2013 Target Data Breach: What Happened, Cost, Timeline and Cybersecurity Lessons

2013 Target Data Breach: What Happened, Cost, Timeline and Cybersecurity Lessons

Quick answer: The 2013 Target data breach began with credentials stolen from a third-party HVAC contractor. Attackers used that foothold to enter Target’s environment, move toward point-of-sale systems, install malware and exfiltrate payment card data. The breach was initially believed to involve about 40 million Target credit and debit card accounts. Target later acknowledged that the attack had also exposed contact and identifying information for as many as 70 million individuals.  A U.S. Senate Commerce Committee staff analysis later highlighted weak third-party security, missed intrusion alerts, and insufficient isolation of sensitive network assets as apparent missed opportunities to stop the attack.

More than a decade later, the Target breach remains a useful cybersecurity case study because the attack was not just about malware. It was about how vendor access, identity, segmentation, monitoring, and incident response interact. Those same control areas remain central to modern Zero Trust and cyber-resilience programs.

Target Data Breach at a Glance

Fact What the record shows
When Holiday shopping season, 2013
Initial access Credentials stolen from HVAC vendor Fazio Mechanical Services, according to the Senate staff report
Primary attack path Third-party access, lateral movement, POS malware and data exfiltration
Payment cards Approximately 40 million credit and debit card accounts may have been impacted
Personal information Names, mailing addresses, phone numbers or email addresses for up to 70 million individuals
Public disclosure December 19, 2013
Multistate settlement $18.5 million in 2017
Target-reported net cumulative expenses $202 million after $90 million in insurance recoveries
Core lessons Third-party risk, least privilege, segmentation, alert response, detection engineering and incident readiness

Why Does the Target Data Breach Still Matter?

The Target breach is often remembered as a retail payment-card incident, but its lasting lesson is broader: trusted access can become an attack path when identity controls, network boundaries and detection processes fail together. The Senate staff report said Target appeared to miss multiple opportunities to stop the attackers, including weak vendor security, automated malware warnings that were not adequately acted on, and movement from less-sensitive areas into systems containing consumer data.

For security leaders today, that makes the case relevant far beyond retail. Organizations increasingly depend on contractors, SaaS providers, cloud platforms, remote access and machine identities. A modern security program has to govern those relationships continuously rather than assuming that a valid credential equals a trustworthy session.

Red River Tip: Treat third-party access as an identity problem

A vendor security questionnaire alone does not provide enough protection when a contractor account has access to systems beyond what it actually needs. Maintain an inventory of all third-party identities, enforce strong authentication, limit each vendor to the specific applications and data required for its work, make elevated permissions temporary, and monitor activity throughout the access period.

What Happened During the 2013 Target Data Breach?

A U.S. Senate Commerce Committee staff report said the attackers reportedly gained access through credentials belonging to Fazio Mechanical Services, a Pennsylvania HVAC and refrigeration contractor with remote access to Target systems for billing, project management, and contract-related work.  The report said the attackers used the vendor foothold to gain access to Target’s network and then moved through multiple internal systems.

Attackers installed RAM-scraping malware on Target point-of-sale terminals. RAM scraping captures payment data while it is temporarily available in plaintext in system memory. The Senate report noted that media and security researchers identified a tailored version of BlackPOS malware in the attack.

The attack also included malware used to move stolen data through Target’s environment and out of the network. The Senate analysis reported that Target’s FireEye system generated alerts during malware installation, but those warnings did not prevent the breach from continuing.

