Skip to content
Security Notes

Target's HVAC vendor: ten years of third-party access lessons

By Elias Lankinen11 min read

I have thorough, well-sourced material. Now I'll write the post.

The thermostat that wasn't

Here is the detail that almost everyone gets wrong about the most famous retail hack in American history: the burglars did not come in through the air conditioning. The story people remember is tidy and a little absurd. In late 2013, thieves stole 40 million payment cards from Target by hacking its heating and cooling system, presumably wiggling from a smart thermostat into the cash registers. It is a good story. It is also mostly false. The vendor at the center of the breach, a Pennsylvania refrigeration contractor called Fazio Mechanical Services, did not remotely monitor or control a single Target thermostat. Its digital connection to Target was, in Fazio's own words after the attack, "exclusively for electronic billing, contract submission and project management". That correction is the whole point. The lesson of Target was never about HVAC. It was about the invisible web of outside companies that every large organization hands a set of keys to, and how one of those keys, issued to a firm that fixed refrigerators, became the way into the checkout lanes of roughly 1,800 stores. More than a decade later, that lesson has only grown teeth.

Source: Jay Reed via Wikimedia Commons
Source: Jay Reed via Wikimedia Commons

How it actually happened

The intrusion did not begin at Target. It began with a phishing email sent to employees at Fazio Mechanical, a heating, air conditioning and refrigeration firm in Sharpsburg, a small borough outside Pittsburgh. According to security journalist Brian Krebs, who broke most of the story, the email carried malware, and the strain investigators pointed to was Citadel. Citadel is a "password-stealing bot," a descendant of the ZeuS banking trojan built specifically to harvest login credentials from infected machines. It sat on Fazio's systems and quietly collected the usernames and passwords the company used to do business with its clients. Fazio's defenses were thin. Krebs reported that the company was running the free version of Malwarebytes Anti-Malware. That product is a competent on-demand scanner, but the free tier does not offer real-time protection, meaning it only catches malware when someone manually runs a scan, and its license explicitly prohibits corporate use. A machine protected that way can host a credential-stealer for weeks without anyone noticing. The infection appears to have started at least two months before card data began leaving Target's registers. With Fazio's credentials in hand, the attackers logged into Target's vendor-facing portals. Contractors reached Target through an external billing system called Ariba and a project-management and contract portal called Partners Online. These were legitimate doors, opened with legitimate keys. The problem was what lay on the other side. From that vendor beachhead, the attackers moved. This is the part the "HVAC hack" myth obscures: a billing portal should have no pathway to a cash register. In Target's network, one existed. Investigators later concluded the intruders escalated their privileges, likely abusing Active Directory, the directory service that manages accounts and permissions across a Windows network, until they could reach the systems that processed payments. A Gartner analyst put the failure bluntly to Krebs: "if they thought their network was properly segmented, they wouldn't have needed to have two-factor access for everyone" and yet the segmentation clearly failed to hold.

Scraping the registers

Between roughly November 15 and November 28, 2013, the attackers uploaded malware to Target's point-of-sale devices, the terminals where customers swipe cards. By the end of that stretch it had reached most of the fleet. The malware was a "RAM scraper," and the name describes exactly what it does. When you swipe a card, the terminal must briefly hold the card number in the clear, in memory, in order to process the transaction. Even if that data is encrypted when stored and encrypted when transmitted, there is a fraction of a second when it exists as plain text in RAM. The scraper reads memory during that window and copies the numbers before they can be re-encrypted. It is a clever end run around encryption: you do not break the lock, you photograph the contents while the door is briefly open. For nearly three weeks, from November 27 to December 15, 2013, the scrapers harvested card data from essentially every swipe across Target's U.S. stores. The stolen numbers were funneled to "drop" servers the attackers had compromised, staging points in Miami and Brazil, before being pulled onward to operators in Eastern Europe. In the end, Target disclosed roughly 40 million payment card accounts stolen and separate personal information, names, addresses, phone numbers and email addresses, for as many as 70 million people.

