The Target breach, start to finish: a contractor's login, ignored alarms and 40 million cards
In the 2013 holiday season, the security tools at America's No. 3 retailer spotted the malware that was stealing its customers' cards, and the warnings sat unanswered until the Justice Department phoned nearly 2 weeks later.[1][6] This long read follows the whole Target heist in order: the small contractor whose login was stolen, the registers, the alarms, the disclosures, the bill, and the one control that would have broken the chain.
The vendor login that opened the door
Fazio Mechanical Services was a refrigeration and HVAC contractor based in Sharpsburg, Pennsylvania, that worked on Target stores.[2] Like many suppliers, it had an account on Target's systems. The company later said that connection existed only for electronic billing, contract submission and project management, not for controlling heating or cooling equipment.[2]
The Senate Commerce Committee staff who reconstructed the attack found that the contractor had been hit with malware delivered by phishing email at least 2 months before the break-in, and that its Target credentials were taken that way.[1] The staff also noted that details about Target's suppliers, including pages for its supplier portal and facilities management, could be found with ordinary internet searches, so picking a supplier to go after did not require inside knowledge.[1]
On November 12, 2013, the intruders used the stolen login to get into Target's network for the first time.[1] A former vendor manager told the Senate staff that Target rarely asked low-level contractors for a second proof of identity when they signed in, so a password alone was enough.[1]
Two months earlier, in September 2013, Target had been certified as compliant with the payment card industry's security standard, the rulebook card brands use to judge whether a merchant protects card data properly.[1] On paper, the systems that touched cards were separated from everything else. In practice, a login created to send invoices became the first step on a path that ended at the checkout lanes. The staff report lists weak separation between the vendor side and sensitive systems as one of the failures that made that path possible.[1]
How the malware reached the registers
Getting from a billing account to a cash register took the attackers a few days. The Senate staff said they may have used a default account name that shipped with a common IT management product, a reminder that factory settings left in place are one of the easiest ways to move around a network.[1] Between November 15 and 28, they tried their card-stealing software on a handful of store terminals. By November 30, most of Target's point-of-sale systems were infected.[1]
The software read card details from a terminal's memory at the moment of a swipe, before the data was scrambled for its trip to the bank. Target later said cards used in its U.S. stores from November 27 to December 15 were exposed, a 19-day window that took in Black Friday and most of the holiday rush.[4] The stolen numbers were collected on servers inside Target's own network. Starting December 2, they were shipped out in batches during normal business hours, roughly 10 a.m. to 6 p.m. Central time, when the extra traffic would blend in with the day's work. About 11 GB left the company, with drop servers traced to Russia, Miami and Brazil.[1]
The cards did not stay hidden for long. Within days they were for sale on an underground card shop in batches of up to 1 million, priced from about $20 to more than $100 each depending on the card.[3] One New England bank quietly bought back about 20 of its own customers' cards from the shop. Every one of the 19 that were still valid had been used at Target stores across the country during the breach window, which gave banks an independent way to confirm where the leak was.[3]
The alarms that went unanswered
Target was not flying blind. About 6 months before the breach it had installed a malware detection system from the security firm FireEye, and a team in Bangalore, India, watched it around the clock and reported to the security operations center in Minneapolis.[7] On November 30, as the malware was being installed, the system raised an alert. More alerts followed as the attackers updated their software in early December, and some were marked at the top of the system's severity scale.[1][7] The company's antivirus software had flagged suspicious behavior on November 28 as well.[1]
The Bangalore team passed the warnings to Minneapolis. The Senate staff concluded that Target's security team neither acted on the alarms nor let the detection system remove the malware automatically.[1] That automatic removal feature had been switched off. Reporting at the time said the team had turned it off because it produced too many false positives, and may not yet have trusted the tool to act on its own.[6][7] The alerts carried a generic malware label, the kind a busy team sees many of every day.[6]
Target's spokeswoman later said the team had looked at the activity and judged that it did not need immediate follow-up, and that the company was investigating whether different judgments would have changed the outcome.[6] Researchers later found that the malware itself contained login details for the thieves' staging servers, a clue that could have led investigators to the data before it left.[8] Instead, the outside world moved first. On December 12, the Justice Department told Target about the breach. Within about 3 days, nearly all of the malware was gone.[1][6]
Disclosure, 70 million more records and a CEO's exit
A security journalist reported the breach on December 18, and Target confirmed it on December 19, putting the number at about 40 million credit and debit card accounts.[1][4] The company said guests would owe nothing for fraudulent charges and offered a year of free credit monitoring.[5]
Then the story grew. On January 10, 2014, Target said that names, mailing addresses, phone numbers and email addresses for up to 70 million people had also been taken. It stressed that this was part of the same incident, discovered as the investigation went on, not a new break-in.[5] With overlap between the 2 groups, later estimates put the total at up to 110 million customers.[15] Target also reported that comparable sales for the holiday quarter had fallen about 2.5%.[5]
In March 2014, the Senate Commerce Committee staff published its "kill chain" analysis, a stage-by-stage walk through the attack that found Target had missed chances to stop it at several points along the way.[1] On May 5, 2014, chairman and CEO Gregg Steinhafel stepped down after a 35-year career at the company, and the chief financial officer took over on an interim basis.[9][15] Private security firms pinned the attack on Russian cybercriminals, but the U.S. government did not make an official attribution, and no one has been publicly convicted of the intrusion.[15]
What the breach cost Target
The legal bills came from 3 directions: shoppers, the banks that had to replace cards, and the states. In March 2015, Target agreed to a $10 million class action settlement with consumers, with individuals able to claim up to $10,000 for documented losses.[10] In August 2015, it agreed to pay up to $67 million to banks that issued Visa cards.[11] In December 2015, it added a $39.4 million deal covering Mastercard issuers and other banks and credit unions.[12]
On May 23, 2017, Target settled with 47 states and the District of Columbia for $18.5 million, which the Nevada attorney general called the largest multistate data breach settlement reached to that point.[13] Money was only part of it. The agreement required a formal security program run by a designated executive, encryption and network access controls, password rotation and two-factor sign-in for certain accounts.[13] The fixes Target had made after the breach became obligations it had to keep.[15]
Adding it up, Target's filings put the total cost of the breach at about $292 million. Insurance covered roughly $90 million, leaving about $202 million for the company to absorb.[14]
Walking the chain backwards
Read the story in reverse and every link was visible before it broke. The card data left because nobody acted on the alerts in early December. The malware was installed because nobody acted on the alert of November 30 or the antivirus warning 2 days earlier. The attackers reached the registers because a supplier's billing login could travel far beyond the billing system. And the login was stolen because a single phishing email landed at a small contractor with no reason to think it was anyone's target.[1]
Any one of those links, closed, would have shortened or stopped the heist. The two that mattered most were a wall that kept supplier access away from the payment systems, and a rule that a serious alert gets a human decision within hours, not a shrug.
