added these two figures together and reported "110 million" affected customers. That combined figure overstates the number of unique people involved, because the two data sets overlapped substantially: many of the roughly 70 million people whose contact information was stolen were also among the 40 million payment-card holders. The Congressional Research Service's subsequent summary of the incident placed the effective ceiling closer to 98 million individuals once that overlap is accounted for. None of this changes the scale of the breach — it remains one of the largest retail breaches on record — but the frequently repeated "110 million" figure is a rounding-up of two overlapping datasets rather than a confirmed count of distinct victims.
Attribution Without Prosecution
Despite the breach's scale and the years of investigative reporting that followed it, no individual has ever been criminally charged specifically for breaching Target's network or writing the BlackPOS malware used against it. Investigative reporter Brian Krebs, who broke the original story, published a follow-up ten years later, in December 2023, tracing years of circumstantial evidence about the identity behind "Rescator," the online alias used to sell the stolen Target and Home Depot card data. That reporting connected an email address used by Rescator's forum persona to Mikhail Shefel, a Moscow-based former payment-processing employee who later changed his surname to Lenin, and to a wider network of individuals associated with the payment processor ChronoPay, including its former CEO Pavel Vrublevsky, who by the time of that reporting was imprisoned in Russia on unrelated fraud charges. Reasonable circumstantial attribution to Russia-based cybercriminal networks is not in serious dispute among researchers who have studied the case, but attribution built from forum handles, email metadata, and malware artifacts is not the same thing as a criminal conviction, and readers should not conflate confident attribution with legal accountability — the latter never happened for the Target intrusion itself.
The Financial Reckoning, Line by Line
Target's own SEC filings give a more granular account of the breach's cost than the often-cited "$300 million" round number. In fiscal 2013, Target recorded $61 million in gross breach-related expenses, offset by $44 million in insurance proceeds, for a net cost of $17 million. In fiscal 2014, gross expenses reached $191 million against $46 million in insurance recoveries, a net cost of $145 million for that year alone, bringing cumulative net costs to roughly $162 million through early 2015. By the time Target's later 10-K filings closed out the matter, cumulative gross breach-related expenses had reached approximately $292 million, offset by about $90 million in insurance recoveries, for a final net cost near $202 million — separate from, and not inclusive of, the various card-network settlements described below.
Those card-network settlements were themselves negotiated in stages rather than as a single payment. Target reached a $10 million agreement with a consumer class action, given preliminary court approval in March 2015 and finalized later that year. Separately, Target settled with Visa card issuers for up to $67 million in August 2015 — a deal reported at the time as roughly three and a half times the size of an approximately $19 million MasterCard-issuer settlement that banks had initially voted down. A revised MasterCard-track settlement of $19,107,939.38 and a further $20.25 million settlement covering Discover, American Express, and other card issuers not part of the Visa or MasterCard processes were finalized in December 2015. The $18.5 million paid to 47 state attorneys general and the District of Columbia in May 2017 was the last major settlement to close, and required Target to designate an executive responsible for information security, commission independent third-party security assessments, encrypt cardholder data, segment payment systems from the rest of its network, and adopt two-factor authentication for certain access — measures that, notably, target the exact gaps the Senate kill-chain analysis and Fazio Mechanical vector had exposed.
Legacy: What Changed and What Didn't
The Target case remains one of the most heavily documented breaches in corporate history precisely because it generated primary records at every level: a congressional staff investigation, multiple state attorney-general settlements with specific remedial terms, federal court-approved class settlements, and Target's own audited financial disclosures. That density of documentation is also what allows the nuances above to be stated with confidence rather than speculation — the record supports both the core "confirmed" verdict and a more precise picture of where popular retellings round the story off.
Evidence Filters16
HVAC vendor credentials used as initial access vector
SupportingStrongFazio Mechanical Services, a third-party HVAC contractor with remote network access to Target's systems, had its credentials stolen via a phishing email deploying the Citadel banking trojan. The stolen credentials provided the initial foothold into Target's network.
