How the Target breach happened: a vendor's billing login and the alarms nobody answered
The biggest retail breach of 2013 did not start at a cash register. It started with a login that belonged to a small heating and refrigeration contractor, and it ended with about 40 million payment cards and up to 70 million customer records in criminal hands.[1][4] This case file covers how thieves got from a vendor's billing login to the checkout lanes, the alarms that went off, what it cost, and the one missing control.
What happened
In the fall of 2013, a Pennsylvania refrigeration and HVAC contractor, Fazio Mechanical Services had an online connection to Target for billing, contracts and project management.[2] According to a later analysis by Senate Commerce Committee staff, the contractor's computers were hit by malware delivered by email roughly two months before the break-in, and that is believed to be how its Target login was stolen.[1]
In mid-November 2013, the intruders used those credentials to get inside Target's network. Over the following two weeks they tested card-stealing malware on a small number of store checkout terminals, and by November 30 most of the chain's point-of-sale systems were infected.[1][2] Cards swiped in U.S. stores between November 27 and December 15, the heart of the holiday shopping season, were exposed.[3]
Target did not find the breach on its own. The Department of Justice notified the company on December 12. A security journalist broke the story on December 18, and Target confirmed it the next day, putting the number at about 40 million credit and debit card accounts.[1][3] In January 2014 the company added that names, mailing addresses, phone numbers and email addresses for up to 70 million people had also been taken. It said this was part of the same incident, not a new one.[4]
How they got in
The contractor was not running Target's air conditioning remotely. It said publicly that its connection was used only for electronic billing, contract submission and project management.[2] That is exactly the point. A low-privilege supplier login, meant for sending invoices, turned out to be a door into the same network that eventually reached the registers.
The Senate staff report walks through the attack in stages and finds a weak spot at almost every one. Two-factor authentication (a second proof of identity, such as a code on a phone) was rarely required for lower-level contractors. Once inside, the attackers apparently benefited from a default account password that had never been changed. Most importantly, the network was not divided tightly enough to stop someone who came in through the vendor side from moving to the systems that handle payment cards.[1]
At the checkout lanes, the malware grabbed card numbers from the terminals' memory in the brief moment before they were encrypted and sent onward. The stolen data was gathered inside Target's network, then shipped out to servers in several countries, including Russia, during ordinary business hours when heavy traffic helped it blend in. Staff put the haul at about 11 GB.[1]
How it was caught and what it cost
The painful part of this story is that Target's defenses did notice. The company had invested in malware-detection tools, and according to the Senate staff analysis, they raised automated alerts when the data-theft malware was installed in early December, including details of where the data was being sent. Antivirus software had also flagged suspicious activity on November 28. The report found that those warnings were not acted on in time, and that the theft continued until outside investigators called.[1] Target had also been certified as meeting the payment card industry's security standard in September 2013, a reminder that passing an audit is not the same as being watched.[1]
The bills arrived for years. In 2015 Target agreed to a $10 million settlement with consumers, a $67 million settlement with Visa and about $39 million with banks and credit unions that had to reissue cards, bringing publicly reported settlements to roughly $116 million by the end of that year.[5] In May 2017 it agreed to pay $18.5 million to 47 states and the District of Columbia. That deal also required Target to hire an executive to run its security program, bring in independent assessors, and keep its cardholder data environment segmented from the rest of its network.[6]
The missing control
The missing control: vendor access segmented from payment systems.
A supplier who needs to submit invoices should land in a small, walled-off area that can reach the billing portal and nothing else. If the contractor's stolen login had been limited to that corner, the attackers would have been standing in a closet with a filing cabinet, not in a hallway that led to every cash register in the country. The Senate staff named weak segmentation as the failure that let the intrusion cross from vendor access to payment systems, and the state attorneys general later wrote segmentation into Target's settlement.[1][6] It would not have stopped the phishing, but it would have made the stolen password nearly worthless.
What to do in your business
- List every outside login. Write down every vendor, contractor, IT provider and software company that can sign in to your systems, and what each one can actually reach. Remove any account nobody can explain.
- Put payments on their own network. Ask your IT provider or card processor to keep card terminals and point-of-sale gear on a separate network (or at least a separate Wi-Fi and VLAN, a virtual network divider) from office PCs, guest Wi-Fi and anything a vendor touches.
- Require a second factor for remote access. Turn on two-factor authentication for every remote or vendor login, including the "small" ones for billing and scheduling.
- Change default passwords. Check routers, cameras, card terminals and management software for factory or default passwords and replace them.
- Make sure alerts reach a person. Decide who reads security warnings from your antivirus, firewall or managed IT provider, how fast they must respond, and who they call. An alert that nobody reads is just a log file.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.
- U.S. Senate Committee on Commerce, Science, and Transportation: A "Kill Chain" Analysis of the 2013 Target Data Breach (Majority Staff Report, March 26, 2014)
- Krebs on Security: Target Hackers Broke in Via HVAC Company
- Target: Target Confirms Unauthorized Access to Payment Card Data in U.S. Stores
- Target: An Update on Our Data Breach and Financial Performance
- CNN Money: Target settles for $39 million over data breach
- New York State Attorney General: A.G. Schneiderman Announces $18.5 Million Multi-State Settlement With Target Corporation Over 2013 Data Breach