{
  "id": "case-target-hvac-breach",
  "slug": "target-corporation-hvac-breach",
  "title": "Target Corporation Point-of-Sale Data Breach (Fazio Mechanical Ingress)",
  "summary": "Landmark retail cyberattack where attackers penetrated Target internal corporate networks using stolen billing portal credentials from a third-party refrigeration and HVAC vendor, subsequently deploying BlackPOS memory scraping malware to steal 40 million credit card numbers and 70 million customer records.",
  "case_number": "0:14-md-02522",
  "court": "U.S. District Court for the District of Minnesota",
  "district": "D. Minn.",
  "country": "United States",
  "opened_at": "2014-04-02",
  "status": "settled",
  "victim_sector": "Retail, Financial Services",
  "victim_country": "United States",
  "loss_amount_usd": 292000000,
  "loss_amount_note": "Target reported $292 million in cumulative gross expenses from the breach, offset by $90 million in insurance recoveries.",
  "first_seen_at": "2013-11-27T00:00:00Z",
  "last_updated_at": "2026-08-10T14:00:00Z",
  "actor_slug": "resator-blackpos",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Attackers gained initial network entry using legitimate credentials stolen via a spearphishing email directed at Fazio Mechanical Services, an external HVAC contractor.",
      "evidence_locator": "Senate Commerce Committee Forensic Report, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Senate Commerce Committee Report on Target Breach",
      "source_url": "https://www.commerce.senate.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1056.001",
      "evidence_excerpt": "Operatives deployed a customized variant of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals to scrape payment card magnetic stripe tracks from process memory.",
      "evidence_locator": "US-CERT Advisory TA14-002A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory TA14-002A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/ta14-002a",
      "technique_name": "Keylogging",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1041",
      "evidence_excerpt": "Track 1 and Track 2 payment card data harvested from memory was temporarily staged on internal compromised servers before being batched and exfiltrated to compromised FTP servers in Russia and Brazil.",
      "evidence_locator": "Forensic Investigation Report, Section 4.2",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Target Special Litigation Committee Report",
      "source_url": "https://www.sec.gov",
      "technique_name": "Exfiltration Over C2 Channel",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2013-11-27",
      "description": "BlackPOS memory scraping malware begins collecting customer payment card data across Target cash registers."
    },
    {
      "event_type": "disclosure",
      "event_date": "2013-12-19",
      "description": "Target officially confirms unauthorized access to payment card data affecting approximately 40 million customer accounts."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Stolen electronic vendor credentials from Fazio Mechanical Services, a small heating and air conditioning (HVAC) contractor in Pennsylvania, compromised via a phishing email harboring Citadel malware.",
    "blast_radius": "Approximately 40 million credit and debit card records and 70 million customer personal records compromised. Target incurred $292 million in total gross breach expenses, executive resignations (CEO and CIO), and paid an $18.5 million multistate settlement.",
    "kill_chain": [
      {
        "phase": "Third-Party Vendor Ingress",
        "title": "Compromised Contractor Billing Credentials",
        "description": "Attackers infected an HVAC subcontractor with Citadel malware to harvest legitimate login credentials for Target vendor portal, which lacked multifactor authentication.",
        "technical_artifacts": [
          "Citadel banking trojan",
          "Vendor billing portal login"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Internal Lateral Traversal",
        "title": "Active Directory and Subnet Infiltration",
        "description": "Because the vendor portal was connected to Target's broader corporate network without microsegmentation, attackers traversed internal subnets to reach point-of-sale management servers.",
        "technical_artifacts": [
          "PsExec utility",
          "Internal administrative shares"
        ],
        "mitre_technique_id": "T1021.002"
      },
      {
        "phase": "Payload Deployment",
        "title": "BlackPOS Memory Scraper Rollout",
        "description": "Operatives deployed a customized version of BlackPOS (Kaptoxa) malware across thousands of cash register POS terminals during the Black Friday holiday shopping surge.",
        "technical_artifacts": [
          "BlackPOS / Kaptoxa executable",
          "POS-RAM scraper"
        ],
        "mitre_technique_id": "T1056.001"
      },
      {
        "phase": "Data Staging & Exfiltration",
        "title": "Internal FTP Staging and Multi-Hop Exfiltration",
        "description": "Scraped Track 1 and Track 2 magnetic stripe data was saved to internal staging servers and periodically pushed to external compromised FTP servers in Russia and Brazil.",
        "technical_artifacts": [
          "Internal FTP staging server",
          "Encrypted batch exfiltration"
        ],
        "mitre_technique_id": "T1041"
      }
    ],
    "defensive_takeaways": [
      "Strictly segregate third-party vendor portals from internal production and payment card processing networks.",
      "Deploy Point-to-Point Encryption (P2PE) on all cash register terminals so card data is never decrypted in system memory.",
      "Enforce multifactor authentication for 100% of vendor and supply chain access gateways.",
      "Configure real-time monitoring and alerting for unauthorized lateral connections into POS subnets."
    ]
  }
}