BlackPOS RAM-scraping malware installed on POS terminals
SupportingStrongBlackPOS (Kaptoxa) malware was deployed on a significant fraction of Target's 1,800 US store POS terminals, harvesting payment card data from system memory between swipe and encryption. The malware exfiltrated 40 million card numbers over 21 days.
FireEye alerts not acted upon
SupportingStrongTarget's FireEye intrusion detection system generated alerts during the malware installation phase. Those alerts were not escalated or acted upon. This failure of internal detection and response compounded the initial vendor-access vulnerability.
Brian Krebs disclosed breach publicly 18 December 2013
SupportingStrongJournalist Brian Krebs at KrebsOnSecurity.com was first to publicly report the breach, on 18 December 2013, based on banking industry sources who had observed a pattern of card fraud traced to Target purchases. Target confirmed the breach the same day.
CEO Gregg Steinhafel and CIO Beth Jacob both resigned within months
SupportingCIO Beth Jacob resigned in March 2014; CEO Gregg Steinhafel resigned on 5 May 2014. Both departures were attributed by the board and analysts to the breach and the company's handling of it. Steinhafel had been with Target for 35 years.
$18.5M state AG settlement and ~$300M total costs
SupportingStrongTarget reached an $18.5 million settlement with the attorneys general of 47 states in May 2017. Cumulative costs including fraud reimbursements, legal fees, security upgrades, and settlements were estimated at approximately $300 million over subsequent years.
Fazio's free Malwarebytes endpoint security — inadequacy question
NeutralReports indicated Fazio used a free version of Malwarebytes that did not include real-time protection as its primary endpoint security tool. Whether this directly caused the Citadel infection is debated; the adequacy of vendor security assessments by Target is a separate question.
Rebuttal
The Fazio credential theft was the proximate entry point, but the deeper failure was Target's network segmentation allowing a vendor portal with HVAC billing access to reach POS systems. Even a well-secured vendor should not have had that network path.
Industry-wide EMV acceleration and PCI DSS reforms followed
NeutralWeakThe Target breach accelerated the US payment card industry's EMV (chip-and-PIN) migration timeline and prompted revisions to PCI DSS third-party vendor access standards. The 2015 EMV liability shift became a direct industry response to lessons from Target and subsequent breaches.
Card-network settlements (Visa, MasterCard, other issuers) totaling over $116 million confirm the scale of downstream bank losses
SupportingStrongBeyond the $18.5M state settlement and $10M consumer settlement, Target separately settled with Visa card issuers for up to $67 million (August 2015), a revised MasterCard-issuer track for $19,107,939.38, and a further $20.25 million with issuers of Discover, American Express and other cards not covered by the Visa/MasterCard processes (both finalized December 2015). These figures come from Target's own settlement agreements as reported by law firms tracking the litigation, and independently corroborate the scale of financial-sector harm alongside Target's own SEC-disclosed breach costs.
No individual has ever been criminally charged for the Target intrusion itself
DebunkingDespite a decade of investigative reporting narrowing in on the identity behind the 'Rescator' card-selling persona (most recently Brian Krebs's December 2023 reporting linking the alias to Moscow-based Mikhail Shefel and a wider ChronoPay-linked network including imprisoned former CEO Pavel Vrublevsky), no criminal charges specific to the Target network intrusion or the BlackPOS malware have been filed against any named individual. Attribution built on forum handles, leaked emails and malware artifacts is strong circumstantially but is not equivalent to a prosecution or conviction.
Rebuttal
This does not undermine the confirmed facts of the breach itself (the intrusion, the vendor-credential vector, and the stolen-data volumes are independently documented by Target, banks, and regulators). It limits only the 'who did it and were they punished' dimension — attribution and prosecution are separate questions from the breach's occurrence and scale.
