A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network and plant POS malware, exposing ~40M payment cards and ~70M customer records.
Reviewed by the Social Engineering Examples team.
In late 2013, attackers stole payment-card and personal data from Target during the holiday shopping season. Investigators and a US Senate Commerce Committee staff report ("A 'Kill Chain' Analysis of the 2013 Target Data Breach") concluded the intrusion began not at Target directly but at a third party: Fazio Mechanical Services, a small Sharpsburg, PA refrigeration/HVAC contractor. Fazio had remote access to Target's systems strictly for electronic billing, contract submission, and project management (via portals a former Target insider identified as Ariba and Partners Online). KrebsOnSecurity broke the vendor angle, and sources said Fazio was compromised by a malware-laced phishing email at least about two months before the Target card theft, with the malware reported (unconfirmed) as Citadel, a password-stealing bot derived from the Zeus banking trojan. Attackers used the harvested vendor credentials to reach Target's network, moved laterally into more sensitive systems, and planted RAM-scraping malware on point-of-sale terminals. Target has confirmed the breach exposed ~40M card accounts (Nov 27-Dec 15, 2013) and ~70M records of customer PII, and publicly acknowledged the breach on Dec 19, 2013. Several details (the specific Citadel malware, the exact lateral-movement path from the billing portal into the POS environment) remain reported-but-unconfirmed in public sources; the core facts (vendor-credential origin, phishing vector, card/PII counts, costs) are corroborated by Target SEC filings, the Senate report, Fazio's own statement, and settlement documents.
This was a supply-chain compromise that began with commodity, non-targeted email phishing. Security researchers noted the attack on Fazio most likely started as a broad "shotgun" malware-spam blast rather than a bespoke spear-phish; once the criminals reviewed the pool of infected machines, they realized one victim (Fazio) had a business relationship with Target and prioritized it. Password-stealing malware on Fazio's systems captured the vendor's Target-portal login. Because those credentials were legitimate, they let the attackers slip past the perimeter as a trusted vendor. From that foothold the attackers moved laterally: the Senate report faults Target for not requiring two-factor authentication for low-privilege vendors, not adequately isolating sensitive cardholder systems from the vendor-facing portal, and ignoring automated intrusion alerts. Attackers then deployed RAM-scraping POS malware to harvest card data from live transactions and exfiltrated it out of the network. Krebs also documented that Target left extensive vendor documentation on public, login-free web pages, whose file metadata could help an attacker map internal Windows domains and usernames for reconnaissance.
Lure: a routine-looking business email carrying a malicious attachment (reported as likely a PDF or Office document) sent to employees at the HVAC vendor. The "tell" for the vendor was largely invisible because detection was so weak: Fazio's primary anti-malware was reported to be the free, consumer version of Malwarebytes, which does not provide real-time protection. General warning signs of this pattern: unexpected attachments to staff, reliance on free/consumer-grade endpoint tools in a business, vendor accounts with broad or poorly segmented network access, and absence of multifactor authentication on vendor logins.
~40M payment cards and ~70M PII records exposed; Target's CEO and CIO later departed; the company faced congressional scrutiny, a Senate staff "kill chain" report, and years of litigation. Financial outcomes included cumulative gross breach costs of about $292M (net ~$202M after insurance recoveries), an $18.5M multistate AG settlement (2017), a ~$10M consumer class settlement (2015), and separate settlements with banks and card networks. The incident became a landmark case for third-party/vendor risk and network segmentation.
It is the canonical example of how a security failure at a small, low-profile supplier can cascade into one of the largest retail breaches in history. The initial vector was ordinary mass phishing, not a sophisticated targeted attack, which underscores that any vendor with network access expands an enterprise's attack surface. It drove mainstream adoption of vendor-risk management, least-privilege vendor access, network segmentation, and MFA for third parties, and accelerated the US shift to chip (EMV) cards.
Enforce multifactor authentication for all vendor and remote logins; grant vendors least-privilege access and segment vendor-facing portals from cardholder/POS environments; monitor for anomalous use of vendor credentials in unrelated network areas; require and verify baseline security (real-time, business-grade endpoint protection, patching, phishing training) in vendor contracts; act on automated intrusion/malware alerts rather than suppressing them; limit publicly exposed internal documentation and strip revealing file metadata; deploy phishing-resistant email defenses and user reporting; use POS hardening and file-integrity monitoring to detect RAM-scraping malware.
A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…