Skip to main content

Fact check

Is it true: Target data breach (Nov 27 - Dec 18 2013)?

Confirmed5% confidence

Yes — this is confirmed.

Target's network was accessed via stolen credentials from HVAC vendor Fazio Mechanical Services. BlackPOS RAM-scraping malware captured 40M payment-card numbers and 70M PII records between 27 Nov and 18 Dec 2013. Brian Krebs broke the story 18 Dec 2013. CEO Gregg Steinhafel resigned May 2014; CIO Beth Jacob resigned March 2014. $18.5M state AG settlement May 2017. Total cost ~$300M. PCI DSS vendor-access reforms followed.

The claim

Between 27 November and 18 December 2013, attackers stole 40 million payment-card numbers and 70 million records of personal information from Target's point-of-sale systems. Entry was gained via stole

Key evidence

HVAC vendor credentials used as initial access vector

CEO Resignation and PCI DSS Reforms Reflected Genuine Accountability

Read the full evidence file

Conspirafy steelmans each claim, then follows the evidence. How we reach a verdict · Check another claim