The Target breach started with an HVAC vendor
Christmas 2013, millions of cards, and the little company plugged into the big one.
In late 2013 Target, the US shop, lost card data for tens of millions of customers. The story that stuck was not a genius at a keyboard in a hoodie. It was an HVAC vendor. Attackers used that smaller company’s access to get into Target’s network, then to the point of sale world where cards were handled. The breach became public around Christmas. People still quote it when they talk about “third parties.”
The boring door
Big firms have lots of companies plugged in: cooling, payroll, a marketing tool, a contractor VPN. Each plug is a door. The contractor’s password policy is not the retailer’s password policy. That gap is the crime scene more often than a zero day.
You are not Target. You still have little vendors: a tax app, a printer cloud, a “smart” camera outfit, the cousin who logs into the router. Their leak can become your leak.
Cards and the year after
If a shop you used had a breach, the card number is the easy part. Watch the statement. Ask for a new number. Change the password if you had an account. Turn on alerts. Do not call a number that arrived in an email the same week with “Target help” in the subject. That wave of fake help is as reliable as rain.
The habit this breach bought us
Ask who else can see a system before you plug a new gadget into the same WiFi as your laptop. Guest networks exist for a reason. Unique passwords exist so one vendor dump is not a skeleton key. Target was a headline. The pattern is still how a lot of quieter theft starts: not through the front door, through the company that services the air conditioner.