It was the week before Christmas, 2013. Americans were flooding Target stores for holiday shopping. Unbeknownst to anyone, hackers had been silently sitting inside Target's payment systems for three weeks, skimming the card info of every single person who swiped at a register.
Here's the wild part: they didn't get in through Target. They got in through Fazio Mechanical, a small Pennsylvania company that handled Target's refrigeration and HVAC systems. The hackers stole Fazio's credentials and walked right through Target's back door. By the time it was over, 40 million credit cards and 70 million customer records had been stolen. Target's CEO resigned. Over $200 million in damages.
A chain is only as strong as its weakest link. The most sophisticated hackers find the side door: a vendor, a contractor, a third party app. Same playbook, 13 years later.