A hacker allegedly compromised Massachusetts HVAC vendor ENE Systems and claimed the intrusion provided access into customer environments, including Boston Children’s Hospital. According to reporting cited by DataBreaches.net, the attacker attempted to extort the vendor, said the ransom was not paid, and shared screenshots as proof while asserting continued access to ENE Systems and some client networks. Boston Children’s Hospital and Mass General Hospital acknowledged vendor-related cybersecurity concerns but said operations were not disrupted, and Boston Children’s said no patient data were affected.
The incident renewed scrutiny of HVAC and facilities contractors as a supply-chain entry point into larger organizations. The reporting drew parallels to the Target breach, where HVAC contractor Fazio Mechanical Services said its remote connection to Target was limited to billing, contract submission, and project management rather than direct control of heating or refrigeration systems. Fazio said it was a victim of a sophisticated attack, was cooperating with investigators, and that no other customers were affected, underscoring how trusted vendor access can expose hospitals and retailers alike to downstream compromise.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Boston Children's Hospital and Mass General Hospital acknowledged cybersecurity concerns related to the vendor incident. Boston Children's said operations were unaffected and no patient data were impacted, while both hospitals indicated there was no disruption to care.
The alleged ENE Systems intruder said the compromise provided access into client environments, including Boston Children's Hospital, and shared screenshots as proof. The claims suggested a supply-chain style intrusion path through the HVAC vendor.
A hacker allegedly breached Massachusetts-based HVAC vendor ENE Systems and claimed to have maintained access to the vendor's environment. According to the report, the attacker attempted to extort ENE Systems, but the ransom was not paid.
Fazio Mechanical Services publicly stated that its remote connection to Target was limited to billing, contract submission, and project management, not HVAC monitoring or control. The company said no other customers were affected, it was cooperating with the U.S. Secret Service and Target, and it was not the subject of the federal investigation.
Attackers used access associated with HVAC contractor Fazio Mechanical Services in the intrusion that led to the Target data breach. The incident became a prominent example of third-party or supply-chain compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.