Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)
Key Facts
- Legal Status: SETTLED in U.S. District Court for the District of Minnesota.
- Primary Target Sector: Retail, Financial Services.
- Documented Financial Loss: $292.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Stolen electronic vendor credentials from Fazio Mechanical Services, a small heating and air conditioning (HVAC) contractor in Pennsylvania, compromised via a phishing email harboring Citadel malware.
Operational & Financial Fallout
Approximately 40 million credit and debit card records and 70 million customer personal records compromised. Target incurred $292 million in total gross breach expenses, executive resignations (CEO and CIO), and paid an $18.5 million multistate settlement.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Stolen electronic vendor credentials from Fazio Mechanical Services, a small heating and air conditioning (HVAC) contractor in Pennsylvania, compromised via a phishing email harboring Citadel malware.
Adversary Kill Chain Flow
4 Documented PhasesAttackers infected an HVAC subcontractor with Citadel malware to harvest legitimate login credentials for Target vendor portal, which lacked multifactor authentication.
Because the vendor portal was connected to Target's broader corporate network without microsegmentation, attackers traversed internal subnets to reach point-of-sale management servers.
Operatives deployed a customized version of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals during the Black Friday holiday shopping surge.
Scraped Track 1 and Track 2 magnetic stripe data was saved to internal staging servers and periodically pushed to external compromised FTP servers in Russia and Brazil.
Approximately 40 million credit and debit card records and 70 million customer personal records compromised. Target incurred $292 million in total gross breach expenses, executive resignations (CEO and CIO), and paid an $18.5 million multistate settlement.
Procedural & Incident Timeline
BlackPOS memory scraping malware begins collecting customer payment card data across Target cash registers.
Target officially confirms unauthorized access to payment card data affecting approximately 40 million customer accounts.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Attackers gained initial network entry using legitimate credentials stolen via a spearphishing email directed at Fazio Mechanical Services, an external HVAC contractor." | Senate Commerce Committee Forensic Report, Page 12 | reviewed |
| T1056.001 | Keylogging Credential Access | "Operatives deployed a customized variant of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals to scrape payment card magnetic stripe tracks from process memory." | US-CERT Advisory TA14-002A | reviewed |
| T1041 | Exfiltration Over C2 Channel Exfiltration | "Track 1 and Track 2 payment card data harvested from memory was temporarily staged on internal compromised servers before being batched and exfiltrated to compromised FTP servers in Russia and Brazil." | Forensic Investigation Report, Section 4.2 | reviewed |