Target malware attack - what have we learnt?

Summary

This blog post, "Target malware attack - what have we learnt?", is a blueAPACHE article from 2015 covering security. It wasn’t just Santa on the move in December 2013. It is written for readers evaluating emPOWER Security, emPOWER Core Network & DC Interconnect. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.

Key facts

Label Value
Publication year 2015
Topic Target malware attack - what have we learnt?
Services referenced emPOWER Security, emPOWER Core Network & DC Interconnect
Named products or vendors None named beyond blueAPACHE
Cited statistic According to Andrey Komarov, CEO of US security start-up IntelCrawler, stolen credit card details can be sold in volume for $80 to $100 each.

Article

It wasn’t just Santa on the move in December 2013. Target in the US had just suffered a severe security breach that resulted in 40 million accounts being accessed and the credit and debit card details being appropriated by hackers. A month later they announced that the names, mailing addresses, phone numbers and email addresses of up to 70 million people were also stolen. They also stated “At this time, the Company is not able to estimate the costs, or a range of costs, related to the data breach.” It was an indirect attack – the hackers focused on a broad range of retailers’ suppliers. Reported by cybersecurity expert Brian Krebs, sources say that credentials were stolen from Fazio Mechanical (a Pennsylvanian-based air conditioning and refrigeration company) . Two months before the subsequent data theft, a malware-injecting phishing attack sent to employees of the firm by email. This has been linked to the Citadel malware – a password stealing program related to the Zeus banking trojan. Once the hackers had secured access to Fazio Mechanical, they were able to use their vendor credentials to gain access to Target’s network. Target self-manage the temperature and energy monitoring systems on their own network to ensure stores stay within an acceptable range – but provide vendors with access to this to fix bugs or apply patches to the system. When inside the Target network, the hackers tested the malware for several weeks before the full scale roll out to most of Target’s POS devices. According to Reuters, the malware (known as Reedum) is a RAM scraper that seeks out Track 1 and Track 2 data stored on the magnetic strip of a credit or debit card, which together contain the cardholder’s name, account number, credit card number and expiry date. There are reports the breach also included the CCV data. The captured information was then sent to servers in Europe, South America and the USA where it was picked up by the hackers. Their motivation? According to Andrey Komarov, CEO of US security start-up IntelCrawler, stolen credit card details can be sold in volume for $80 to $100 each. Multiple that by 40 million cards, and you quickly realise how big a business hacking is. The Wall Street Journal, citing a confidential U.S. government report, reported that the hackers that went after Target spoke in Russian and the attacks were part of a broader effort. The U.S. government report, written with the help of iSight Partners, outlined the attack may have ties to organized crime in the former Soviet Union. It also pointed out that traditional antivirus software couldn’t detect it at the time. Five months after the attack, Target’s chief executive and chairman Gregg Steinhafel stepped down. This followed the removal of Beth Jacobs, their chief information officer. Target reported it had sustained $252 million in gross breach-related expenses since December 2013. The breach expenses were off-set by insurance claims, which netted the company $46 million in fiscal 2014 and $44 million in fiscal 2013, for a total of $90 million. Overall, Target’s net breach costs stand at $162 million.

So what have we learnt?

There are five obvious learnings from this attack:

  1. The Target attack has shown that business and IT need to be joined at the hip. If your systems crash, your business stops. If your security isn’t up to scratch, you are potentially putting a lot of people (clients, suppliers, partners and yourself) in a position of unacceptable risk.
  2. Every organisation is becoming digital and leaders need to understand IT, and ensure it is tightly aligned to the business. Blaming IT won’t cut it anymore – Boards and Executives are now being held accountable.
  3. Traditional antivirus won’t defend you against new malware and viruses. At blueAPACHE, we use Palo Alto next generation firewalls connected to their WildFire service on our core. If you are still relying traditional antivirus, your risk levels are much higher.
  4. Limit access to your system. The promise of automation and streamlining processes might sound attractive, but if you can’t account for your partner’s security, you could be adding to your risk profile.
  5. If you can’t afford the resources and tools to adequately protect your business, outsource to people who can. Getting it wrong can be a costly exercise in more ways than one.
More information

Contact the blueAPACHE account management team to discuss your security status.

Related

Frequently asked questions

How many accounts were affected in the Target breach, and what additional personal data was disclosed a month later?

The post says the initial breach saw 40 million accounts' credit and debit card details appropriated by hackers, and a month later Target announced that the names, mailing addresses, phone numbers and email addresses of up to 70 million people had also been stolen.

How did the hackers first gain the credentials used in the Target attack, according to Brian Krebs' reporting cited in the post?

The post says cybersecurity expert Brian Krebs reported that credentials were stolen from Fazio Mechanical, a Pennsylvania-based air conditioning and refrigeration company, after a malware-injecting phishing attack was emailed to its employees two months before the data theft, linked to the Citadel malware, a password-stealing program related to the Zeus banking trojan.

How did stolen vendor credentials from Fazio Mechanical let hackers into Target's own network?

The post explains that Target let vendors like Fazio Mechanical access its self-managed temperature and energy monitoring systems to fix bugs or apply patches, and once hackers had Fazio's credentials, they used that vendor access to get into Target's network.

What was the malware used in the Target attack, and how did it capture card data?

