Skip to main content

Target breach (week 9)

In 2013, Target had their systems targeted (no pun intended) by a group of hackers. They gained access to Target’s network via a third party company. A heating and air company known as Fazio Mechanical Services had access to Target’s network so they could monitor the systems of their stores in Pittsburgh. Target found that it was more cost effective to hire other companies to perform maintenance in their stores instead of hiring a fulltime team. (Carrol & Rigden, 2014)

Fazio Mechanical Services was targeted by a spear phishing attack. It is estimated that this breach occurred a few months before the Target hack was successful, which puts the initial attack at August or September of 2013. Once the hackers had access to Fazio’s network they stole their credentials for Target’s network. They then installed malware on several Target POS systems on November 15th, 2013. These POS systems acted as a ‘test system’ from the 15th to the 28th of November. On the 30th of November the malware began to copy itself and onto more POS systems and it began to copy credit card information as it was scanned in. (Carrol & Rigden, 2014)

They used information gathered from their test run to decide how to hide the malware. They were also very smart with their test period. Target was focused on keeping their systems up during Black Friday, that they were not fully monitoring their security. The hackers hid the malware as ‘BladeLogic’. The initial data collection ran from November 30th to December 2nd, when it began to send the data to stations in Virginia, Utah and California and it only sent the data during usual business hours to disguise it in normal business traffic. The breach was found by Federal law enforcement on December 12th. (Carrol & Rigden, 2014)

After investigating the breach, they found that the breach was conducted by a hacker known as Rescator. This hacker was known for their black market website that sold credit card information. While they do not have proof of Rescator’s true identity they believe that Rescator is a 22 year old Ukrainian student named Andrey Khodyrevskiy. Overall, Andrey caused over 20 million dollars of damages to Target. (Carrol & Rigden, 2014)

 

Carrol, A., & Rigden, T. (16, January 2014). The Story. Retrieved from Target Security Breach: https://people.carleton.edu/~carrolla/story.html

Comments