As more and more details surrounding the Target breach continue to unfold, it's becoming evident just how complicated it can be for investigators and journalists to follow the trail of evidence left behind. The latest reports suggest that one or more business partners were used by the attackers to gain access to Target's systems. Below is a summary of top stories which provide insight into the tangled web of third party vendors and suppliers which may have left Target vulnerable to attack, highlighting just how esstential it is for organizations to be aware of their third party risks.
Krebs on Security: New Clues in the Target Breach
Security journalist Brian Krebs reported on January 29 that the breach may have occurred through an IT Management Software the retailer (and several others) is running on its internal network. He cites Malcovery's CTO statement that "an SQL Injection attack resulted in malware being placed on the network and credit card or personal information being exfiltrated from the network."
WSJ: Target Hackers Used Stolen Vendor Credentials
Yesterday evening the WSJ also published details concerning the breach, pointing to the possibilty of a vendor's software being the source of the exploited vulnerability. Target spokeswoman Molly Snyder confirmed in the article that a vendor's credentials were stolen and used to access their systems, however she did not reveal which vendor was implicated or what systems were accessed. The article references an earlier statement by the WSJ that Target was investigating their HR software as well as a supplier's database platform.