How Hackers Breached Target: Step by Step

  1. A third-party vendor was compromised. Attackers reportedly stole Target-access credentials from Fazio Mechanical Services after compromising the vendor.
  2. Vendor credentials created a foothold. The stolen credentials were used to enter a Target-accessible environment. The precise technical path from the vendor portal to the payment environment was not fully established in the public record.
  3. Attackers moved through internal systems. The Senate staff analysis concluded that attackers appear to have moved from less-sensitive areas into systems associated with consumer data, pointing to insufficient isolation of sensitive assets.
  4. POS malware captured payment-card data. RAM-scraping malware was installed on point-of-sale systems and collected card data as transactions were processed.
  5. Stolen data was staged and exfiltrated. Additional malware moved the collected data through Target’s environment and to attacker-controlled infrastructure.
  6. Security alerts did not stop the operation. The Senate staff report said Target appeared to have failed to respond effectively to multiple automated warnings related to malware installation and data exfiltration.

Target Data Breach Timeline

Date/Period What Happened
At least two months before the payment-card breach The Senate report said attackers reportedly stole Fazio Mechanical credentials through malware-infected email.
Nov. 12-30, 2013 Public reports summarized by the Senate staff report placed initial Target network access and early POS malware installation in this period. These dates were based on reporting and investigator accounts, not a definitive Target disclosure.
Nov. 27-Dec. 15, 2013 Target said unauthorized access to payment-card data occurred in U.S. stores during this period.
Dec. 12, 2013 Target officials testified that the company was not aware of the breach until contacted by the U.S. Department of Justice.
Dec. 18, 2013 Security journalist Brian Krebs publicly reported the breach.
Dec. 19, 2013 Target publicly confirmed that approximately 40 million credit and debit card accounts may have been impacted.
Jan. 10, 2014 Target disclosed that names, mailing addresses, phone numbers or email addresses for up to 70 million individuals had also been taken.
Apr. 29, 2014 Target described security changes including enhanced monitoring and logging, POS application whitelisting, stronger segmentation, reduced vendor access and expanded two-factor authentication.
May 23, 2017 Target entered an $18.5 million multistate settlement related to the breach.
2017 SEC filing Target reported $292 million of cumulative breach expenses, offset by $90 million of insurance recoveries, for $202 million in net cumulative expenses.

What Data Was Compromised in the Target Breach?

In its December 2013 disclosure, Target said the compromised payment-card data included customers’ names, card numbers, expiration dates, and CVV codes.  In January 2014, Target said separate guest information taken in the same breach included names, mailing addresses, phone numbers or email addresses for up to 70 million individuals.

Why Did the Target Breach Become So Large?

The public record does not reduce the breach to one single failure. The Senate staff analysis instead identified multiple points where the attack might have been disrupted.

Third-party access expanded the attack surface

A contractor credential became a path into a much larger enterprise environment. Modern third-party risk programs should combine vendor due diligence with identity governance, strong authentication, least privilege and continuous access review.

Sensitive systems were not isolated enough

The attackers were able to move from an external-vendor foothold toward systems holding consumer and payment data. Segmentation and microsegmentation are designed to constrain that kind of lateral movement.

Detection did not translate into action

Security tooling reportedly generated alerts, but a detection only has value if it is triaged, investigated and escalated quickly enough to change the outcome.

Egress activity was not stopped in time

The attackers were able to move collected data out of the environment. Modern controls can combine network telemetry, SIEM/XDR, DLP, anomaly detection and egress filtering to identify unusual data movement.

Incident readiness is an operating discipline

A response plan should define who owns each class of alert, when an incident is escalated, what can be isolated automatically and how business, legal and communications leaders engage. NIST SP 800-61 Rev. 3 now frames incident response as part of broader cybersecurity risk management, not a one-time emergency procedure.

Red River Tip: Measure the handoff from detection to response

Do not evaluate a SOC only by whether a tool generated an alert. Test the full path: telemetry arrived, the alert was enriched, severity was assigned correctly, an analyst took ownership, escalation occurred inside the required window and containment actions were available. The operational handoff is where many mature-looking security programs fail.

How Did Target Respond After the Breach?

Target publicly confirmed the payment-card breach on December 19, 2013. In January, Target broadened its disclosure, reporting that personal information belonging to as many as 70 million people had also been affected. The company also offered affected U.S. store customers credit monitoring and identity-theft protection.

