Target confirmed on 19 December 2013 that intruders had reached its payment system: about 40 million credit and debit card accounts, from purchases in its American stores between 27 November and 15 December. On 10 January 2014 the company added the part that changed the story. Alongside the cards, it said, the intruder had taken names, mailing addresses, phone numbers or email addresses for up to 70 million individuals, much of it partial — none of it a card number, and all of it belonging to people whose worst case had been a reissued card. The same statement cut fourth-quarter guidance to adjusted earnings of $1.20 to $1.30 a share, against the $1.50 to $1.60 promised earlier. A year of free credit monitoring was offered to every American guest.
How they got in came out in stages. On 15 January Brian Krebs published a close look at the malware: a memory scraper called BlackPOS, catalogued by Symantec as Reedum, that captured a card's magnetic stripe in the instant after a swipe, while it still sat unencrypted in memory. It ran to about 207 kilobytes and sold for between $1,800 and $2,300. The dumps were pooled on a control server inside Target's own network and collected by hand. On 5 February Krebs named the way in: credentials taken from Fazio Mechanical Services of Sharpsburg, Pennsylvania, a refrigeration contractor, used to enter Target's network on 15 November 2013. Fazio's president, Ross Fazio, confirmed a Secret Service visit; the firm said its connection with Target was "exclusively for electronic billing, contract submission and project management".
The alarms had worked. Bloomberg Businessweek reported on 13 March 2014 that Target had installed a $1.6 million malware-detection system from FireEye six months earlier, watched around the clock by a team of security specialists in Bangalore, with its automatic-removal function switched off. On Saturday 30 November the system saw the intruders. Bangalore raised an alert and flagged the security operations centre in Minneapolis, and, in the magazine's account, nothing happened. Federal investigators told the company about the theft roughly a fortnight later. Asked about it, a Target spokesperson said that with the benefit of hindsight the company was investigating whether different judgments might have produced a different outcome. Detection had never been the missing piece.
The endings arrived slowly. Target announced its chief information officer's resignation on 5 March 2014 and, on 5 May, that of its chief executive, Gregg Steinhafel; analysts tied it to the breach. By the quarter ended 3 May it had booked $88 million of breach expenses against $52 million of expected insurance recoveries, with more than a hundred actions filed against it in the United States and one in Canada, and the FTC, SEC and state attorneys general all investigating. A $10 million consumer settlement received final approval on 17 November 2015. On 23 May 2017 Target settled with 47 states and the District of Columbia for $18.5 million, then the largest multi-state breach settlement, in an agreement describing more than 41 million card accounts and contact information for more than 60 million customers.
Three more sets of registers
January belonged to no single retailer. On 10 January Krebs reported a card breach at Neiman Marcus; the company said its processor had flagged potentially unauthorised activity in mid-December and its forensics firm found evidence of the intrusion on 1 January. The scale settled later — 77 American stores, about 370,000 payment cards, at least 9,200 of them used fraudulently — in the figures set out when 43 states and the District of Columbia announced a $1.5 million settlement on 8 January 2019. On 25 January banks told Krebs they were tracking fraud on cards recently used at Michaels; the chain said the same day that it might have suffered an attack, and on 17 April confirmed two separate eight-month intrusions, at Michaels and at its Aaron Brothers subsidiary, exposing as many as three million cards. On 31 January White Lodging, which ran 168 full-service hotels under Hilton, Marriott, Sheraton and Westin franchises, was investigating fraud traced to hotel restaurants and gift shops rather than front desks, running from about 23 March 2013 to the end of the year; an update in February put it at fourteen properties.
A list, a fridge and a coffee app
The month's other failures were about custody of data. On New Year's Day a site calling itself SnapchatDB, put up the night before, was found holding 4.6 million Snapchat usernames and phone numbers, the last two digits withheld. Gibson Security had reported the flaw on 27 August 2013 and published code on 25 December; the anonymous group behind the list dismissed the mitigations announced two days later as minor obstacles. The Federal Trade Commission settled with Snapchat on 8 May 2014 over the failure to verify phone numbers. On 13 January the penetration tester Daniel Wood told the Full Disclosure list that the Starbucks iOS app kept usernames and passwords in clear text in a log file; Starbucks said it had known. On 16 January Proofpoint said more than 750,000 malicious emails sent between 23 December and 6 January came from over 100,000 consumer devices, one a refrigerator — possibly, it said, the first proven Internet-of-Things attack. Symantec's Liam O'Murchu said the spam traced to Windows machines running Waledac, and that everything behind a home router shares one address; Proofpoint would not name a model. On 30 January Yahoo said stolen third-party credentials had been used to enter Mail accounts.
