The breach at Target Corp. that exposed credit card and personal data on more than 110 million consumers appears to have begun with a malware-laced email phishing attack. Sources close to the investigation say that those credentials were stolen in an email malware attack at Fazio Mechanical. The company did not specify which component(s) of Targets online operations that the company accessed externally, but a former employee at Target said nearly all Target contractors access an external billing system called Ariba, as well as a Target project management portal.”]
Source: https://krebsonsecurity.com/2014/02/email-attack-on-vendor-set-up-breach-at-target/

