☰Series Navigation (13 parts)
Every article in this series so far has involved a nation. The United States, Israel, Russia, intelligence agencies with billion-dollar budgets and years to spend. It would be easy to file the whole subject under “problems for governments” and move on. This article exists to close that exit, because the same attack that took down a nuclear plant and the U.S. Treasury also took down a store’s cash registers, and it got in through the heating guy.
If you run any kind of organization, this is the one that’s about you.
What was the Target breach?
In late 2013, during the Christmas shopping rush, attackers installed malicious software on the checkout systems in Target stores across the country. As customers swiped their cards to pay, the malware scraped the card data straight out of the register’s memory and sent it out to be collected and sold. By the time it was stopped, around 40 million payment cards had been compromised, along with personal information, names, addresses, phone numbers, emails, for as many as 70 million people.
The fallout was enormous. Banks reissued millions of cards. Target faced a wave of lawsuits and a bill that ran well past a hundred million dollars once settlements and response costs were counted. Both the CEO and the chief information officer eventually lost their jobs. For a while, Target was the public face of the corporate data breach, the cautionary tale every board in America suddenly wanted to understand.
And the way in had nothing to do with cash registers.
How did attackers get into Target through an HVAC company?
Here is the chain, and every link in it is ordinary.
Target, like every large company, works with outside vendors, and it gives some of them limited access to its systems to do their jobs. One of those vendors was Fazio Mechanical Services, a small heating, ventilation, and air conditioning contractor in Pennsylvania. Fazio had legitimate access to a Target vendor portal for the boring business of billing, contracts, and project management. There is nothing unusual about that. Refrigeration and climate control matter to a retailer, and the contractor needs a way to submit invoices and coordinate work.
The attackers started with Fazio, not Target. They sent the contractor a phishing email carrying password-stealing malware, and it worked, reportedly in part because the small company was relying on a free consumer antivirus tool not meant for business protection. With that malware in place, the attackers harvested Fazio’s login credentials for the Target vendor portal.
Now they had a legitimate way into Target’s network, wearing the identity of a trusted vendor. From that vendor portal, they worked their way deeper, moving from the system meant for contractors into Target’s internal network, escalating their access until they could reach the systems that ran the point-of-sale registers. Then they pushed their card-scraping malware out to those registers across nearly 1,800 stores and started collecting.
Read that path again. The people who serviced the air conditioning became the road to the credit card numbers of 40 million shoppers. Nobody at Target decided to give the HVAC contractor access to the cash registers. They gave the contractor access to a billing portal, and the network was built so that a foothold in one corner could be walked, step by step, all the way to the most sensitive systems in the company.
Why is a vendor with limited access still a serious risk?
Because access is not the boundary people imagine it is, and this is the lesson I spent years trying to get across in real companies.
When you grant a vendor limited access, you picture a small, contained room. What you opened is a door into your building, and what matters is not the size of the room behind that door but whether someone who gets through it can then move into the rest of the building. At Target, the door for a billing portal turned out to connect, through a series of steps, to the payment systems. The access granted was narrow. The access achievable was not.
And here is the thread that ties Target to Crypto AG and the Hezbollah pagers and every poisoned update in this series: you inherit your vendor’s security. Fazio Mechanical was a small contractor that had every reason to focus on refrigeration and no particular reason to run an enterprise-grade security program.
The moment Target connected its network to Fazio’s, Fazio’s weaker security became part of Target’s attack surface. Target could have the best defenses in retail and it wouldn’t matter, because the attacker didn’t attack Target’s defenses. It attacked the heating company and walked in through a door Target had opened on purpose.
Every organization has a Fazio. The cleaning service with a login to the building system. The small software vendor whose tool runs on your servers. The marketing agency with access to your customer list. The bookkeeper with the keys to the finances. Each one is a door, and each one comes with that vendor’s security posture attached, whether you’ve ever looked at it or not.
Target’s alarms went off. Why didn’t it matter?
This detail turns the story from a failure of prevention into a failure of something worse.
Target was not defenseless. It had spent money on a serious threat-detection system, and the system worked. When the attackers’ malware went active, the system generated alerts. It saw the thing happening and it said so. The alarms fired.
Nobody acted on them. The warnings were generated and, by the accounts that followed, investigated and then not escalated to anyone who stopped the attack. For roughly three weeks, card data poured out of Target’s registers while the alerts that could have ended it sat unaddressed. In the end, Target didn’t catch the breach through its own response at all. An outside payment processor noticed fraud patterns and came to Target, weeks into the theft.
I spent twenty years in operations, and this is the failure that I find least forgivable and most common. Detection without response is not security. It is theater. An alarm that no one answers is worse than no alarm, because it lets you believe you’re protected while the building burns.
Buying the tool is the easy part, and companies love buying tools because it feels like action. The hard part, the part nobody wants to fund, is the boring human machinery of watching the alerts, knowing what they mean, and having a plan for what to do when one fires at two in the morning. Target had the smoke detector. It had disconnected the part where somebody calls the fire department.
What should any organization take from the Target breach?
Three things, and they cost attention more than money.
Map your vendors as attack surface, the way an attacker sees them, instead of only as business relationships. Every outside party with any access to your systems is a potential path in, and their security is now your security. You need to know who they are, what they can reach, and how seriously they take their own defense. Most organizations cannot even produce a complete list. That gap is the first problem.
Segment your network so a foothold isn’t a conquest. The reason a billing portal reached the cash registers is that the path existed. Systems that don’t need to talk to each other should not be able to, so that an attacker who gets into one corner is trapped there instead of free to roam. This is a design decision made on a calm day, and it is the single thing that most often decides whether an incident is contained or catastrophic.
Fund the response, not the detection alone. An alert nobody answers bought you nothing. If you’re going to spend on tools that watch for intruders, you have to spend at least as much on the people and the plans that turn an alert into an action. The alarm is the cheap part. Answering it is the job.
The next article is the strangest one in this series: a backdoor that a single volunteer spent two years earning the trust to plant in software running on much of the internet, caught by pure luck days before it spread. For the wider view of security and the executives and writers who need to understand it, the cybersecurity hub collects the rest of my work on this.
Frequently Asked Questions
Continue the Series
1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI
