One-line: Attackers got into a giant retailer through a small heating-and-cooling vendor, then stole 40 million payment cards.
Customer payment-card data (about 40 million cards) and personal information for about 70 million more customers.
Two big weaknesses: a third-party vendor with network access, and no separation between that vendor’s access and Target’s payment systems.
Attackers sent a phishing email to Fazio Mechanical Services, an HVAC contractor. Stolen vendor credentials let the attackers into Target’s network in November 2013. Because the network was not segmented, they reached the point-of-sale systems and installed card-stealing malware that ran from November 27 to December 15, 2013. Target’s security tools flagged the malware, but the alerts were not acted on.
Confidentiality: payment-card and personal data were stolen.
About 40 million cards and 70 million customer records. Total costs exceeded 200 million dollars; Target agreed to an 18.5 million dollar multistate settlement in 2017.