Case study
Case Study - Target
In 2013, the Target corporation experienced a major data breach that compromised the personal and financial information of millions of its customers.
4 slides · 1 min read · Domain 4
The attackers gained unauthorized access to Target's computer network through a thirdparty HVAC vendor, exploiting vulnerabilities in the vendor's system. Once inside, the cybercriminals managed to navigate to Target's point-of-sale (POS) systems. The breach exposed sensitive data, including credit and debit card information, names, addresses, and phone numbers. Target faced severe backlash for the incident, leading to financial losses, reputational damage, and legal consequences.
This high-profile breach underscored the critical importance of securing third-party access, implementing robust network defenses, and safeguarding customer data against increasingly sophisticated cyber threats.
Protecting network parts
The attackers gained access to Target's network through a third-party HVAC vendor, highlighting the importance of securing network parts beyond the organization's immediate control. A thorough vendor risk management program and strict access controls for external entities could have mitigated this risk.
Protecting communication channels:
The attackers intercepted unencrypted communication channels between Target's POS systems and the central network, enabling the theft of credit card information. Implementing end-to-end encryption for sensitive data in transit and ensuring secure communication protocols could have prevented this compromise.
Use of layout values in network design:
The layout values of Target's network were exploited as the attackers moved laterally within the network from the HVAC system to the POS systems.
