Home Depot Data Breach 2014: How 56M Cards and 53M Emails Were Exposed

Home Depot’s 2014 breach exposed 56M payment cards and 53M emails after stolen vendor credentials led to malware on self-checkout systems.
تم كتابته بواسطة
تم النشر في
Wednesday, October 7, 2026
تم التحديث بتاريخ
October 7, 2026

In 2014, attackers used credentials assigned to a Home Depot vendor to enter the retailer’s network. The intrusion later reached the payment environment and checkout systems processing customer transactions.

Approximately 56 million unique payment cards were exposed during affected transactions. Separate files containing about 53 million email addresses were also stolen. The two figures refer to separate datasets.

The investigation examined how access expanded, how long card information remained exposed, what first alerted Home Depot, and why later sources reported different victim counts. Financial filings, lawsuits, settlements, and remediation records then documented breach expenses, legal outcomes, and security changes that followed containment.

What Happened in the 2014 Home Depot Data Breach?

Third-party vendor credentials provided the initial entry into Home Depot’s network. The compromise later reached self-checkout systems, where malicious code exposed payment-card information.

Email-address files were also stolen. Systems tied to the compromise were isolated, the malicious software was removed from U.S. and Canadian networks, and the investigation continued after the active payment-system exposure had ended.

How Did Hackers Get Into Home Depot?

The documented attack path moved from third-party network entry to elevated rights, internal navigation, and malware deployment on self-checkout systems.

Stolen Vendor Credentials and the POS Access Limit

A username and password assigned to a third-party Home Depot vendor had been stolen before they were used against the retailer. Those credentials opened the network perimeter, although the November 2014 disclosure does not explain how they were originally stolen.

Point-of-sale devices remained beyond the credentials’ direct reach, so further progress required elevated rights.

Elevated Rights and Internal Network Movement

The attackers later acquired elevated rights. Home Depot did not identify the account changes, vulnerabilities, or administrative mechanism used to obtain them.

Those rights allowed navigation across portions of the company’s network. No detailed route, segmentation path, or list of traversed systems was published.

Self-Checkout Malware and Payment-Card Exposure

Unique, custom-built malware was deployed to self-checkout systems in stores across the United States and Canada. Reaching those terminals connected the earlier network activity with the payment-card breach.

Public disclosures did not state why self-checkout systems were selected or explain the software’s collection mechanism. RAM scraping, memory extraction, or another specific capture technique therefore cannot be treated as established from those filings alone. Payment-card data was exposed after malicious code reached the checkout environment, but the collection method remains unspecified.

Home Depot Data Breach Timeline

The breach unfolded across several 2014 milestones, with each date marking a separate stage of the incident.

Date Event Significance
April 2014 Malware believed present Home Depot later determined that malicious software was present sometime between April and September 2014. April is not a confirmed network-entry date.
April 10, 2014 U.S. self-checkout exposure window begins The consumer settlement uses April 10 as the start of the affected U.S. self-checkout transaction period.
September 2, 2014 Investigation begins Banking partners and law enforcement reported that criminals may have breached company systems, prompting an investigation that morning.
September 8, 2014 Breach publicly confirmed Home Depot announced that its payment-data systems had been breached and said card users at U.S. and Canadian stores could potentially be affected.
September 13, 2014 U.S. self-checkout exposure window ends Settlement documents use September 13 as the end of the affected U.S. transaction period. It is not the confirmed malware-removal date.
September 18, 2014 56M-card scope disclosed; malware elimination confirmed Approximately 56 million unique payment cards were estimated to have been put at risk, and the malware had been eliminated from U.S. and Canadian networks.
November 6, 2014 53M email addresses disclosed Separate files containing about 53 million email addresses were reported stolen, alongside additional findings on the intrusion path.

