the Target breach (2013)
loresecuritygovernance & risk
The 2013 holiday-season compromise of about 40 million payment cards and 70 million customer records at the US retailer Target, entered through credentials stolen from a heating and air-conditioning contractor with remote access to the corporate network.
It is the case that made third-party risk and network segmentation board-level topics: an HVAC vendor's account had no business being able to reach point-of-sale systems. Detection failed at the last step - the monitoring tools fired alerts that nobody actioned - which is the more uncomfortable half of the story, since the controls worked and the process did not. The chief executive resigned, one of the first times a breach visibly ended a career at that level.
Also known as: hvac vendor breach, 40 million cards, pos malware