← Case Files · The Breach Files
Target, 2013: 40 million cards, and the air-conditioning contractor
- People affected
- 40 million payment cards, 70 million customer records
- When it happened
- 27 November – 15 December 2013
- Made public
- 18 December 2013
- How they got in
- Stolen credentials belonging to a refrigeration contractor, then memory-scraping malware on the tills
- Attributed to
- Never publicly identified; the malware was a variant of BlackPOS
- What it cost
- Around $202 million gross; the chief executive and CIO both resigned
What was exposed: Card numbers · Expiry dates · CVVs from the magnetic stripe · PINs (encrypted) · Names · Addresses · Phone numbers · Email addresses
If you want one story that explains why every large company now runs a vendor security programme, this is it. The attackers who took 40 million card numbers out of Target during the 2013 Christmas shopping season did not start at Target. They started at a refrigeration contractor in Pennsylvania.
What happened
Fazio Mechanical Services supplied and maintained heating, ventilation and refrigeration systems for Target stores. Like many suppliers, it had a login to a Target-run web portal for billing, contracts and project management. In autumn 2013, someone sent Fazio a phishing email carrying a variant of Citadel — commodity password-stealing malware, sold openly on criminal forums. It worked, and the contractor's Target credentials went with it.
That portal was never meant to be a route into the store network. But the segmentation between the vendor-facing systems and the internal corporate network was not strong enough to keep an attacker out once they were inside with valid credentials, and from the corporate network the attackers found their way to the point-of-sale estate.
On 27 November 2013, the day before Thanksgiving and the start of the busiest shopping period of the American year, they pushed memory-scraping malware onto the tills.
How card scraping worked
Card data on a magnetic stripe is encrypted in transit and at rest. But at the moment the stripe is read, the terminal holds the track data in memory in the clear for a fraction of a second so it can process the transaction. That gap is what BlackPOS-family malware exists to exploit: it sits on the terminal, watches its own process memory for the pattern of a card track, and copies it out.
The stolen tracks were written to a file on an internal server, then moved out of the network in batches over the following two weeks — timed, according to the Senate committee's later analysis, to blend into normal business hours.
The alerts fired. Target had installed FireEye malware detection earlier that year, and it flagged the malicious software as it was deployed. Symantec's endpoint product flagged related activity too. The alerts reached a security operations team, and no one escalated them before the exfiltration began. This is the part worth remembering: the failure was not that Target had no detection. It was that detection without a response process is a log file nobody reads.
The timeline
- Autumn 2013 — Phishing malware steals Fazio Mechanical's Target portal credentials.
- 15 November — Attackers are inside Target's network, testing their access.
- 27 November — Card-scraping malware is live across the point-of-sale estate; capture begins.
- 30 November — FireEye alerts fire and are not escalated.
- 2–15 December — Stolen track data is exfiltrated in batches.
- 12 December — The US Department of Justice notifies Target that card data traced to its stores is appearing on carding markets.
- 15 December — Target removes the malware.
- 18 December — Brian Krebs publishes the story. Target confirms the following day.
- 10 January 2014 — Target discloses the additional 70 million customer records.
- March 2014 — CIO Beth Jacob resigns. May 2014 — Chief executive Gregg Steinhafel resigns.
- May 2017 — $18.5 million settlement with 47 states and the District of Columbia.
What it cost, and who paid
Target reported roughly $202 million in gross breach-related expenses across the following years, materially offset by insurance. Card issuers bore the cost of reissuing tens of millions of cards and recovered part of it through settlements with Visa and MasterCard. Consumers, in the main, were made whole on fraudulent transactions — card networks' liability rules are designed for exactly that — but spent the season cancelling cards and waiting for replacements.
The people who paid the highest personal price were the executives. A chief executive of a Fortune 50 retailer losing his job over an intrusion was new in 2014, and it is the reason the subject stopped being delegated downwards.
What it changed
Chip cards arrived in America. The United States had been an outlier: the rest of the developed world had moved to EMV chip cards years earlier, leaving the US magnetic stripe as the softest target on the planet. Target accelerated a rollout that was already planned, and the card networks brought forward the October 2015 liability shift that made whichever party had not adopted chip technology responsible for fraudulent transactions. Card-present fraud in the US fell sharply afterwards — and moved online, where it remains.
Vendor access became a controlled thing. Before Target, third-party portal accounts were plumbing. After it, they became an audited asset class: scoped credentials, network segmentation between vendor systems and everything else, and contractual security obligations that a refrigeration contractor is now expected to meet.
"We had alerts" stopped being a defence. The Senate committee's report walked through the intrusion as a kill chain and showed that Target had opportunities to break it at nearly every stage. That framing — where did detection exist, and why did it not produce a response — is now the standard shape of a post-incident review.
If you shopped there
The cards involved were reissued more than a decade ago, so the direct risk is long gone. The 70 million customer records — names, addresses, phone numbers, email addresses — are a different matter, because that information does not expire and has been folded into marketing and fraud datasets ever since.
- Treat unsolicited contact as unverified, always. The lasting value of a retail customer record is that it makes a scam call or message specific: the caller knows where you shop, where you live, and what you bought.
- Check your card statements line by line, monthly. Card fraud is usually detected by the cardholder, not the bank, and small test charges come before large ones.
- Prefer a payment method with a buffer — a credit card or a payment service — over anything drawn directly on your current account, so a disputed transaction is not money already gone.
Questions people ask
How did hackers get into Target?
Through Fazio Mechanical Services, a refrigeration and air-conditioning contractor. Malware delivered by a phishing email stole the contractor's credentials for a Target vendor portal, and from there the attackers found a route into the internal network and eventually onto the point-of-sale terminals.
How many people were affected by the Target breach?
Around 40 million payment cards were captured from the tills between 27 November and 15 December 2013, and a separate 70 million customer records — names, addresses, phone numbers and email addresses — were also taken. The two sets overlap, so the total number of individuals is somewhere between the two figures.
Did Target ignore warnings?
Its monitoring did generate alerts. Target had deployed FireEye, and the system flagged the malware as it was installed; the alerts went to a security operations team and were not acted on before the data started leaving. That detail — detection working and response failing — is why the case is taught as an operations failure rather than a technology one.
What did the Target breach cost?
Target reported gross breach-related expenses of around $202 million, partly offset by insurance. Settlements included $18.5 million with 47 US states in 2017, roughly $10 million to consumers, and payments to card issuers through Visa and MasterCard. The chief information officer resigned in March 2014 and the chief executive in May.
Sources
- US Senate Committee on Commerce, Science and Transportation — "A Kill Chain Analysis of the 2013 Target Data Breach", March 2014
- Target Corporation SEC filings and quarterly results, 2014–2015
- Multistate attorneys general settlement announcement, May 2017
- Contemporaneous reporting by Brian Krebs, who broke the story on 18 December 2013
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.