Target Hack Began With ... Refrigeration Contractor?

Hackers may have gained access through Pittsburgh company's computers
By John Johnson,  Newser Staff
Posted Feb 8, 2014 10:34 AM CST
Target Hack Began With ... Refrigeration Contractor?
A Target store in Watertown, Mass.   (AP Photo/Steven Senne, File)

It's beginning to look like the hackers who got into Target's computer network did so by first hijacking the computers of an unlikely source—a company near Pittsburgh that provides refrigeration, heating, and A/C service to the chain, reports KrebsOnSecurity. Once hackers gained access to Fazio Mechanical Service's network, they were somehow able to get into Target's payment system. Fazio has confirmed that it got hit by a "sophisticated cyberattack operation" and is cooperating with the Secret Service and Target to figure out what happened.

Fazio says it submits bills and contract proposals to Target electronically, and that is presumably where the vulnerability occurred. That surprises security expert Chester Wisniewski of Sophos, who tells AP that something probably went wrong on Target's end. "If normal practices were followed, they wouldn't have been able to get access," he says. It's not clear what kind of setup Target had, but companies are not required to keep consumer information on a separate network, he adds. (More Target stories.)

Get the news faster.
Tap to install our app.
X
Install the Newser News app
in two easy steps:
1. Tap in your navigation bar.
2. Tap to Add to Home Screen.

X