The Target Breach (2013) - 40 Million credit cards were stolen
What happened?
In 2013, attackers entered Target's network via a third-party HVAC vendor. They used a phishing email to infect the vendor, stole their login details and accessed Target's portal. Then, they installed malware on their payment terminals. Over the next weeks, they stole 40 million credit and debit card numbers along with personal information from millions of customers.
Target spent more than $200 million in legal settlements and lost half of its board of directors. The CEO resigned!
Attack Chain
Every cyberattack follows a pattern. Security teams use the Cyber Kill Chain to break attacks into stages.
Stage 1: Reconnaissance
Before the attack, someone researched Target's suppliers. They were looking for a small company with network access to Target - a contractor with weaker security than a huge corporation.
They found Fazio Mechanical Services, a small HVAC company in Pennsylvania. Fazio had access to Target's network so they could monitor heating, ventilation, and air conditioning systems in Target stores.
The attacker's question: "Who has network access to my real target, but isn't the real target?"
The defender's failure: Target gave network access to a third party without demanding the same security standards they applied to themselves.
Stage 2: Weaponization and Delivery
Attackers sent phishing emails to Fazio employees. One email contained a malware attachment called Citadel - a password-stealing Trojan. An employee opened it.
Citadel installed itself silently and began logging keystrokes. When Fazio employees logged into Target's vendor portal, Citadel captured their usernames and passwords.
The attacker's tool: A standard, Trojan. Nothing custom. Nothing sophisticated.
The defender's failure: Fazio had no anti-malware protection that detected Citadel. And Target's vendor portal didn't require multi-factor authentication — a password alone was enough.
Stage 3: Initial Access
The attacker's move: Lateral movement. Once inside, they explored.
The defender's failure: Lack of network segmentation. The vendor portal should have been walled off from everything else. One compromised password shouldn't grant access to the entire network
Stage 4: Lateral Movement
Attackers moved from the vendor portal to Target's internal servers. They eventually reached a server that managed point-of-sale (POS) systems — the cash registers in every Target store.
On this server, they uploaded custom malware called BlackPOS. BlackPOS is designed to do one thing: scrape credit card data from memory the moment a card is swiped.
They pushed BlackPOS to POS terminals in over 1,800 Target stores across the United States.
The attacker's tool: Custom POS malware. But it relied on a common Windows vulnerability to spread.
The defender's failure: The POS server wasn't monitored for unauthorized access. New software appearing on POS terminals didn't trigger any alerts.
Stage 5: Collection and Exfiltration
For 19 days — from November 27 to December 15, 2013 — BlackPOS collected every credit card swiped at every infected terminal. The data was stored on a compromised server inside Target's network.
Then, the attackers moved the data out. They transferred 11 GB of stolen card numbers to a remote server.
The attacker's move: Staged exfiltration. Collect first, then move everything at once. Harder to detect than constant small transfers.
The defender's failure: Target's security software — a $1.6 million system from FireEye actually detected the exfiltration. It sent an alert. A team in Bangalore, India, saw the alert and flagged it. They forwarded it to Target's security team in Minneapolis.
Stage 6: Discovery
On December 12, 2013, the US Department of Justice notified Target that they'd found Target credit card numbers being sold on black market websites. Only then did Target realize they'd been breached.
On December 15, Target confirmed the breach. On December 19, they made it public.
For 19 days, the malware ran. For 19 days, alerts were ignored. For 19 days, 40 million credit cards walked out the door.
Why this Breach changed everything
The Target breach wasn't the biggest in history, but it was the most public. It changed how companies think about third-party risk:
- Vendor access is now scrutinized. Companies ask: "Who has access to our network, and how strong is THEIR security?"
- Network segmentation became mandatory. PCI DSS standards now require strict isolation of payment systems from the rest of the network.
- Alert fatigue became a known problem. FireEye did its job. The alert was real. But humans ignored it because there were too many alerts and not enough people to investigate them.
- Multi-factor authentication went mainstream. One password should never be enough to access a corporate network.