recommended reading

Here’s How Hackers Stole 110 Million Americans’ Data From Target

Flickr user jpellgen

More than 110 million Target customers had their credit-card information stolen because at least one employee of a heating and air-conditioning contractor succumbed to an email phishing scheme, cybersecurity blogger Brian Krebs reported Wednesday.

The revelation, if true, is the strongest indication yet of what went wrong since Krebs first exposed the massive heist of consumer financial data at the national retail giant late last year, a startling cyberattack that has prompted intense congressional inquiry. Neiman Marcus and other chains have also recently been victimized, though it is not believed that the perpetrators are the same.

Last week, Krebs reported that hackers infiltrated Target's network by swiping the login credentials of Fazio Mechanical Services, a Pennsylvania-based contractor.

Now, anonymous sources tell Krebs that credentials "were stolen in an email malware attack at Fazio that began at least two months before thieves started stealing card data from thousands of Target cash registers." It appears that the culprits used a password-stealing bot known as Citadel to get the job done.

Fazio, in response to its sudden notoriety last week, sent out a statement explaining that it had been "the victim of a sophisticated cyberattack operation." But Krebs notes that the company's defense against malicious attacks was a free version of a somewhat impotent anti-malware program, which "is made explicitly for individual users and its license prohibits corporate use."

Members of Congress are calling for a bill to create a national reporting standard for data breaches similar to the one that hit Target. Retailers and financial institutions would be required to notify government and consumers of breaches when they occur.

The new revelations arrive on a day when the White House rolled out a set of voluntary guidelines intended to help businesses defend themselves against hackers.

(Image via jpellgen/

Threatwatch Alert

Network intrusion / Stolen credentials

85M User Accounts Compromised from Video-sharing Site Dailymotion

See threatwatch report


Close [ x ] More from Nextgov

Thank you for subscribing to newsletters from
We think these reports might interest you:

  • Data-Centric Security vs. Database-Level Security

    Database-level encryption had its origins in the 1990s and early 2000s in response to very basic risks which largely revolved around the theft of servers, backup tapes and other physical-layer assets. As noted in Verizon’s 2014, Data Breach Investigations Report (DBIR)1, threats today are far more advanced and dangerous.

  • Featured Content from RSA Conference: Dissed by NIST

    Learn more about the latest draft of the U.S. National Institute of Standards and Technology guidance document on authentication and lifecycle management.

  • PIV- I And Multifactor Authentication: The Best Defense for Federal Government Contractors

    This white paper explores NIST SP 800-171 and why compliance is critical to federal government contractors, especially those that work with the Department of Defense, as well as how leveraging PIV-I credentialing with multifactor authentication can be used as a defense against cyberattacks

  • Toward A More Innovative Government

    This research study aims to understand how state and local leaders regard their agency’s innovation efforts and what they are doing to overcome the challenges they face in successfully implementing these efforts.

  • From Volume to Value: UK’s NHS Digital Provides U.S. Healthcare Agencies A Roadmap For Value-Based Payment Models

    The U.S. healthcare industry is rapidly moving away from traditional fee-for-service models and towards value-based purchasing that reimburses physicians for quality of care in place of frequency of care.

  • GBC Flash Poll: Is Your Agency Safe?

    Federal leaders weigh in on the state of information security


When you download a report, your information may be shared with the underwriters of that document.