It's beginning to look like the hackers who got into Target's computer network did so by first hijacking the computers of an unlikely source—a company near Pittsburgh that provides refrigeration, heating, and A/C service to the chain, reports KrebsOnSecurity. Once hackers gained access to Fazio Mechanical Service's network, they were somehow able to get into Target's payment system. Fazio has confirmed that it got hit by a "sophisticated cyberattack operation" and is cooperating with the Secret Service and Target to figure out what happened.
Fazio says it submits bills and contract proposals to Target electronically, and that is presumably where the vulnerability occurred. That surprises security expert Chester Wisniewski of Sophos, who tells AP that something probably went wrong on Target's end. "If normal practices were followed, they wouldn't have been able to get access," he says. It's not clear what kind of setup Target had, but companies are not required to keep consumer information on a separate network, he adds.