The alarms nobody answered

Here is the second thing people misremember. Target was not blind. Its systems saw the attack, more than once, and did nothing. Six months before the breach, Target had installed software from FireEye, a well-regarded threat-detection company, and it worked. According to the Senate Commerce Committee's "kill chain" analysis of the breach, published in March 2014 under then-chairman Jay Rockefeller, FireEye flagged the exfiltration malware on November 30 and again on December 2. The alerts were detailed. They identified the malware, and in some accounts even named the staging servers and included the usernames and passwords the attackers were using. Target had a security operations team in Bangalore, India, watching those alerts around the clock. The Bangalore team saw them and escalated to the security center in Minneapolis. And there the chain broke: Minneapolis did not act. FireEye also had a feature that could automatically delete detected malware, and Target's team had turned it off, preferring to keep humans in the loop. The humans did not move. Anti-virus software from Symantec reportedly flagged suspicious activity on the same servers around the same time. The signal was there, repeatedly, in bright red. The organization simply failed to respond to it. Target did not learn it had been robbed from its own tools. It learned on December 12, when the U.S. Secret Service contacted the company after the banking industry traced a wave of fraudulent charges back to a common point of purchase. Target went public on December 19, in the middle of the Christmas shopping season.

What it cost, and who paid

The financial reckoning stretched on for years, and the numbers are worth stating precisely because they are so often blurred. The figure people cite most, $18.5 million, was not the cost of the breach. It was a single 2017 settlement with 47 states and the District of Columbia, announced by the New York attorney general as the largest multistate data-breach settlement reached to that point. It was one line item among many. Target separately paid about $39 million to settle claims from banks and credit unions that had to reissue cards in 2015, and roughly $10 million to affected consumers. Add it all up and the picture is larger. In its 2017 annual filing, Target reported $292 million in cumulative breach-related expenses, offset by about $90 million in insurance recoveries, for a net cost north of $200 million. And that excludes the harder-to-quantify damage: a sales slump the following quarter, and a collapse of consumer trust during the busiest weeks of the retail year. The human cost at the top was also real. CIO Beth Jacob resigned in March 2014, and in May, chairman, president and CEO Gregg Steinhafel stepped down after 35 years at the company, one of the first times a major American CEO lost his job directly over a cyberattack. That precedent, that a breach could end a career at the very top, changed how boardrooms talked about security.

The lesson that outlived the headline

Strip away the specifics and Target taught one durable thing: your security perimeter is only as strong as the weakest organization you have given access to. Every vendor with a login, an API key, or a network connection is an extension of your attack surface, whether or not you think of them that way. Fazio was a refrigeration contractor. Nobody at Target lost sleep over a refrigeration contractor. That was precisely the blind spot the attackers walked through. The concrete failures line up as a checklist of what not to do:

  1. Excessive access. A billing vendor could reach systems adjacent to payment processing. Access should have been scoped to exactly what Fazio needed and nothing more, the principle security engineers call least privilege.
  2. Weak segmentation. The network let an intruder pivot from a vendor portal toward point-of-sale systems. Payment-card standards (PCI DSS) require isolating the cardholder-data environment; Target's isolation did not hold.
  3. No vendor vetting. Fazio's use of a free, non-real-time anti-malware tool was a red flag that no one at Target was in a position to see, because no one was checking.
  4. Ignored alerts. The best detection tooling in the world is worthless if the humans behind it do not act on what it reports. None of these are exotic. They are the unglamorous fundamentals of security, and the reason Target became a case study taught in business schools and Senate hearings alike is that a company with a real security budget got the fundamentals wrong in a way that was entirely preventable.
Source: Fleshas / BalticServers.com via Wikimedia Commons
Source: Fleshas / BalticServers.com via Wikimedia Commons

