← All enforcement actions
PCI DSSState AGClass ActionRetail

Target~$202M PCI fine (2013)

HVAC vendor credentials → 40M payment cards + 70M customer records

Penalty
~$202M
Regulator
47 State AGs + class action + card networks
Jurisdiction
United States
Records affected
110M

What happened

Attackers used phished credentials from a third-party HVAC vendor (Fazio Mechanical) to pivot into Target's network and install RAM-scraping malware on POS systems, exfiltrating 40M card details + 70M customer records during the 2013 holiday season. Settlements + remediation exceeded $202M; the CEO and CIO resigned.

Root cause

What every team should do

  1. Vendor network access must be JIT, scoped, MFA-enforced, and segmented from CDE
  2. Build a Vendor Risk Management program (SOC 2 CC9.2 / FFIEC) with annual reviews
  3. EDR alerts need a 24x7 SOC with named on-call rotation and resolution SLAs
Source: Target 10-K (Mar 2014), State AG settlement (May 23, 2017).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which PCI controls you are missing — mapped to enforcement patterns like this one.

Run my PCI audit Generate missing policies

Related enforcement actions

Equifax
$700M+
Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days
TJX Companies
~$256M
The breach that wrote PCI DSS — 94M cards stolen via insecure WEP wireless