By April 2014, Target said it had implemented additional monitoring and logging, application whitelisting on point-of-sale systems, enhanced segmentation, tighter vendor access, password resets, broader two-factor authentication and reduced privileges for certain accounts. Those measures directly address several control areas implicated in the attack.

How Much Did the Target Data Breach Cost?

The $18.5 million figure often associated with the Target breach was the 2017 multistate settlement, not the total cost of the incident. The company’s 2017 Form 10-K put cumulative expenses from the breach at $292 million. With $90 million recovered through insurance, Target’s net financial impact was $202 million.

Target also reported weaker-than-expected sales after the breach was announced. In January 2014, the company reduced its fourth-quarter U.S. outlook and said sales had been meaningfully weaker than expected since the December 19 announcement. This is a useful reminder that breach impact includes operational disruption, legal expense, remediation, insurance, customer trust and revenue effects, not just a settlement amount.

Seven Cybersecurity Lessons from the Target Breach for Organizations Today

  1. Third-party risk must extend beyond questionnaires. Know which vendors have access, which identities they use, what resources they can reach, how authentication is enforced and how quickly access can be revoked.
  2. Identity should be foundational. Passwords alone are an inadequate control for privileged or remote access. Use phishing-resistant MFA where appropriate, conditional access, privileged-access controls and least privilege.
  3. Segment around critical resources. Do not rely on a flat internal network or broad trust based on location. Segment sensitive systems and enforce policy at the resource and identity level.
  4. Alerts need ownership and response SLAs. A high-quality detection pipeline must include prioritization, investigation, escalation, containment authority and after-action tuning.
  5. Monitor outbound behavior, not just inbound threats. Data theft requires movement. Egress monitoring, DLP, network analytics and integrated telemetry can expose abnormal transfer patterns.
  6. Practice incident response before an incident. Run tabletop exercises and technical simulations. Validate contact trees, decision authority, forensic readiness, legal obligations and recovery processes.
  7. Treat cybersecurity as enterprise risk. The Target breach affected technology, operations, customers, regulators, leadership and financial performance. Security governance belongs in business-risk discussions, not only inside IT.

From the 2013 Attack Path to Modern Security Controls

Observed Attack Vector Modern Response
Stolen vendor credentials Phishing-resistant MFA, vendor IAM, conditional access, privileged access management, access expiration
Overly broad vendor reach Least privilege, application-level access, Zero Trust policy enforcement
Lateral movement Network segmentation, microsegmentation, identity-aware access controls
POS malware EDR, application allowlisting, endpoint hardening, behavioral detection
Missed malware alerts SOC/MDR, detection engineering, severity tuning, escalation SLAs, automated containment where appropriate
Data staging and exfiltration SIEM/XDR correlation, DLP, egress monitoring, anomaly detection, controlled outbound paths
Slow organizational response Tested incident-response playbooks, executive decision paths, legal and communications integration, continuous improvement

Red River Perspective: What the Target Breach Teaches About Zero Trust

The breach is sometimes described as proof that organizations need more security tools. That is too simplistic. Target already had security technology capable of producing alerts. The more important question is whether identity, segmentation, telemetry, and response processes operate together as a coherent security architecture.

Robert Jordan, Senior Design Architect and Zero Trust Practice Lead at Red River, emphasizes a practical approach to modernization: “Zero Trust does not have to be a rip-and-replace effort.” Organizations can start by mapping vendor identities and access paths, identifying sensitive resources, checking what telemetry existing tools already produce, testing segmentation and fixing the highest-risk gaps first.

Red River’s current Zero Trust approach begins with understanding the existing environment and prioritizing practical use cases rather than assuming every control must be replaced at once. Applied to the Target case, the first use cases would likely include third-party identity governance, least-privilege vendor access, segmentation around payment or sensitive-data systems and an operationally tested detection-and-response workflow.

