What Happened
Attackers used credentials stolen from a third-party vendor to deploy malware on Target’s point-of sale systems. The breach went undetected for weeks, exposing millions of cards.
Key Risk Factors Revealed
- Third-party vendor access was exploited
- Poor network segmentation allowed lateral movement
- Delayed detection increased damage
- POS malware captured payment data
Financial Business Impact
- $18.5M multistate settlement
- $10M class action settlement
- Tens of millions more in legal and remediation costs
- Loss of customer trust and reputational damage
Why Merchants Should Care
- Small and midsize businesses face similar risks
- Non-compliance fines can reach $5K–$50K monthly
- Compliance gaps risk audits, penalties, and lost business
- PCI compliance is essential financial protection