Sources use multiple start and end dates because each marks a separate stage of the breach. The April-to-September period refers to when malware was believed to have been present, while April 10 through September 13 is the U.S. self-checkout transaction window defined by the consumer settlement. September 2 marks the start of the investigation, September 8 the public confirmation, and September 18 the announcement that the malware had been eliminated. None of those dates establishes the precise day the attackers first entered the network.

What Data Was Stolen in the Home Depot Breach?

The breach involved payment-card information from in-store transactions and files containing millions of email addresses.

56 Million Payment Cards

Approximately 56 million unique payment cards were put at risk across Home Depot stores in the United States and Canada. U.S. settlement records specifically cover customers who used credit or debit cards at self-checkout lanes during the defined transaction window.

Public filings identify the exposed records as payment-card data but do not provide a field-by-field inventory. The records belonged to the in-store payment environment; the later email disclosure concerned a separate set of files.

53 Million Email Addresses

About 53 million email addresses were taken in separate files. Those records did not contain passwords, payment-card information, or other sensitive personal information. How the files were obtained remains unspecified in the public findings, and their theft was not attributed to the self-checkout malware.

How the Two Counts Relate

One figure counts unique payment cards, while the other counts email addresses. The available evidence does not quantify overlap between the two sets. Adding 56 million and 53 million therefore would not produce a verified total of affected individuals.

Were Passwords, PINs, or Online Purchases Affected?

The files holding the email addresses did not contain passwords. Home Depot also reported no evidence that debit PIN numbers were compromised.

No evidence was found that the breach affected customers who shopped online at HomeDepot.com or HomeDepot.ca. Public filings tied the card exposure to self-checkout systems in U.S. and Canadian stores.

How Much Did the Home Depot Data Breach Cost?

Home Depot’s filings distinguish gross breach expenses from expected insurance recoveries, so the financial impact cannot be represented accurately by a single headline figure. 

Financial Item Amount Meaning / Description
Gross breach-related expenses $261 million Cumulative pretax gross expenses recorded by January 31, 2016.
Expected insurance recoveries $100 million Expected proceeds offsetting part of the recorded expense.
Net pretax expenses $161 million Net expenses after subtracting expected insurance recoveries from gross expenses ($261M - $100M).

$261 Million in Gross Expenses

The $261 million figure represents the cumulative pretax gross expenses Home Depot had recorded by January 31, 2016. It reflects the financial impact recognized before expected insurance recoveries were applied.

Because the amount is a gross accounting figure, it should not be treated as the company’s final net expense. Insurance offsets changed the amount Home Depot ultimately reported on a pretax basis.

$100 Million in Expected Insurance Recoveries

Home Depot expected to recover $100 million through insurance. Those proceeds offset part of the breach-related expenses already recorded. The insurance amount does not reduce the original gross figure itself. Instead, it explains the difference between the $261 million in gross expenses and the lower net pretax amount.

$161 Million in Net Pretax Expenses

After accounting for the expected $100 million in insurance recoveries, Home Depot reported $161 million in net pretax expenses.

The calculation is straightforward:

$261 million gross expenses - $100 million expected insurance recoveries = $161 million net pretax expenses. For that reason, $261 million and $161 million should not be presented as competing estimates of the breach cost. They describe the same recorded financial impact at different stages of the accounting treatment: before and after expected insurance recoveries.

What Lawsuits and Settlements Followed the Home Depot Breach?

The legal aftermath included a 2016 consumer settlement and a 2020 multistate agreement.

Consumer Class Action

A consumer settlement filed in 2016 established a $13 million fund for eligible customers and also provided identity-monitoring benefits. Eligibility was tied to people whose payment information was compromised after using a credit or debit card at a U.S. Home Depot self-checkout lane during the settlement-defined period.

Multistate Settlement

On November 24, 2020, Home Depot reached an agreement with 46 states and the District of Columbia. The settlement required $17.5 million in payments and specified information-security measures.

What Did Home Depot Change After the Breach?

Home Depot’s response combined immediate containment with payment-security work already underway, followed years later by formal requirements imposed through the 2020 multistate settlement.

