Open cardosec

Case 0CABC1 · Famous breaches · L1 Foundations

Target 2013

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Attackers stole credentials from Fazio Mechanical, an HVAC vendor with access to a Target vendor portal
  2. Pivoted from the vendor-facing network to point-of-sale systems due to weak segmentation
  3. RAM-scraping POS malware (BlackPOS variant) captured card data in memory before encryption
  4. About 40M cards and 70M customer records; FireEye alerts fired but were not acted on
  5. Lessons: third-party access control, network segmentation, and alert triage that actually escalates

If the interviewer pushes back

  • How does PCI DSS scoping relate to the segmentation failure at Target?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.