The hackers who hit Target and gained access to their systems, capturing financial and personal data from 110, millions of customer-customers of the company managed to do so by cheating an employee of an outside vendor. A click on a malicious message was about to bring the disaster, according to a report published on Wednesday by security researcher blogger Brian Krebs.
An employee of Fazio Mechanical, an air conditioning company in Sharpsburg, was the victim of a spear phishing attack in which hackers sent malware with a message that appeared to come from a trusted source. A click on the link in the email was the cause of the crash, according to Krebs, who also cited evidence.
As soon as the hackers gained access to the worker's computer, they were able to enter the Target system. Fazio reported last week that it was perhaps the passage from which the hackers gained access to Target's network, but details of how the attack had taken place had not been announced.
Disclosure highlights a central problem facing all companies trying to secure their networks. Although businesses invest millions of dollars each year to fight hackers, they are still vulnerable due to the loose third-party security measures that access their systems.
Target spokeswoman Molly Snyder said: "An intruder stole a vendor's credentials and used them to gain access to our system." The spokeswoman declined to name the partner company or reveal how the credentials were stolen, citing an ongoing investigation.
Krebs said Fazio was not immediately aware of the phishing attack because it was using a free anti-malware program that "does not offer real-time protection against threats."
George is still wondering what he is doing here….