Show 6 more evidence points
The FireEye auto-delete feature was deliberately disabled, not simply an oversight
DebunkingMultiple contemporaneous reports (Bloomberg Businessweek's March 2014 investigation, later corroborated in academic and legal-scholarship retrospectives) establish that Target's security team had turned off FireEye's automatic malware-deletion capability, keeping a human decision point in the loop rather than letting the software auto-remediate on a live payment network. This was a considered security-posture choice common in the industry, not a technical failure to configure the tool.
Rebuttal
The choice to require human sign-off before auto-deletion is a defensible practice in isolation; the actual failure was that the humans responsible for reviewing the resulting alerts (received in Bangalore and forwarded to Minneapolis on at least two separate dates, 30 November and 2 December 2013) did not act on them for roughly two weeks. This nuances 'they ignored the alarm' from pure incompetence toward a documented organizational-response failure layered on top of a reasonable technical policy.
The widely cited '110 million affected' figure overstates unique victims due to dataset overlap
DebunkingTarget's two disclosures — roughly 40 million payment-card accounts (19 December 2013) and roughly 70 million records of personal contact information (10 January 2014) — are frequently added together in media coverage to produce a combined total of 110 million. The Congressional Research Service's review of the incident instead placed the effective ceiling near 98 million individuals once overlap between the two datasets (many card holders were also in the contact-information set) is taken into account.
Rebuttal
This is a correction to a popularized round number, not a reduction in the breach's severity — Target itself never disclosed a single combined 'unique individuals affected' figure, and 98 million (CRS's estimate) versus 110 million (the simple sum) both describe one of the largest retail breaches on record either way.
Target held a valid PCI DSS compliance certification shortly before the breach, and the resulting lawsuit against its auditor was dropped, not adjudicated
DebunkingTrustwave, Target's PCI qualified security assessor, reportedly scanned Target's network about two months before the breach and found no disqualifying vulnerabilities. Two banks (Trustmark National Bank and Green Bank) sued both Target and Trustwave in federal court in Chicago alleging Trustwave's monitoring service failed to detect the three-week intrusion despite promising continuous coverage. The plaintiffs voluntarily dismissed the case without prejudice, meaning it could be refiled but no court ever ruled on whether Trustwave's certification or monitoring was actually deficient.
Rebuttal
This shows that PCI compliance certification is not proof of adequate security (a real and useful lesson from the case), but it also means the specific allegation that Trustwave's audit or monitoring was negligent was never proven in court — the lawsuit's dismissal without prejudice leaves that particular claim legally untested rather than confirmed.
Target's own SEC filings itemize breach costs in stages, not as a single lump figure
NeutralStrongTarget's 10-K disclosures show $61M gross/$17M net cost in fiscal 2013, $191M gross/$145M net in fiscal 2014 (cumulative net ~$162M through early 2015), rising to a final cumulative figure of roughly $292M gross against $90M in insurance recoveries (~$202M net) once later filings closed out the matter — a more granular accounting than the commonly cited round '$300 million' figure, and one that is separate from the card-network and state settlements paid on top of it.
HVAC Vendor Credential Compromise Was Supply-Chain Attack, Not Internal Corporate Concealment
NeutralThe Target breach began when attackers compromised credentials of Fazio Mechanical Services, Target's HVAC vendor, and used network access granted for electronic billing and project management to pivot to the point-of-sale environment. This attack vector — third-party vendor credential compromise — was a novel and sophisticated technique at the time, not a well-known risk that Target had deliberately ignored. The attack vector has since become a recognized supply-chain risk category and informed subsequent NIST and PCI DSS guidance.
CEO Resignation and PCI DSS Reforms Reflected Genuine Accountability
DebunkingTarget CEO Gregg Steinhafel resigned in May 2014 — a significant accountability event that corporations rarely accept voluntarily. The breach also accelerated US adoption of EMV chip-card standards and PCI DSS 3.0's enhanced third-party vendor security requirements. These outcomes reflect the accountability mechanisms working — reputational pressure forcing leadership change and industry standards reform — not a system designed to protect corporations from consequences of security failures.