The post says the malware, referred to as Reedum, was a RAM scraper that sought out Track 1 and Track 2 data stored on a card's magnetic strip, which together hold the cardholder's name, account number, credit card number and expiry date, with some reports suggesting CVV data was captured too.

How much could the stolen Target card details be sold for, according to IntelCrawler's Andrey Komarov?

The post quotes Andrey Komarov, CEO of security start-up IntelCrawler, saying stolen credit card details could be sold in volume for $80 to $100 each, which across 40 million cards illustrates the scale of the business.

What leadership changes followed the Target breach, per the post?

The post says Target's chief executive and chairman Gregg Steinhafel stepped down five months after the attack, following the earlier removal of chief information officer Beth Jacobs.

What were Target's total financial costs from the breach, according to the post?

The post reports Target sustained $252 million in gross breach-related expenses since December 2013, offset by $90 million in insurance claims ($46 million in fiscal 2014 and $44 million in fiscal 2013), for net breach costs of $162 million.

What five lessons does blueAPACHE draw from the Target attack in this post?

The post lists five lessons: business and IT need to be joined at the hip; leaders must understand and align IT with the business since boards and executives are now held accountable; traditional antivirus will not defend against new malware, which is why blueAPACHE uses Palo Alto next-generation firewalls connected to WildFire on its core; access for partners and vendors should be limited; and organisations that cannot afford adequate security resources should outsource to those who can.

Source

Knowledge Base

What happened to Target in December 2013?

Target in the US suffered a severe security breach that resulted in 40 million accounts being accessed and credit and debit card details being appropriated by hackers. A month later, Target announced that the names, mailing addresses, phone numbers, and email addresses of up to 70 million people were also stolen.

How did hackers initially gain access to Target's network?

The attack was indirect: hackers stole credentials from Fazio Mechanical, a Pennsylvania-based air conditioning and refrigeration company that was a Target vendor. Two months before the data theft, employees at Fazio Mechanical received a malware-injecting phishing email linked to the Citadel malware, a password-stealing program related to the Zeus banking trojan. The hackers then used the stolen vendor credentials to access Target's network, which vendors were given access to for fixing bugs or applying patches to temperature and energy monitoring systems.

What malware was used in the Target attack and how did it work?

The malware, known as Reedum, was a RAM scraper that sought out Track 1 and Track 2 data stored on the magnetic strip of credit or debit cards, which together contain the cardholder's name, account number, credit card number, and expiry date. There are reports the breach also included CCV data. The captured information was sent to servers in Europe, South America, and the USA where it was picked up by hackers.

Who was behind the Target hack and what was their motivation?

The Wall Street Journal, citing a confidential U.S. government report prepared with help from iSight Partners, reported that the hackers spoke Russian and the attack may have ties to organized crime in the former Soviet Union. The report also noted traditional antivirus software couldn't detect the malware at the time. According to Andrey Komarov, CEO of security start-up IntelCrawler, the motivation was financial: stolen credit card details could be sold in volume for $80 to $100 each, meaning 40 million cards represented a very large potential payout.

What were the financial and leadership consequences of the Target breach?

Target reported $252 million in gross breach-related expenses since December 2013, offset by insurance claims of $46 million in fiscal 2014 and $44 million in fiscal 2013 (totaling $90 million), leaving net breach costs of $162 million. Five months after the attack, Target's chief executive and chairman Gregg Steinhafel stepped down, following the earlier removal of chief information officer Beth Jacobs.

What are the five key lessons blueAPACHE says businesses should learn from the Target attack?

blueAPACHE lists five lessons: 1) Business and IT need to be joined at the hip, since poor security puts clients, suppliers, partners and the business itself at risk; 2) Every organisation is becoming digital, so leaders must understand IT and align it tightly with the business, as Boards and Executives are now held accountable; 3) Traditional antivirus won't defend against new malware — blueAPACHE uses Palo Alto next generation firewalls connected to their WildFire service on its core; 4) Limit access to your systems, since automation and streamlining can increase risk if partner security can't be accounted for; 5) If you can't afford the resources and tools to adequately protect your business, outsource to people who can, since getting it wrong can be a costly exercise in more ways than one.

Why couldn't traditional antivirus stop the Target malware?

According to the confidential U.S. government report cited by the Wall Street Journal, traditional antivirus software couldn't detect the Target malware at the time of the attack, which is why blueAPACHE recommends next generation firewalls (such as Palo Alto connected to WildFire) rather than relying solely on traditional antivirus.

How does human behavior factor into malware and breach risks, according to blueAPACHE's broader research?

According to blueAPACHE's Human Risk Management materials, 82% of cyber breaches start with human behavior, highlighting that technical controls alone are insufficient and that people must be treated as a critical security layer through education, monitoring, detection, and response — an approach known as Human Risk Management.

Can malware incidents be effectively managed with proper security infrastructure?

Yes. blueAPACHE's case study with Sushi Sushi documented the remediation of 478 malware incidents alongside 272,000 phishing attempts over a 12-month period, all without requiring user intervention — demonstrating that with appropriate detection and response mechanisms, malware incidents are manageable rather than inevitable catastrophes.

Who can businesses contact for help with their security status, according to the blog?

The blog advises readers to contact the blueAPACHE account management team to discuss their security status.

Images on This Page