Case file · TARGET 2013

How the Target breach happened: a vendor's billing login and the alarms nobody answered

Published 2026-09-26 · 4 min read

The biggest retail breach of 2013 did not start at a cash register. It started with a login that belonged to a small heating and refrigeration contractor, and it ended with about 40 million payment cards and up to 70 million customer records in criminal hands.[1][4] This case file covers how thieves got from a vendor's billing login to the checkout lanes, the alarms that went off, what it cost, and the one missing control.

What happened

In the fall of 2013, a Pennsylvania refrigeration and HVAC contractor, Fazio Mechanical Services had an online connection to Target for billing, contracts and project management.[2] According to a later analysis by Senate Commerce Committee staff, the contractor's computers were hit by malware delivered by email roughly two months before the break-in, and that is believed to be how its Target login was stolen.[1]

In mid-November 2013, the intruders used those credentials to get inside Target's network. Over the following two weeks they tested card-stealing malware on a small number of store checkout terminals, and by November 30 most of the chain's point-of-sale systems were infected.[1][2] Cards swiped in U.S. stores between November 27 and December 15, the heart of the holiday shopping season, were exposed.[3]

Target did not find the breach on its own. The Department of Justice notified the company on December 12. A security journalist broke the story on December 18, and Target confirmed it the next day, putting the number at about 40 million credit and debit card accounts.[1][3] In January 2014 the company added that names, mailing addresses, phone numbers and email addresses for up to 70 million people had also been taken. It said this was part of the same incident, not a new one.[4]

How they got in

The contractor was not running Target's air conditioning remotely. It said publicly that its connection was used only for electronic billing, contract submission and project management.[2] That is exactly the point. A low-privilege supplier login, meant for sending invoices, turned out to be a door into the same network that eventually reached the registers.

The Senate staff report walks through the attack in stages and finds a weak spot at almost every one. Two-factor authentication (a second proof of identity, such as a code on a phone) was rarely required for lower-level contractors. Once inside, the attackers apparently benefited from a default account password that had never been changed. Most importantly, the network was not divided tightly enough to stop someone who came in through the vendor side from moving to the systems that handle payment cards.[1]

At the checkout lanes, the malware grabbed card numbers from the terminals' memory in the brief moment before they were encrypted and sent onward. The stolen data was gathered inside Target's network, then shipped out to servers in several countries, including Russia, during ordinary business hours when heavy traffic helped it blend in. Staff put the haul at about 11 GB.[1]

How it was caught and what it cost

The painful part of this story is that Target's defenses did notice. The company had invested in malware-detection tools, and according to the Senate staff analysis, they raised automated alerts when the data-theft malware was installed in early December, including details of where the data was being sent. Antivirus software had also flagged suspicious activity on November 28. The report found that those warnings were not acted on in time, and that the theft continued until outside investigators called.[1] Target had also been certified as meeting the payment card industry's security standard in September 2013, a reminder that passing an audit is not the same as being watched.[1]

The bills arrived for years. In 2015 Target agreed to a $10 million settlement with consumers, a $67 million settlement with Visa and about $39 million with banks and credit unions that had to reissue cards, bringing publicly reported settlements to roughly $116 million by the end of that year.[5] In May 2017 it agreed to pay $18.5 million to 47 states and the District of Columbia. That deal also required Target to hire an executive to run its security program, bring in independent assessors, and keep its cardholder data environment segmented from the rest of its network.[6]

The missing control

The missing control: vendor access segmented from payment systems.

A supplier who needs to submit invoices should land in a small, walled-off area that can reach the billing portal and nothing else. If the contractor's stolen login had been limited to that corner, the attackers would have been standing in a closet with a filing cabinet, not in a hallway that led to every cash register in the country. The Senate staff named weak segmentation as the failure that let the intrusion cross from vendor access to payment systems, and the state attorneys general later wrote segmentation into Target's settlement.[1][6] It would not have stopped the phishing, but it would have made the stolen password nearly worthless.

What to do in your business

Watch the case
Episode drops 2026-09-26
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More case files

Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.

Sources
  1. U.S. Senate Committee on Commerce, Science, and Transportation: A "Kill Chain" Analysis of the 2013 Target Data Breach (Majority Staff Report, March 26, 2014)
  2. Krebs on Security: Target Hackers Broke in Via HVAC Company
  3. Target: Target Confirms Unauthorized Access to Payment Card Data in U.S. Stores
  4. Target: An Update on Our Data Breach and Financial Performance
  5. CNN Money: Target settles for $39 million over data breach
  6. New York State Attorney General: A.G. Schneiderman Announces $18.5 Million Multi-State Settlement With Target Corporation Over 2013 Data Breach