Evidence Cited by Believers7
HVAC vendor credentials used as initial access vector
SupportingStrongFazio Mechanical Services, a third-party HVAC contractor with remote network access to Target's systems, had its credentials stolen via a phishing email deploying the Citadel banking trojan. The stolen credentials provided the initial foothold into Target's network.
BlackPOS RAM-scraping malware installed on POS terminals
SupportingStrongBlackPOS (Kaptoxa) malware was deployed on a significant fraction of Target's 1,800 US store POS terminals, harvesting payment card data from system memory between swipe and encryption. The malware exfiltrated 40 million card numbers over 21 days.
FireEye alerts not acted upon
SupportingStrongTarget's FireEye intrusion detection system generated alerts during the malware installation phase. Those alerts were not escalated or acted upon. This failure of internal detection and response compounded the initial vendor-access vulnerability.
Brian Krebs disclosed breach publicly 18 December 2013
SupportingStrongJournalist Brian Krebs at KrebsOnSecurity.com was first to publicly report the breach, on 18 December 2013, based on banking industry sources who had observed a pattern of card fraud traced to Target purchases. Target confirmed the breach the same day.
CEO Gregg Steinhafel and CIO Beth Jacob both resigned within months
SupportingCIO Beth Jacob resigned in March 2014; CEO Gregg Steinhafel resigned on 5 May 2014. Both departures were attributed by the board and analysts to the breach and the company's handling of it. Steinhafel had been with Target for 35 years.
$18.5M state AG settlement and ~$300M total costs
SupportingStrongTarget reached an $18.5 million settlement with the attorneys general of 47 states in May 2017. Cumulative costs including fraud reimbursements, legal fees, security upgrades, and settlements were estimated at approximately $300 million over subsequent years.
Card-network settlements (Visa, MasterCard, other issuers) totaling over $116 million confirm the scale of downstream bank losses
SupportingStrongBeyond the $18.5M state settlement and $10M consumer settlement, Target separately settled with Visa card issuers for up to $67 million (August 2015), a revised MasterCard-issuer track for $19,107,939.38, and a further $20.25 million with issuers of Discover, American Express and other cards not covered by the Visa/MasterCard processes (both finalized December 2015). These figures come from Target's own settlement agreements as reported by law firms tracking the litigation, and independently corroborate the scale of financial-sector harm alongside Target's own SEC-disclosed breach costs.
Counter-Evidence5
No individual has ever been criminally charged for the Target intrusion itself
DebunkingDespite a decade of investigative reporting narrowing in on the identity behind the 'Rescator' card-selling persona (most recently Brian Krebs's December 2023 reporting linking the alias to Moscow-based Mikhail Shefel and a wider ChronoPay-linked network including imprisoned former CEO Pavel Vrublevsky), no criminal charges specific to the Target network intrusion or the BlackPOS malware have been filed against any named individual. Attribution built on forum handles, leaked emails and malware artifacts is strong circumstantially but is not equivalent to a prosecution or conviction.
Rebuttal
This does not undermine the confirmed facts of the breach itself (the intrusion, the vendor-credential vector, and the stolen-data volumes are independently documented by Target, banks, and regulators). It limits only the 'who did it and were they punished' dimension — attribution and prosecution are separate questions from the breach's occurrence and scale.
The FireEye auto-delete feature was deliberately disabled, not simply an oversight
DebunkingMultiple contemporaneous reports (Bloomberg Businessweek's March 2014 investigation, later corroborated in academic and legal-scholarship retrospectives) establish that Target's security team had turned off FireEye's automatic malware-deletion capability, keeping a human decision point in the loop rather than letting the software auto-remediate on a live payment network. This was a considered security-posture choice common in the industry, not a technical failure to configure the tool.
Rebuttal
The choice to require human sign-off before auto-deletion is a defensible practice in isolation; the actual failure was that the humans responsible for reviewing the resulting alerts (received in Bangalore and forwarded to Minneapolis on at least two separate dates, 30 November and 2 December 2013) did not act on them for roughly two weeks. This nuances 'they ignored the alarm' from pure incompetence toward a documented organizational-response failure layered on top of a reasonable technical policy.
