The encyclopedia · Software & IT · Technical decision · 2013
Hackers got into Target through an air-conditioning vendor — and stole 40 million cards
In 2013 hackers used an HVAC vendor's credentials to breach Target, stealing 40 million card numbers and data on 70 million customers. The CEO resigned.
Target · 2013-12
What happened
In the 2013 holiday shopping season, the retailer Target suffered one of the largest data breaches in history. Attackers gained access not by breaking through Target's own defenses directly, but by stealing credentials from a third-party vendor that serviced Target's heating and air-conditioning systems. Through that vendor's access, the attackers moved into Target's network.
Once inside, the attackers installed malware on Target's point-of-sale systems and stole the credit and debit card numbers of about 40 million customers, along with personal information (names, addresses, emails) of about 70 million people. The breach went undetected for weeks, despite Target having security tools that had flagged the intrusion — alerts that were not acted on.
The fallout was severe. Target paid an $18.5 million multi-state settlement and a $10 million class-action settlement, spent hundreds of millions on remediation, and saw its sales and reputation damaged. Chief executive Gregg Steinhafel resigned in 2014. The breach became a landmark case in cybersecurity — a stark example of how a weak link in a supply chain, and ignored security alerts, can expose the data of tens of millions of customers.
Why it happened
- Attackers entered Target's network through a third-party HVAC vendor's stolen credentials, exploiting a weak link in the supply chain.
- Once inside, they installed malware on point-of-sale systems and stole 40 million card numbers and data on 70 million customers.
- Target's security tools flagged the intrusion, but the alerts were not acted on, so the breach went undetected for weeks.
- The breach cost Target hundreds of millions in settlements and remediation, damaged its sales and reputation, and led to the CEO's resignation.
The lesson
Your security is only as strong as your weakest vendor. Target was breached through an HVAC vendor's credentials, and its alerts were ignored. An alert no one acts on is no alert at all.
Aftermath
The Target breach was one of the largest in history and a landmark case in cybersecurity, exposing the data of tens of millions of customers through a third-party vendor's credentials and ignored alerts. It cost Target hundreds of millions in settlements and remediation, damaged its holiday sales and reputation, and led to the CEO's resignation. The lesson is durable: a company's security extends to every vendor with access to its network, and security tools are worthless if the alerts they generate are ignored — the breach you don't act on is the one that destroys you.
Sources
- 2013 Target data breach — Wikipedia (40M cards, HVAC vendor, $18.5M settlement)
- DC Office of the Attorney General, 23 May 2017 — AG Racine Announces $18.5 Million Multistate Settlement with Target over 2013 Data Breach (46 states; 41M+ payment card accounts; stolen third-party vendor credentials)
spotted an error? The club wants to know.
More like this
A bad CrowdStrike update blue-screened 8.5M Windows PCs in the biggest IT outage ever
Equifax left a known software flaw unpatched — and exposed the data of 147 million people
Meta's 'designed for privacy' glasses shipped users' intimate footage to Kenya reviewers
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.