Immediate Response and Payment-Security Changes

The attackers’ method of entry was closed off, and the malware was eliminated from U.S. and Canadian networks. The exact technical step used to shut down the entry route was not disclosed.

An enhanced payment-data encryption project had begun in January 2014, before the breach became public, but implementation was accelerated afterward. Deployment across U.S. stores was completed in September 2014, with Canadian rollout planned for early 2015.

The encryption and EMV projects also required nearly 85,000 new PIN pads. Home Depot’s U.S. EMV program had started in January 2013, so chip-card technology was not introduced because of the breach. The company continued the rollout on an accelerated schedule, while Canadian stores already used the technology.

2020 Settlement-Mandated Security Requirements

The multistate agreement added formal controls around risk assessment, penetration testing, intrusion detection, encryption, logging and monitoring, two-factor authentication, vendor-account management, and a post-settlement information-security assessment.

Relevant personnel were also required to receive security-awareness and privacy training. A qualified CISO was required to report security posture and risks to senior leadership and the board, with adequate resources assigned to the information-security program.

Final Thoughts

The Home Depot case shows why third-party access cannot be judged only by a vendor account’s initial permissions. A foothold that stops short of payment systems can still become consequential if later privilege changes and internal movement expand its reach.

Payment cards, email addresses, accounting expenses, insurance recoveries, and settlement amounts measure separate parts of the incident. Keeping those units distinct prevents technical scope and financial impact from collapsing into one misleading headline number.

Frequently Asked Questions

Was BlackPOS officially confirmed as the Home Depot malware?

No. Home Depot described the code as unique, custom-built malware deployed to self-checkout systems. Its primary disclosures did not identify the malware as BlackPOS, so that name should not be presented as Home Depot’s official attribution.

Were Home Depot stores in Canada affected?

Yes. The payment-card exposure involved stores in both the United States and Canada, and the malware was later confirmed as eliminated from networks in both countries.

Did the stolen vendor credentials provide direct access to point-of-sale systems?

No. Home Depot specifically reported that the stolen third-party credentials did not provide direct access to its POS devices. Elevated rights and further movement through the network were required before the intrusion reached self-checkout systems.

Were customer passwords or debit PINs compromised?

The files containing approximately 53 million email addresses did not contain passwords. Home Depot also reported no evidence that debit PIN numbers were compromised.

Were HomeDepot.com or HomeDepot.ca purchases affected?

Home Depot reported no evidence that the breach affected customers who shopped online at HomeDepot.com or HomeDepot.ca.

Why do different sources give different dates for the Home Depot breach?

The dates mark separate stages of the incident. April 2014 falls within the period when malware was believed to have been present, while April 10 through September 13 was the U.S. self-checkout transaction window used in the consumer settlement. September 2 marked the start of Home Depot’s investigation, September 8 the public confirmation, and September 18 the announcement that the malware had been eliminated. None of those dates establishes the exact day the attackers first entered the network.

المشاركات ذات الصلة
Malware vs. Virus vs. Worm: How They Spread, Examples & Key Differences
Malware is malicious software; viruses replicate inside a host file, and worms spread as standalone programs. Their replication methods determine how infections continue.
12 SaaS Security Threats and How to Mitigate Them
SaaS security threats include stolen credentials, session hijacking, and data loss. Mitigation requires secure sign-ins, limited permissions, and controlled integrations.
Capital One Data Breach (2019): Attack Path, Root Causes, and Cloud Security Lessons
The Capital One breach shows how a misconfigured WAF, AWS credentials, IAM permissions, and S3 access formed an attack path, plus where cloud defenses can stop it today.

ابدأ العرض التوضيحي الخاص بك الآن!

جدولة عرض تجريبي
إصدار تجريبي مجاني لمدة 7 أيام
لا توجد التزامات
قيمة مضمونة بنسبة 100%

مقالات قاعدة المعارف ذات الصلة

لم يتم العثور على أية عناصر.