The widely cited '110 million affected' figure overstates unique victims due to dataset overlap
DebunkingTarget's two disclosures — roughly 40 million payment-card accounts (19 December 2013) and roughly 70 million records of personal contact information (10 January 2014) — are frequently added together in media coverage to produce a combined total of 110 million. The Congressional Research Service's review of the incident instead placed the effective ceiling near 98 million individuals once overlap between the two datasets (many card holders were also in the contact-information set) is taken into account.
Rebuttal
This is a correction to a popularized round number, not a reduction in the breach's severity — Target itself never disclosed a single combined 'unique individuals affected' figure, and 98 million (CRS's estimate) versus 110 million (the simple sum) both describe one of the largest retail breaches on record either way.
Target held a valid PCI DSS compliance certification shortly before the breach, and the resulting lawsuit against its auditor was dropped, not adjudicated
DebunkingTrustwave, Target's PCI qualified security assessor, reportedly scanned Target's network about two months before the breach and found no disqualifying vulnerabilities. Two banks (Trustmark National Bank and Green Bank) sued both Target and Trustwave in federal court in Chicago alleging Trustwave's monitoring service failed to detect the three-week intrusion despite promising continuous coverage. The plaintiffs voluntarily dismissed the case without prejudice, meaning it could be refiled but no court ever ruled on whether Trustwave's certification or monitoring was actually deficient.
Rebuttal
This shows that PCI compliance certification is not proof of adequate security (a real and useful lesson from the case), but it also means the specific allegation that Trustwave's audit or monitoring was negligent was never proven in court — the lawsuit's dismissal without prejudice leaves that particular claim legally untested rather than confirmed.
CEO Resignation and PCI DSS Reforms Reflected Genuine Accountability
DebunkingTarget CEO Gregg Steinhafel resigned in May 2014 — a significant accountability event that corporations rarely accept voluntarily. The breach also accelerated US adoption of EMV chip-card standards and PCI DSS 3.0's enhanced third-party vendor security requirements. These outcomes reflect the accountability mechanisms working — reputational pressure forcing leadership change and industry standards reform — not a system designed to protect corporations from consequences of security failures.
Neutral / Ambiguous4
Fazio's free Malwarebytes endpoint security — inadequacy question
NeutralReports indicated Fazio used a free version of Malwarebytes that did not include real-time protection as its primary endpoint security tool. Whether this directly caused the Citadel infection is debated; the adequacy of vendor security assessments by Target is a separate question.
Rebuttal
The Fazio credential theft was the proximate entry point, but the deeper failure was Target's network segmentation allowing a vendor portal with HVAC billing access to reach POS systems. Even a well-secured vendor should not have had that network path.
Industry-wide EMV acceleration and PCI DSS reforms followed
NeutralWeakThe Target breach accelerated the US payment card industry's EMV (chip-and-PIN) migration timeline and prompted revisions to PCI DSS third-party vendor access standards. The 2015 EMV liability shift became a direct industry response to lessons from Target and subsequent breaches.
Target's own SEC filings itemize breach costs in stages, not as a single lump figure
NeutralStrongTarget's 10-K disclosures show $61M gross/$17M net cost in fiscal 2013, $191M gross/$145M net in fiscal 2014 (cumulative net ~$162M through early 2015), rising to a final cumulative figure of roughly $292M gross against $90M in insurance recoveries (~$202M net) once later filings closed out the matter — a more granular accounting than the commonly cited round '$300 million' figure, and one that is separate from the card-network and state settlements paid on top of it.
