2013 Mega Data Breach — payment cards & PII
Data compromised
Email addresses, Names, Addresses, Phone numbers, Payment card details, Card numbers, Personal identifiable information, Payment information, Credit/financial data, Internal documents
Technical writeup
Initial entry via phishing attack on third-party HVAC vendor (Fazio Mechanical). Lack of internal network segmentation allowed lateral movement from vendor portal to POS systems. RAM-scraping malware (Kaptoxa) stole card data during decryption in memory. Exposed: credit/debit card numbers (40M+), CVV codes, names, addresses, emails, phone numbers.
Root cause
Phishing on third-party HVAC vendor; weak network segmentation; RAM-scraping malware on POS systems.