Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedReported

Target 2013 card breach traced to phishing of HVAC vendor Fazio Mechanical

Target Corporation · Retail · United States · December 2013

People or records affected
110,000,000
110.0M as reported

What happened

Attackers stole payment card data from Target point-of-sale terminals during the 2013 holiday season. Brian Krebs reported, and a US Senate Commerce Committee kill-chain analysis echoed, that the intrusion began with malware-laden emails sent to employees of Fazio Mechanical Services, a Pennsylvania HVAC contractor with access to Target's vendor portals. Roughly 40 million payment cards and personal data on about 70 million people were exposed.

How the deception worked

Criminals emailed malware to staff at Fazio Mechanical, a refrigeration and HVAC contractor. Investigators believed the payload was Citadel, a password-stealing derivative of the ZeuS banking trojan; Fazio ran a free anti-malware product without real-time protection. The stolen credentials let attackers log into Target's external vendor-facing systems (Ariba and Partners Online), from which they pivoted into the internal network, deployed memory-scraping malware to point-of-sale registers, and staged and exfiltrated track data from cards swiped in US stores.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Vendor portal accounts should be scoped to the billing and project functions they need, with no network path into card-processing segments, and third-party remote access should require phishing-resistant MFA.

Sources (3)

  1. Email Attack on Vendor Set Up Breach at Target
    Krebs on Security·krebsonsecurity.comOpen ↗
  2. A 'Kill Chain' Analysis of the 2013 Target Data Breach
    US Senate Committee on Commerce, Science, and Transportation·commerce.senate.govOpen ↗
  3. Target Breach: Phishing Attack Implicated
    Dark Reading·darkreading.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.