Timeline
| Date | What happened |
|---|---|
| Sep 2013 | Target certified as compliant with the card industry security standard.[1] |
| Nov 12, 2013 | Intruders first log in with the contractor's stolen credentials.[1] |
| Nov 15–28, 2013 | Card-stealing software tested on a small number of registers.[1] |
| Nov 28, 2013 | Antivirus software flags suspicious behavior.[1] |
| Nov 30, 2013 | Most registers infected; FireEye raises an alert.[1][7] |
| Dec 2, 2013 | Stolen data starts leaving the network; more alerts fire.[1] |
| Dec 12, 2013 | Justice Department notifies Target.[1] |
| Dec 19, 2013 | Target confirms about 40 million card accounts affected.[4] |
| Jan 10, 2014 | Target adds up to 70 million people's contact details.[5] |
| May 5, 2014 | CEO steps down.[9] |
| Aug 18, 2015 | Up to $67 million settlement with Visa issuers.[11] |
| May 23, 2017 | $18.5 million settlement with 47 states and D.C.[13] |
The missing control
The missing control: keep supplier access walled off from payment systems, and make sure every serious alert gets a human response. Either one would have cut this chain; together they would have made the stolen password close to useless and the malware short-lived.[1]
- Map what each outside account can reach. For every contractor, software company and IT provider with a login, write down what it is for and what it can actually touch, then remove access that goes beyond that purpose.
- Put card terminals on their own network. Ask your IT provider or payment processor to keep point-of-sale devices on a separate network segment from office computers, guest Wi-Fi and anything a vendor uses.
- Require two-factor sign-in for every remote login. Include the small accounts used for invoices, scheduling or support, since those are the ones attackers expect to be loosely guarded.
- Replace default names and passwords. Check routers, cameras, terminals and management software for factory accounts and change or disable them.
- Name an alert owner and a deadline. Decide who reads warnings from your antivirus, firewall or managed IT provider, how fast they must act, and when a device gets pulled offline without waiting for a meeting.
What it means now
Target had bought good tools, passed its audit and staffed a round-the-clock monitoring team, and it still lost 40 million cards. The gap was not technology. It was the space between a warning and a decision, and between what a supplier needed and what it could reach.
For a small business the scale is different but the shape is the same. Your weakest outside login and your least-read alert inbox are where the next heist starts. Close the first and answer the second, and a stolen password becomes an annoyance instead of a headline.
How the Target breach happened: a vendor's billing login and the alarms nobody answered: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
- How the Caesars hack happened: a con at the outsourced IT help desk
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Senate Committee on Commerce, Science, and Transportation: A "Kill Chain" Analysis of the 2013 Target Data Breach (Majority Staff Report, March 26, 2014)
- Krebs on Security: Target Hackers Broke in Via HVAC Company
- Krebs on Security: Cards Stolen in Target Breach Flood Underground Markets
- Target: Target Confirms Unauthorized Access to Payment Card Data in U.S. Stores
- Target: Target Provides Update on Data Breach and Financial Performance
- Business Insurance: Target says it declined to act on early alert of cyber breach
- The Register: Target failed to act on security alerts
- Help Net Security: Target failed to act on malware alerts and signs of breach
- SEC (Target Form 8-K exhibit): Target announces CEO leadership transition, May 5, 2014
- CBS News: Target agrees to pay $10 million to data breach victims
- CU Times: Target Settles With Visa for $67 Million
- NBC News: Target to pay $39 million settlement to banks over data breach
- Nevada Attorney General: Attorney General Laxalt and 47 States Reach $18.5 Million Settlement With Target Corporation over 2013 Data Breach
- The SSL Store: Cost of 2013 Target Data Breach Nears $300 Million
- CyberScoop: Target pays out $18.5M to victims of infamous 2013 data breach