In 2013, Target had their systems targeted (no pun intended)
by a group of hackers. They gained access to Target’s network via a third party
company. A heating and air company known as Fazio Mechanical Services had
access to Target’s network so they could monitor the systems of their stores in
Pittsburgh. Target found that it was more cost effective to hire other companies
to perform maintenance in their stores instead of hiring a fulltime team. (Carrol & Rigden, 2014)
Fazio Mechanical Services was targeted by a spear phishing
attack. It is estimated that this breach occurred a few months before the
Target hack was successful, which puts the initial attack at August or
September of 2013. Once the hackers had access to Fazio’s network they stole
their credentials for Target’s network. They then installed malware on several
Target POS systems on November 15th, 2013. These POS systems acted
as a ‘test system’ from the 15th to the 28th of November.
On the 30th of November the malware began to copy itself and onto more
POS systems and it began to copy credit card information as it was scanned in. (Carrol &
Rigden, 2014)
They used information gathered from their test run to decide
how to hide the malware. They were also very smart with their test period.
Target was focused on keeping their systems up during Black Friday, that they
were not fully monitoring their security. The hackers hid the malware as ‘BladeLogic’.
The initial data collection ran from November 30th to December 2nd,
when it began to send the data to stations in Virginia, Utah and California and
it only sent the data during usual business hours to disguise it in normal
business traffic. The breach was found by Federal law enforcement on December
12th. (Carrol & Rigden, 2014)
After investigating the breach, they found that the breach
was conducted by a hacker known as Rescator. This hacker was known for their
black market website that sold credit card information. While they do not have
proof of Rescator’s true identity they believe that Rescator is a 22 year old
Ukrainian student named Andrey Khodyrevskiy. Overall, Andrey caused over 20
million dollars of damages to Target. (Carrol & Rigden, 2014)
Carrol, A., & Rigden, T. (16, January 2014). The
Story. Retrieved from Target Security Breach:
https://people.carleton.edu/~carrolla/story.html
Comments
Post a Comment