Student Name: Galinato Mark Ian N.
Target Organization: Target Corporation
Date of Incident: November – December 2013
I. The Breach Profile
This was a massive Phishing and POS (Point-of-Sale) Malware attack
that lasted about three weeks during the 2013 holiday season. It was a
"supply chain" hit where hackers used a vendor's credentials to get inside.
The scale was huge: 40 million credit cards were stolen, along with the
personal data of 70 million customers.
II. The Technical Breakdown
The Entry Point (Vector): Hackers stole login info from a third-
party HVAC vendor. Because Target hadn’t segmented their
network, the attackers were able to jump from the vendor's billing
portal straight into the internal systems that run the cash registers.
The Goal: Purely financial. They wanted to "scrape" credit card data
in real-time as customers swiped their cards so they could sell that info
on the dark web.
III. Impact Assessment
Data Stolen: 40 million payment cards and 70 million records of
names, addresses, and phone numbers.
Consequences: Target paid an $18.5 million settlement and faced
over $200 million in total losses. It also led to the resignation of
both their CEO and CIO after a massive drop in public trust.
IV. Preventive Measures
Network Segmentation: Keep the "public" or vendor-facing parts of
the network completely separate from the "private" payment systems.
Multi-Factor Authentication (MFA): Requiring more than just a
password for outside vendors to log in.
Real-time Monitoring: Target’s security software actually flagged the
malware, but the team didn't act. Security alerts need to be actively
managed and escalated immediately.
Zero Trust: Treating every user—even a trusted vendor—as a
potential risk that needs constant verification.