A system to watch with, no law to be watched by
India's January opened with a surveillance system, not a breach. In the first week of January the Indian press reported NETRA — network traffic analysis — built by the Centre for Artificial Intelligence and Robotics, a laboratory of the Defence Research and Development Organisation, and under test by the Intelligence Bureau and the Cabinet Secretariat. It was described as scanning tweets, status updates, email, instant messages, blogs and forums in real time for words such as attack, bomb, blast and kill, and as able to capture voice traffic on Skype and Google Talk. Deployment was being worked out by an inter-ministerial group taking in the Department of Telecommunications, the home ministry, DRDO, C-DOT and CERT-In, with 300 gigabytes of storage per node across more than a thousand nodes. No privacy statute sat behind any of it.
The card half landed differently here. A magnetic-stripe dump lifted from a register in Minneapolis was worth less in Mumbai: the Reserve Bank had required a second factor — information not visible on the card — for every online card-not-present transaction since 1 August 2009, under a circular of 18 February 2009 which also ordered alerts above Rs 5,000. Its circular of 28 February 2013 went further: EMV chip-and-PIN for new cards issued for international use, conversion of magnetic-stripe cards already used abroad, PCI-DSS terminals, velocity checks, and an interim ceiling of $500 on cards with no international history. Domestic chip migration took until the end of 2018. What India lacked was the other half of the American month — a duty to tell people. Privacy became a fundamental right in 2017, CERT-In's six-hour direction followed in 2022, and the DPDP Act in 2023.
Google buys DeepMind, IBM bets on Watson
Google confirmed on 26 January 2014 that it had bought DeepMind Technologies, a three-year-old London firm founded by Demis Hassabis, Shane Legg and Mustafa Suleyman and known chiefly for a workshop paper describing a program that learned Atari games from raw screen pixels. Google acknowledged the purchase but never a price; reports put it at about £400 million, and at more than $500 million, and had the founders making an internal ethics board a condition of the sale. It was described as Google's largest European acquisition to that date, and it produced the deep Q-network of February 2015 and the Seoul match of March 2016. IBM had moved first: on 9 January it formed a Watson Group, more than $1 billion committed, a $100 million venture fund and 2,000 staff in Manhattan, against Virginia Rometty's hope of $10 billion in annual revenue within a decade, which never arrived. Google's $3.2 billion purchase of Nest, the learning thermostat maker, was announced on 13 January and cleared American antitrust review the following month.
Intel drops a name, FireEye buys Mandiant
Two vendor decisions framed the month, both away from the tills. On 2 January 2014 FireEye announced that it had bought Mandiant — the incident-response firm called in after breaches, and the endpoint software to go with FireEye's network appliances — in a deal valued at about $1 billion, some 21.5 million shares and $106.5 million in cash, which had closed on 30 December 2013; Kevin Mandia became chief operating officer, and the company he founded was sold to Google for $5.4 billion in 2022. On 6 January, opening the Consumer Electronics Show in Las Vegas, Intel's chief executive Brian Krzanich said the McAfee brand would be retired over about a year in favour of Intel Security, the red shield kept. John McAfee, gone from the firm since 1994, said he was "everlastingly grateful" to be free of the association; Intel sold control to TPG in 2016 and the name came back. On 15 January Microsoft extended antimalware signatures for Windows XP to 14 July 2015, while warning that they would not make an unpatched machine safe.
⏳ Time capsule — January 2014
- On 1 January Latvia adopted the euro, becoming the eighteenth member of the eurozone.
- On 1 January the first shops licensed to sell recreational marijuana opened in Colorado.
- On 5 January a GSLV Mk.II placed the GSAT-14 communications satellite in orbit, the first successful flight of an Indian-built cryogenic engine.
- On 26 January Shinzo Abe, prime minister of Japan, was chief guest at the Republic Day parade in New Delhi, the first Japanese prime minister invited.
The number that did the work
Twelve years on, the two halves of January 2014 have separate afterlives. The card half ended in hardware: on 1 October 2015 the United States moved liability for counterfeit fraud to whichever party — issuer or merchant — had not adopted chip, and the swipe began its long retreat, a shift the retail intrusions of September 2014 made unavoidable. The vendor half never ended. A refrigeration contractor's credentials opening a retailer's network is the same shape as the trusted software update of December 2020, and third-party access is still the most dependable way into an otherwise well-defended organisation. The seventy million proved the more durable number: it established that a breach is counted in people reached rather than cards reissued, and that the count usually grows after the first announcement.
The smaller stories aged unevenly. Snapchat's list is now a footnote to a settlement; the Starbucks log file was a two-day story. The refrigerator was never produced, and the first Internet-of-Things botnet that genuinely mattered arrived with the cameras and recorders of October 2016 — which is why a disputed claim is worth carrying as a dispute rather than as a finding. Yahoo's January was the plain statement of the decade's most reliable technique: a password stolen from one service is a key to another. For now this is where The Vault begins. January 2014 is the oldest edition in the archive, and the restoration runs backwards from here, towards a December 2013 in which a retailer had only just started counting.