A decade on: the problem got bigger

If Target were a one-off, we could file it under history. It is not. The third-party access problem it exposed has become the dominant story in data breaches, and the numbers have moved in the wrong direction. Verizon's annual Data Breach Investigations Report is the closest thing the industry has to a census. Its 2025 edition found that the share of breaches involving a third party had doubled, from 15 percent to 30 percent, year over year, with stolen credentials and unpatched vulnerabilities the leading ways in. The vector that beat Target, an outside party's access turned against the target, is now implicated in nearly a third of all breaches and, by some later counts, closer to half. Two incidents since Target show how the shape of the problem has evolved. The first is SolarWinds in 2020. Attackers, later attributed by the U.S. government to Russian intelligence, compromised the build process of SolarWinds' Orion network-management software and hid malicious code inside a routine update. Roughly 18,000 organizations installed the poisoned update, including U.S. federal agencies. Where Target's attackers stole one vendor's credentials, SolarWinds' attackers subverted the vendor's own software, so that customers installed the compromise themselves, signed and trusted. The second is MOVEit in 2023. The Cl0p ransomware group exploited a vulnerability in Progress Software's MOVEit Transfer, a widely used file-transfer tool, and used it to steal data from a huge downstream population. Emsisoft's tracking put the toll at more than 2,700 organizations and roughly 95 million individuals. Victims often had no direct relationship with Progress at all; they were customers of customers, exposed by a piece of software four steps removed from them. The through-line from Fazio to Orion to MOVEit is the same insight Target delivered in 2013: attackers go after the weakest, most trusted connection, and the more interconnected the digital economy becomes, the more of those connections exist. What changed is scale. A refrigeration contractor's password compromised one retailer. A poisoned software update compromised thousands of organizations at once.

What actually changed

The most consequential shift Target helped push into the mainstream is a security philosophy called zero trust. The old model treated the corporate network like a walled castle: get past the perimeter, whether as an employee or a vendor, and you were largely trusted to roam. Target's attackers exploited exactly that assumption, entering as a vendor and roaming to the registers. Zero trust throws out the castle. It assumes any account or device could already be compromised, and demands that every request to reach a resource be authenticated, authorized, and continuously checked, no matter where it comes from. A vendor logging in to submit an invoice, under that model, can never see a payment system, because nothing grants that access by default. Alongside it, a discipline called third-party risk management grew from a compliance afterthought into a staffed function with its own budget and executive sponsor. Vendor security questionnaires, continuous monitoring of suppliers' security posture, contractual breach-notification clauses, and least-privilege access for every outside connection are now standard expectations at large enterprises, not aspirations. Regulators followed: financial regulators, the payment-card industry, and frameworks like the U.S. National Institute of Standards and Technology's guidance all tightened their expectations around supply-chain and third-party risk in the years after 2013. The uncomfortable question is whether any of it is keeping pace. The tools and vocabulary are far better than they were when Target's Bangalore analysts watched an unanswered alert. But the Verizon numbers keep climbing, ransomware crews have industrialized the hunt for weak vendors, and the average large company now relies on hundreds or thousands of third parties, each a potential Fazio. Every new integration, every SaaS tool, every API connection is another key handed out, and the math of that only runs one direction. What to watch is not whether a breach like Target's happens again. It happens constantly, in smaller print. Watch, instead, whether organizations learn to treat access itself, rather than the identity or importance of the vendor holding it, as the thing to secure. Fazio fixed refrigerators. The lesson was never about refrigerators.

Sources

  1. Krebs on Security, "Target Hackers Broke in Via HVAC Company", 2014
  2. Krebs on Security, "Email Attack on Vendor Set Up Breach at Target", 2014
  3. BankInfoSecurity, "Senate Report Analyzes Target Breach", 2014
  4. Red River, "2013 Target Data Breach: What Happened, Cost, Timeline and Cybersecurity Lessons", 2023
  5. New York State Office of the Attorney General, "A.G. Schneiderman Announces $18.5 Million Multi-State Settlement With Target Corporation Over 2013 Data Breach", 2017
  6. The SSL Store, "Cost of 2013 Target Data Breach Nears $300 Million", 2017
  7. DataBreachToday, "Breach Aftermath: Target CEO Steps Down", 2014
  8. Verizon, "2025 Data Breach Investigations Report: Alarming surge in cyberattacks through third-parties", 2025
  9. Dark Reading, "Adapting to the Post-SolarWinds Era: Supply Chain Security in 2024", 2024
  10. Emsisoft, "Unpacking the MOVEit Breach: Statistics and Analysis", 2023