HVAC Vendor Credential Compromise Was Supply-Chain Attack, Not Internal Corporate Concealment
NeutralThe Target breach began when attackers compromised credentials of Fazio Mechanical Services, Target's HVAC vendor, and used network access granted for electronic billing and project management to pivot to the point-of-sale environment. This attack vector — third-party vendor credential compromise — was a novel and sophisticated technique at the time, not a well-known risk that Target had deliberately ignored. The attack vector has since become a recognized supply-chain risk category and informed subsequent NIST and PCI DSS guidance.
Timeline
Fazio Mechanical credentials stolen via phishing
Attackers send a phishing email to employees of Fazio Mechanical Services, a Target HVAC contractor, deploying the Citadel banking trojan. Fazio's network credentials for Target's vendor portal are captured. Fazio reportedly uses a free version of Malwarebytes without real-time protection.
BlackPOS deployed on Target POS systems; Thanksgiving shopping begins
Using Fazio credentials, attackers access Target's network and deploy BlackPOS RAM-scraping malware on POS terminals across approximately 1,800 US stores. The Thanksgiving holiday shopping period — the highest-traffic retail period of the year — begins the same day. FireEye alerts are generated but not acted upon.
Brian Krebs discloses breach; Target confirms same day
KrebsOnSecurity publishes a report based on banking industry sources describing a major card breach traced to Target. Target confirms the breach the same day, disclosing 40 million compromised payment-card numbers. Target later reveals 70 million PII records were also stolen. The breach had already ended — 40 million cards were exfiltrated over 21 days.
Source →Senate Commerce Committee releases 'Kill Chain' staff report
The Senate Committee on Commerce, Science and Transportation, chaired by Senator Jay Rockefeller, published a staff report, 'A "Kill Chain" Analysis of the 2013 Target Data Breach,' concluding Target missed multiple distinct opportunities to stop the intrusion before data was exfiltrated.
Source →
Verdict
Target's network was accessed via stolen credentials from HVAC vendor Fazio Mechanical Services. BlackPOS RAM-scraping malware captured 40M payment-card numbers and 70M PII records between 27 Nov and 18 Dec 2013. Brian Krebs broke the story 18 Dec 2013. CEO Gregg Steinhafel resigned May 2014; CIO Beth Jacob resigned March 2014. $18.5M state AG settlement May 2017. Total cost ~$300M. PCI DSS vendor-access reforms followed.
Frequently Asked Questions
How did attackers get into Target's network through an HVAC vendor?
Fazio Mechanical Services had been granted remote access to Target's network for billing and project management. Attackers stole Fazio's credentials via a phishing email deploying the Citadel banking trojan. The critical failure was that Target's network did not adequately segment the vendor portal from payment infrastructure — a path from an HVAC billing login to POS terminals should not have existed.
Did Target's security systems detect the breach?
Yes. Target's FireEye intrusion detection system generated alerts during the BlackPOS malware installation phase. Those alerts were not escalated or acted upon. Had the FireEye alerts been responded to, the breach could have been contained before substantial card data was exfiltrated. The failure of detection response compounded the initial access failure.
How did Brian Krebs find out about the breach before Target disclosed it?
Krebs received information from banking industry sources — card issuers and fraud analysts — who had identified a pattern of payment card fraud that traced back to purchases made at Target stores between late November and mid-December 2013. The banking sector often detects breaches at retailers before the affected company discloses them publicly, because card fraud patterns are visible to card issuers.
What was the long-term impact of the Target breach on the payment card industry?
Sources
Show 10 more sources
Further Reading
- articleTarget hackers broke in via HVAC company — KrebsOnSecurity — Brian Krebs (2014)
- paperSenate Commerce Committee hearing: data security at major retailers — US Senate Commerce Committee (2014)
- bookSpam Nation: The Inside Story of Organised Cybercrime — Brian Krebs (2014)
- articleMissed Alarms and 40 Million Stolen Credit Card Numbers: How Target Blew It — Michael Riley, Ben Elgin, Dune Lawrence and Carol Matlack (2014)
- bookBreached!: Why Data Security Law Fails and How to Improve It — Daniel J. Solove and Woodrow Hartzog (2022)