Target, Neiman Marcus, and Home Depot disclosed major payment-card breaches in which attackers planted point-of-sale malware on in-store checkout systems and harvested customer data at scale. Target said about 40 million payment cards were exposed during the 2013 holiday shopping period, with later estimates rising to as many as 110 million people affected when personal information was included. Reporting tied the Target intrusion to customized memory-scraping malware related to BlackPOS, which was used to collect card data from checkout terminals and stage it on internal servers before exfiltration; investigators and the U.S. Secret Service were drawn into the case as the breach became one of the largest retail compromises on record. Neiman Marcus also reported that its breach was worse than first disclosed, adding to the wave of retail intrusions.
Home Depot later revealed a similarly large compromise affecting its U.S. and Canadian self-checkout systems, saying attackers stole more than 56 million payment card numbers and over 53 million email addresses after entering through credentials taken from a third-party vendor and moving laterally through the network. The incidents intensified pressure on U.S. retailers and payment providers to move away from vulnerable magnetic-stripe cards toward EMV chip technology, while also imposing steep business costs: Target reported a sharp profit decline, tens of millions of dollars in breach-related expenses, and warned that litigation, fraud losses, and investigative costs could continue to materially affect results. Together, the breaches showed how weak vendor access controls, hard-to-detect POS malware, and outdated payment technology enabled large-scale theft of card data from major retailers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Home Depot disclosed that attackers stole more than 56 million payment card numbers and over 53 million email addresses in a major breach. The company said it had removed the malware, worked with law enforcement and outside investigators, warned customers about phishing risks, and improved payment-system encryption.
Home Depot said malware operated on its U.S. and Canadian self-checkout systems from April through September 2014, capturing payment card data. The attackers initially accessed the network using credentials stolen from a third-party vendor before moving laterally and installing custom malware.
Reporting said Target's FireEye security systems generated multiple alerts as attackers installed tools and moved data during the 2013 intrusion, but the warnings were not escalated in time to stop the breach. The account added a new detail about Target's internal detection and response failures during the incident.
Target reported that fourth-quarter profit fell 46 percent year over year to $520 million following the breach. The company said it had recorded $61 million in pretax breach-related expenses, expected partial insurance recovery, and warned that litigation, fraud claims, and investigative costs could continue to affect results.
Neiman Marcus disclosed that its own payment-card breach was larger than first reported, affecting about 1.1 million cards. The incident became part of the broader wave of major retail payment breaches drawing attention in early 2014.
Reporting said a 23-year-old Russian hacker confessed to being the original author of the BlackPOS malware family tied to major retail payment-card breaches. This added a new attribution detail beyond earlier reporting that had only linked the Target intrusion to BlackPOS/Reedum technically.
New reporting described the malware used in the Target intrusion as a customized memory-scraping point-of-sale threat closely related to BlackPOS/Reedum. The attackers were said to have compromised a Target web server, deployed malware to checkout systems, and used an internal server to collect stolen card data while evading antivirus detection.
Target later said the breach affected personal or payment information for as many as 110 million people, greatly expanding the known scope beyond the initial 40 million payment cards. This broader figure was cited in later January and February reporting.
Target disclosed that approximately 40 million credit and debit card accounts may have been compromised in a breach affecting in-store shoppers between late November and mid-December 2013. The company said it was working with a third-party forensics firm, and the U.S. Secret Service confirmed it was investigating.
KrebsOnSecurity reported that Target was investigating a payment-card breach potentially affecting millions of customers at nearly all U.S. stores during the holiday shopping season. Sources said magnetic-stripe track data was stolen from in-store transactions and that the exposure window may have extended through 2013-12-15.
Attackers began harvesting payment card data from Target store customers around the Thanksgiving/Black Friday period. Reporting places the exposure window starting on 2013-11-27 and continuing into mid-December.
Reporting said the Target attackers first accessed the retailer's network on 2013-11-15 using credentials stolen from HVAC subcontractor Fazio Mechanical Services. The intruders then reportedly spent about 13 days testing card-stealing malware on a limited number of POS terminals before wider deployment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcecnet.com
Open sourcebits.blogs.nytimes.com
Open sourceweb.archive.org
Open sourcekrebsonsecurity.com
Open sourcearstechnica.com
Open sourcewired.com
Open sourcekrebsonsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.