Back to the archive

The encyclopedia · Software & IT · Technical decision · 2013

Hackers got into Target through an air-conditioning vendor — and stole 40 million cards

In 2013 hackers used an HVAC vendor's credentials to breach Target, stealing 40 million card numbers and data on 70 million customers. The CEO resigned.

Target · 2013-12

What happened

In the 2013 holiday shopping season, the retailer Target suffered one of the largest data breaches in history. Attackers gained access not by breaking through Target's own defenses directly, but by stealing credentials from a third-party vendor that serviced Target's heating and air-conditioning systems. Through that vendor's access, the attackers moved into Target's network.

Once inside, the attackers installed malware on Target's point-of-sale systems and stole the credit and debit card numbers of about 40 million customers, along with personal information (names, addresses, emails) of about 70 million people. The breach went undetected for weeks, despite Target having security tools that had flagged the intrusion — alerts that were not acted on.

The fallout was severe. Target paid an $18.5 million multi-state settlement and a $10 million class-action settlement, spent hundreds of millions on remediation, and saw its sales and reputation damaged. Chief executive Gregg Steinhafel resigned in 2014. The breach became a landmark case in cybersecurity — a stark example of how a weak link in a supply chain, and ignored security alerts, can expose the data of tens of millions of customers.

Why it happened

  • Attackers entered Target's network through a third-party HVAC vendor's stolen credentials, exploiting a weak link in the supply chain.
  • Once inside, they installed malware on point-of-sale systems and stole 40 million card numbers and data on 70 million customers.
  • Target's security tools flagged the intrusion, but the alerts were not acted on, so the breach went undetected for weeks.
  • The breach cost Target hundreds of millions in settlements and remediation, damaged its sales and reputation, and led to the CEO's resignation.
What it cost40M cards stolen; hundreds of $ millions; CEO outcostly

The lesson

Your security is only as strong as your weakest vendor. Target was breached through an HVAC vendor's credentials, and its alerts were ignored. An alert no one acts on is no alert at all.

Aftermath

The Target breach was one of the largest in history and a landmark case in cybersecurity, exposing the data of tens of millions of customers through a third-party vendor's credentials and ignored alerts. It cost Target hundreds of millions in settlements and remediation, damaged its holiday sales and reputation, and led to the CEO's resignation. The lesson is durable: a company's security extends to every vendor with access to its network, and security tools are worthless if the alerts they generate are ignored — the breach you don't act on is the one that destroys you.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →