← Case Files · The Breach Files

2013 · Retail

Target, 2013: 40 million cards, and the air-conditioning contractor

Case file · 4 min read · Published 14 September 2026

People affected
40 million payment cards, 70 million customer records
When it happened
27 November – 15 December 2013
Made public
18 December 2013
How they got in
Stolen credentials belonging to a refrigeration contractor, then memory-scraping malware on the tills
Attributed to
Never publicly identified; the malware was a variant of BlackPOS
What it cost
Around $202 million gross; the chief executive and CIO both resigned

What was exposed: Card numbers · Expiry dates · CVVs from the magnetic stripe · PINs (encrypted) · Names · Addresses · Phone numbers · Email addresses

If you want one story that explains why every large company now runs a vendor security programme, this is it. The attackers who took 40 million card numbers out of Target during the 2013 Christmas shopping season did not start at Target. They started at a refrigeration contractor in Pennsylvania.

What happened

Fazio Mechanical Services supplied and maintained heating, ventilation and refrigeration systems for Target stores. Like many suppliers, it had a login to a Target-run web portal for billing, contracts and project management. In autumn 2013, someone sent Fazio a phishing email carrying a variant of Citadel — commodity password-stealing malware, sold openly on criminal forums. It worked, and the contractor's Target credentials went with it.

That portal was never meant to be a route into the store network. But the segmentation between the vendor-facing systems and the internal corporate network was not strong enough to keep an attacker out once they were inside with valid credentials, and from the corporate network the attackers found their way to the point-of-sale estate.

On 27 November 2013, the day before Thanksgiving and the start of the busiest shopping period of the American year, they pushed memory-scraping malware onto the tills.

How card scraping worked

Card data on a magnetic stripe is encrypted in transit and at rest. But at the moment the stripe is read, the terminal holds the track data in memory in the clear for a fraction of a second so it can process the transaction. That gap is what BlackPOS-family malware exists to exploit: it sits on the terminal, watches its own process memory for the pattern of a card track, and copies it out.

The stolen tracks were written to a file on an internal server, then moved out of the network in batches over the following two weeks — timed, according to the Senate committee's later analysis, to blend into normal business hours.

The alerts fired. Target had installed FireEye malware detection earlier that year, and it flagged the malicious software as it was deployed. Symantec's endpoint product flagged related activity too. The alerts reached a security operations team, and no one escalated them before the exfiltration began. This is the part worth remembering: the failure was not that Target had no detection. It was that detection without a response process is a log file nobody reads.

The timeline

  1. Autumn 2013 — Phishing malware steals Fazio Mechanical's Target portal credentials.
  2. 15 November — Attackers are inside Target's network, testing their access.
  3. 27 November — Card-scraping malware is live across the point-of-sale estate; capture begins.
  4. 30 November — FireEye alerts fire and are not escalated.
  5. 2–15 December — Stolen track data is exfiltrated in batches.
  6. 12 December — The US Department of Justice notifies Target that card data traced to its stores is appearing on carding markets.
  7. 15 December — Target removes the malware.
  8. 18 December — Brian Krebs publishes the story. Target confirms the following day.
  9. 10 January 2014 — Target discloses the additional 70 million customer records.
  10. March 2014 — CIO Beth Jacob resigns. May 2014 — Chief executive Gregg Steinhafel resigns.
  11. May 2017 — $18.5 million settlement with 47 states and the District of Columbia.

What it cost, and who paid

Target reported roughly $202 million in gross breach-related expenses across the following years, materially offset by insurance. Card issuers bore the cost of reissuing tens of millions of cards and recovered part of it through settlements with Visa and MasterCard. Consumers, in the main, were made whole on fraudulent transactions — card networks' liability rules are designed for exactly that — but spent the season cancelling cards and waiting for replacements.

The people who paid the highest personal price were the executives. A chief executive of a Fortune 50 retailer losing his job over an intrusion was new in 2014, and it is the reason the subject stopped being delegated downwards.

What it changed

Chip cards arrived in America. The United States had been an outlier: the rest of the developed world had moved to EMV chip cards years earlier, leaving the US magnetic stripe as the softest target on the planet. Target accelerated a rollout that was already planned, and the card networks brought forward the October 2015 liability shift that made whichever party had not adopted chip technology responsible for fraudulent transactions. Card-present fraud in the US fell sharply afterwards — and moved online, where it remains.

Vendor access became a controlled thing. Before Target, third-party portal accounts were plumbing. After it, they became an audited asset class: scoped credentials, network segmentation between vendor systems and everything else, and contractual security obligations that a refrigeration contractor is now expected to meet.

"We had alerts" stopped being a defence. The Senate committee's report walked through the intrusion as a kill chain and showed that Target had opportunities to break it at nearly every stage. That framing — where did detection exist, and why did it not produce a response — is now the standard shape of a post-incident review.

If you shopped there

The cards involved were reissued more than a decade ago, so the direct risk is long gone. The 70 million customer records — names, addresses, phone numbers, email addresses — are a different matter, because that information does not expire and has been folded into marketing and fraud datasets ever since.

  1. Treat unsolicited contact as unverified, always. The lasting value of a retail customer record is that it makes a scam call or message specific: the caller knows where you shop, where you live, and what you bought.
  2. Check your card statements line by line, monthly. Card fraud is usually detected by the cardholder, not the bank, and small test charges come before large ones.
  3. Prefer a payment method with a buffer — a credit card or a payment service — over anything drawn directly on your current account, so a disputed transaction is not money already gone.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

How did hackers get into Target?

Through Fazio Mechanical Services, a refrigeration and air-conditioning contractor. Malware delivered by a phishing email stole the contractor's credentials for a Target vendor portal, and from there the attackers found a route into the internal network and eventually onto the point-of-sale terminals.

How many people were affected by the Target breach?

Around 40 million payment cards were captured from the tills between 27 November and 15 December 2013, and a separate 70 million customer records — names, addresses, phone numbers and email addresses — were also taken. The two sets overlap, so the total number of individuals is somewhere between the two figures.

Did Target ignore warnings?

Its monitoring did generate alerts. Target had deployed FireEye, and the system flagged the malware as it was installed; the alerts went to a security operations team and were not acted on before the data started leaving. That detail — detection working and response failing — is why the case is taught as an operations failure rather than a technology one.

What did the Target breach cost?

Target reported gross breach-related expenses of around $202 million, partly offset by insurance. Settlements included $18.5 million with 47 US states in 2017, roughly $10 million to consumers, and payments to card issuers through Visa and MasterCard. The chief information officer resigned in March 2014 and the chief executive in May.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →