CASE DOSSIER settled

Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)

Docket: 0:14-md-02522 Court: U.S. District Court for the District of Minnesota Opened: 2014-04-02 Sector: Retail, Financial Services

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$292.0 million
Target reported $292 million in cumulative gross expenses from the breach, offset by $90 million in insurance recoveries.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in U.S. District Court for the District of Minnesota.
  • Primary Target Sector: Retail, Financial Services.
  • Documented Financial Loss: $292.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Landmark retail cyberattack where attackers penetrated Target internal corporate networks using stolen billing portal credentials from a third-party refrigeration and HVAC vendor, subsequently deploying BlackPOS memory scraping malware to steal 40 million credit card numbers and 70 million customer records.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Stolen electronic vendor credentials from Fazio Mechanical Services, a small heating and air conditioning (HVAC) contractor in Pennsylvania, compromised via a phishing email harboring Citadel malware.

Operational & Financial Fallout

Approximately 40 million credit and debit card records and 70 million customer personal records compromised. Target incurred $292 million in total gross breach expenses, executive resignations (CEO and CIO), and paid an $18.5 million multistate settlement.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Stolen electronic vendor credentials from Fazio Mechanical Services, a small heating and air conditioning (HVAC) contractor in Pennsylvania, compromised via a phishing email harboring Citadel malware.

Adversary Kill Chain Flow

4 Documented Phases
1
Third-Party Vendor Ingress Compromised Contractor Billing Credentials
MITRE ATT&CK T1078 →

Attackers infected an HVAC subcontractor with Citadel malware to harvest legitimate login credentials for Target vendor portal, which lacked multifactor authentication.

Artifacts & Tooling: Citadel banking trojan Vendor billing portal login
2
Internal Lateral Traversal Active Directory and Subnet Infiltration
MITRE ATT&CK T1021.002 →

Because the vendor portal was connected to Target's broader corporate network without microsegmentation, attackers traversed internal subnets to reach point-of-sale management servers.

Artifacts & Tooling: PsExec utility Internal administrative shares
3
Payload Deployment BlackPOS Memory Scraper Rollout
MITRE ATT&CK T1056.001 →

Operatives deployed a customized version of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals during the Black Friday holiday shopping surge.

Artifacts & Tooling: BlackPOS / Kaptoxa executable POS-RAM scraper
4
Data Staging & Exfiltration Internal FTP Staging and Multi-Hop Exfiltration
MITRE ATT&CK T1041 →

Scraped Track 1 and Track 2 magnetic stripe data was saved to internal staging servers and periodically pushed to external compromised FTP servers in Russia and Brazil.

Artifacts & Tooling: Internal FTP staging server Encrypted batch exfiltration
Real-World Blast Radius & Operational Fallout

Approximately 40 million credit and debit card records and 70 million customer personal records compromised. Target incurred $292 million in total gross breach expenses, executive resignations (CEO and CIO), and paid an $18.5 million multistate settlement.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Strictly segregate third-party vendor portals from internal production and payment card processing networks.
✓ Deploy Point-to-Point Encryption (P2PE) on all cash register terminals so card data is never decrypted in system memory.
✓ Enforce multifactor authentication for 100% of vendor and supply chain access gateways.
✓ Configure real-time monitoring and alerting for unauthorized lateral connections into POS subnets.

Procedural & Incident Timeline

2013-11-27 incident

BlackPOS memory scraping malware begins collecting customer payment card data across Target cash registers.

2013-12-19 disclosure

Target officially confirms unauthorized access to payment card data affecting approximately 40 million customer accounts.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Attackers gained initial network entry using legitimate credentials stolen via a spearphishing email directed at Fazio Mechanical Services, an external HVAC contractor." Senate Commerce Committee Forensic Report, Page 12 reviewed
T1056.001 Keylogging
Credential Access
"Operatives deployed a customized variant of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals to scrape payment card magnetic stripe tracks from process memory." US-CERT Advisory TA14-002A reviewed
T1041 Exfiltration Over C2 Channel
Exfiltration
"Track 1 and Track 2 payment card data harvested from memory was temporarily staged on internal compromised servers before being batched and exfiltrated to compromised FTP servers in Russia and Brazil." Forensic Investigation Report, Section 4.2 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress), No. 0:14-md-02522 (U.S. District Court for the District of Minnesota 2014), https://cybercaselibrary.com/cases/target-corporation-hvac-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/target-corporation-hvac-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>