Red River Tip: Test attack paths, not just control inventories

A spreadsheet showing that MFA, EDR, a SIEM and firewalls are deployed does not prove that a Target-style attack path is contained. Validate whether a compromised vendor identity can reach sensitive systems, whether the endpoint and network controls see the movement, whether the SOC escalates it, and whether containment can occur before data leaves the environment.

Could a Target-Style Data Breach Happen Today?

Yes, of course; many similar attacks (albeit smaller in scope) happen all the time. The specific technology stack has changed, but the underlying attack pattern remains relevant: compromise a trusted identity, exploit excessive access, move laterally, establish persistence and extract valuable data. Modern Zero Trust, MFA, EDR/XDR, segmentation, continuous monitoring and stronger incident-response practices can make the attack significantly harder, but they do not eliminate risk.

The most useful question for security leaders is not whether the exact 2013 breach could repeat. It is whether a compromised vendor or employee identity could still move farther than intended in their own environment without being detected and contained quickly.

How Red River Helps Organizations Reduce Breach Risk

Red River helps commercial, federal and SLED organizations strengthen cybersecurity across strategy, architecture and security operations. Depending on the environment, that can include Zero Trust planning, identity and access management, segmentation, SOC and managed detection and response, incident-response planning and security-framework assessments.

The Target case provides a useful starting question: if one trusted credential were compromised today, how far could an attacker get before your controls stopped the movement? Red River can help assess that path, prioritize the highest-risk gaps and build a phased roadmap that improves resilience without assuming a wholesale technology replacement is required.

Explore Red River cybersecurity services

Target Data Breach FAQs

What was the 2013 Target data breach?

Target’s 2013 breach involved a third-party compromise that provided attackers with a foothold in the retailer’s environment. From there, they infected point-of-sale systems with malware and extracted sensitive payment and personal data. 

How did hackers get into Target?

According to the U.S. Senate Commerce Committee staff report, attackers reportedly stole credentials from HVAC vendor Fazio Mechanical Services and used the vendor relationship as an initial foothold into Target’s network.

How many individuals were affected by the 2013 Target data breach?

Target disclosed approximately 40 million potentially impacted credit and debit card accounts and separate personal information for up to 70 million individuals. The incident is often summarized as affecting up to 110 million customers, but the two official figures are more precise when reported separately.

When did the Target data breach happen?

Target said unauthorized payment-card access occurred in U.S. stores between November 27 and December 15, 2013. Public reporting summarized by the Senate staff report placed earlier network and malware activity in November.

Why did Target not stop the breach sooner?

The Senate staff analysis said Target appeared to miss multiple opportunities to stop the attack, including automated malware warnings and insufficient isolation between less-sensitive and more-sensitive parts of the network.

How much did the Target data breach cost?

Target reported $292 million in cumulative breach expenses and $90 million in insurance recoveries, for $202 million in net cumulative expenses. Separately, Target entered an $18.5 million multistate settlement in 2017.

What cybersecurity lesson is most important from the Target breach?

The breach shows why organizations should treat third-party identity, least privilege, segmentation, monitoring and incident response as connected controls. A valid vendor credential should not provide broad trust across an enterprise environment.

Would MFA alone have prevented the Target breach?

MFA would have reduced the risk from stolen vendor credentials, but it should not be treated as a complete answer. Modern defense also requires least privilege, segmentation, endpoint protection, detection, egress monitoring and effective incident response.

What did Target change after the breach?

Target said it enhanced monitoring and logging, deployed POS application whitelisting, improved network segmentation, limited vendor access, reset passwords, expanded two-factor authentication and reduced privileges for certain accounts.

How can organizations test whether they are vulnerable to a similar attack path?

Map third-party identities and access, identify sensitive systems, validate segmentation, simulate credential compromise, confirm detection coverage and measure whether analysts can escalate and contain suspicious activity before data is exfiltrated.

written by

Corrin Jones

Corrin Jones is the Director of Digital Demand Generation. With over ten years of experience, she specializes in creating content and executing campaigns to drive growth and revenue. Connect with Corrin on LinkedIn.

Go to Top