
What happened
Target confirmed on 19 December 2013 that unauthorized access to payment card data had affected customers who shopped in its US stores between 27 November and 15 December, later disclosing that roughly 40 million card accounts and separately about 70 million records of contact information had been taken. A Senate Commerce Committee majority staff report, using the intrusion kill chain framework developed by Lockheed Martin analysts, found that attackers had first obtained network credentials from a Pennsylvania heating and refrigeration contractor, Fazio Mechanical Services, that had remote access to Target's systems for billing and project management, then used that foothold to move toward the point-of-sale environment and install card-scraping malware.
Confidence and limits
The committee's report draws on contemporaneous reporting, a forensic analysis by Dell SecureWorks, and testimony from Target's own chief financial officer, and it is specific about the sequence of malware installation dates in late November and early December. The report is candid that several links remain unconfirmed in the public record, including exactly how the vendor credential was used to reach the payment network, and it frames its account as based on media reports and expert analyses rather than as an independent forensic finding by the committee itself.
Why it mattered
The report's central finding was not the initial vendor compromise alone but a series of subsequent missed opportunities: Target's own malware-detection system reportedly generated alerts as the exfiltration malware was installed and updated, and the report states the security team did not act on those alerts or allow the software to automatically remove the flagged files. The breach became a reference case for the argument that a single strong perimeter control matters less than whether an organization actually responds to the internal alerts its existing tools already generate.
Defensive takeaway
Confirm that your organization has a defined process, with an owner and a time limit, for triaging every high-severity alert from intrusion-detection and endpoint tools, and that third-party vendor accounts are scoped to only the systems each vendor needs.
- Could a compromised vendor account on your network reach systems that store customer payment or personal data?
- What is the average time between a high-severity security alert firing and a person reviewing it in your environment?
- Does your network segment vendor and administrative access away from the systems that process customer transactions?
The kill-chain framing matters because it treats an intrusion as a sequence with multiple points where a defender could have intervened, rather than as a single moment of failure. Target's own statements confirmed the scale of the breach; the committee's reconstruction, while not exhaustive, is what established that the company had chances to stop the attack after the initial vendor compromise and did not take them.
Check whether alerts from your intrusion-detection or malware-analysis tools are reviewed and acted on within hours, and whether any third-party vendor account can reach systems beyond what that vendor's job requires.
A Senate Commerce Committee staff report, built from public reporting, forensic vendor analyses and testimony, maps the breach against a standard intrusion framework; the report itself states it relies on media reports and expert analyses rather than Target's complete internal forensic findings, so some links in the chain remain reconstructed rather than confirmed by Target directly.
Sources & reading trail
Target's own disclosure of the breach, the affected date range, and the initial scope of compromised payment data.
company-primary · Source published: 19 December 2013 · Retrieved: 16 September 2026
Senate Commerce Committee majority staff analysis mapping the breach to the intrusion kill chain, including the vendor-credential foothold and missed intrusion-detection alerts.
government-primary · Source published: 26 March 2014 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.