preview

Target 2013 Breach: A Case Study

Decent Essays

Target 2013 Breach
In the midst of the holiday season, Target shoppers were shocked in December 2013 when the news came out, 40 million Target credit cards had been stolen (Krebs, 2013f) by accessing data on point of sale (POS) systems (Krebs, 2014b). Target later revised that number to include private data for 70 million customers (Target, 2014). The breach transpired between November 27 and December 15th 2014 (Clark, 2014). Over 11 GB of data was stolen (Poulin, 2014). Target missed internal alerts and found out about the breach when they were contacted by the Department of Justice (Riley, Elgin, Lawrence & Matlack, 2014).
The Attack
1. Reconnaissance by attackers may have included a Google search that would have supplied a great deal of information about how Target interacts with vendors. Results would have revealed a vendor portal and a list of HVAC and refrigeration companies (Krebs, 2014g). The results would have also revealed how Target uses Microsoft virtualization software, centralized name resolution and Microsoft System Center Configuration Manager (SCCM), to deploy security patches and system …show more content…

To send raw commands over the network, other customized components were used that would not be discoverable by common network forensics tools and bypass network controls (iSight Partners, 2014). (Radichel, 2014)
10. Data was retrieved using the default user name and password for BMC’s Performance Assurance for Microsoft Servers (Krebs, 2014e). (Radichel, 2014)
11. Data was moved to drop locations on hacked servers all over the world via FTP. Hackers retrieved the data from drop locations which hackers accessed to retrieve it (Krebs, 2014h). (Radichel, 2014)
12. On Nov. 30, monitoring software (FireEye) alerted staff in Bangalore, India, while the attack was in progress. They in turn notified Target staff in Minneapolis but no action was taken (Elgin, 2014). (Radichel, 2014)
13. Credit cards were then sold on the black market (Krebs, 2013c). (Radichel,

Get Access