{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic"},"incident":{"title":"Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical","date":"2013-12","date_precision":"month","victim_org":"Target Corporation","sector":"Retail","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Target reported cumulative gross breach expenses in the hundreds of millions of dollars across later filings; the sources cited here do not itemise a single figure, so no dollar value is asserted.","records_affected":110000000,"threat_actor":null,"summary":"Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.","how_it_worked":"Criminals emailed malware to staff at Fazio Mechanical, a refrigeration and HVAC contractor. Investigators believed the payload was Citadel, a password-stealing derivative of the ZeuS banking trojan; Fazio ran a free anti-malware product without real-time protection. The stolen credentials let attackers log into Target's external vendor-facing systems (Ariba and Partners Online), from which they pivoted into the internal network, deployed memory-scraping malware to point-of-sale registers, and staged and exfiltrated track data from cards swiped in US stores.","lessons":"Vendor portal accounts should be scoped to the billing and project functions they need, with no network path into card-processing segments, and third-party remote access should require phishing-resistant MFA.","confidence":"Reported","sources":[{"title":"Email Attack on Vendor Set Up Breach at Target","url":"https://krebsonsecurity.com/2014/02/email-attack-on-vendor-set-up-breach-at-target/","publisher":"Krebs on Security"},{"title":"A 'Kill Chain' Analysis of the 2013 Target Data Breach","url":"https://www.commerce.senate.gov/services/files/24d3c229-4f2f-405d-b8db-a3a67f183883","publisher":"US Senate Committee on Commerce, Science, and Transportation"},{"title":"Target Breach: Phishing Attack Implicated","url":"https://www.darkreading.com/cyberattacks-data-breaches/target-breach-phishing-attack-implicated","publisher":"Dark Reading"}],"entry_type":"incident","slug":"2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic","year":2013,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2013-target-2013-card-breach-traced-to-phishing-of-hvac-vendor-fazio-mechanic"}}