In 2013, the American retailer Target announced that the credit-card details of around 40 million customers had been stolen during the busy shopping period before Christmas. The breach was traced to an unlikely source: not Target's own systems, but a small company that maintained the shop's air-conditioning units. Login details belonging to that company had been phished, and once the attackers were inside the supplier's network, they were able to move sideways into Target's payment systems. The full clean-up is estimated to have cost Target more than 200 million dollars, and the head of the company was replaced within months. It is now widely accepted that a company is only as secure as its weakest supplier.
