🚀 أصبحت CloudSek أول شركة للأمن السيبراني من أصل هندي تتلقى استثمارات منها
اقرأ المزيد
In 2014, attackers used credentials assigned to a Home Depot vendor to enter the retailer’s network. The intrusion later reached the payment environment and checkout systems processing customer transactions.
Approximately 56 million unique payment cards were exposed during affected transactions. Separate files containing about 53 million email addresses were also stolen. The two figures refer to separate datasets.
The investigation examined how access expanded, how long card information remained exposed, what first alerted Home Depot, and why later sources reported different victim counts. Financial filings, lawsuits, settlements, and remediation records then documented breach expenses, legal outcomes, and security changes that followed containment.
Third-party vendor credentials provided the initial entry into Home Depot’s network. The compromise later reached self-checkout systems, where malicious code exposed payment-card information.
Email-address files were also stolen. Systems tied to the compromise were isolated, the malicious software was removed from U.S. and Canadian networks, and the investigation continued after the active payment-system exposure had ended.
The documented attack path moved from third-party network entry to elevated rights, internal navigation, and malware deployment on self-checkout systems.
A username and password assigned to a third-party Home Depot vendor had been stolen before they were used against the retailer. Those credentials opened the network perimeter, although the November 2014 disclosure does not explain how they were originally stolen.
Point-of-sale devices remained beyond the credentials’ direct reach, so further progress required elevated rights.
The attackers later acquired elevated rights. Home Depot did not identify the account changes, vulnerabilities, or administrative mechanism used to obtain them.
Those rights allowed navigation across portions of the company’s network. No detailed route, segmentation path, or list of traversed systems was published.
Unique, custom-built malware was deployed to self-checkout systems in stores across the United States and Canada. Reaching those terminals connected the earlier network activity with the payment-card breach.
Public disclosures did not state why self-checkout systems were selected or explain the software’s collection mechanism. RAM scraping, memory extraction, or another specific capture technique therefore cannot be treated as established from those filings alone. Payment-card data was exposed after malicious code reached the checkout environment, but the collection method remains unspecified.
The breach unfolded across several 2014 milestones, with each date marking a separate stage of the incident.
Sources use multiple start and end dates because each marks a separate stage of the breach. The April-to-September period refers to when malware was believed to have been present, while April 10 through September 13 is the U.S. self-checkout transaction window defined by the consumer settlement. September 2 marks the start of the investigation, September 8 the public confirmation, and September 18 the announcement that the malware had been eliminated. None of those dates establishes the precise day the attackers first entered the network.
The breach involved payment-card information from in-store transactions and files containing millions of email addresses.
Approximately 56 million unique payment cards were put at risk across Home Depot stores in the United States and Canada. U.S. settlement records specifically cover customers who used credit or debit cards at self-checkout lanes during the defined transaction window.
Public filings identify the exposed records as payment-card data but do not provide a field-by-field inventory. The records belonged to the in-store payment environment; the later email disclosure concerned a separate set of files.
About 53 million email addresses were taken in separate files. Those records did not contain passwords, payment-card information, or other sensitive personal information. How the files were obtained remains unspecified in the public findings, and their theft was not attributed to the self-checkout malware.
One figure counts unique payment cards, while the other counts email addresses. The available evidence does not quantify overlap between the two sets. Adding 56 million and 53 million therefore would not produce a verified total of affected individuals.
The files holding the email addresses did not contain passwords. Home Depot also reported no evidence that debit PIN numbers were compromised.
No evidence was found that the breach affected customers who shopped online at HomeDepot.com or HomeDepot.ca. Public filings tied the card exposure to self-checkout systems in U.S. and Canadian stores.
Home Depot’s filings distinguish gross breach expenses from expected insurance recoveries, so the financial impact cannot be represented accurately by a single headline figure.
The $261 million figure represents the cumulative pretax gross expenses Home Depot had recorded by January 31, 2016. It reflects the financial impact recognized before expected insurance recoveries were applied.
Because the amount is a gross accounting figure, it should not be treated as the company’s final net expense. Insurance offsets changed the amount Home Depot ultimately reported on a pretax basis.
Home Depot expected to recover $100 million through insurance. Those proceeds offset part of the breach-related expenses already recorded. The insurance amount does not reduce the original gross figure itself. Instead, it explains the difference between the $261 million in gross expenses and the lower net pretax amount.
After accounting for the expected $100 million in insurance recoveries, Home Depot reported $161 million in net pretax expenses.
The calculation is straightforward:
$261 million gross expenses - $100 million expected insurance recoveries = $161 million net pretax expenses. For that reason, $261 million and $161 million should not be presented as competing estimates of the breach cost. They describe the same recorded financial impact at different stages of the accounting treatment: before and after expected insurance recoveries.
The legal aftermath included a 2016 consumer settlement and a 2020 multistate agreement.
A consumer settlement filed in 2016 established a $13 million fund for eligible customers and also provided identity-monitoring benefits. Eligibility was tied to people whose payment information was compromised after using a credit or debit card at a U.S. Home Depot self-checkout lane during the settlement-defined period.
On November 24, 2020, Home Depot reached an agreement with 46 states and the District of Columbia. The settlement required $17.5 million in payments and specified information-security measures.
Home Depot’s response combined immediate containment with payment-security work already underway, followed years later by formal requirements imposed through the 2020 multistate settlement.
The attackers’ method of entry was closed off, and the malware was eliminated from U.S. and Canadian networks. The exact technical step used to shut down the entry route was not disclosed.
An enhanced payment-data encryption project had begun in January 2014, before the breach became public, but implementation was accelerated afterward. Deployment across U.S. stores was completed in September 2014, with Canadian rollout planned for early 2015.
The encryption and EMV projects also required nearly 85,000 new PIN pads. Home Depot’s U.S. EMV program had started in January 2013, so chip-card technology was not introduced because of the breach. The company continued the rollout on an accelerated schedule, while Canadian stores already used the technology.
The multistate agreement added formal controls around risk assessment, penetration testing, intrusion detection, encryption, logging and monitoring, two-factor authentication, vendor-account management, and a post-settlement information-security assessment.
Relevant personnel were also required to receive security-awareness and privacy training. A qualified CISO was required to report security posture and risks to senior leadership and the board, with adequate resources assigned to the information-security program.
The Home Depot case shows why third-party access cannot be judged only by a vendor account’s initial permissions. A foothold that stops short of payment systems can still become consequential if later privilege changes and internal movement expand its reach.
Payment cards, email addresses, accounting expenses, insurance recoveries, and settlement amounts measure separate parts of the incident. Keeping those units distinct prevents technical scope and financial impact from collapsing into one misleading headline number.
No. Home Depot described the code as unique, custom-built malware deployed to self-checkout systems. Its primary disclosures did not identify the malware as BlackPOS, so that name should not be presented as Home Depot’s official attribution.
Yes. The payment-card exposure involved stores in both the United States and Canada, and the malware was later confirmed as eliminated from networks in both countries.
No. Home Depot specifically reported that the stolen third-party credentials did not provide direct access to its POS devices. Elevated rights and further movement through the network were required before the intrusion reached self-checkout systems.
The files containing approximately 53 million email addresses did not contain passwords. Home Depot also reported no evidence that debit PIN numbers were compromised.
Home Depot reported no evidence that the breach affected customers who shopped online at HomeDepot.com or HomeDepot.ca.
The dates mark separate stages of the incident. April 2014 falls within the period when malware was believed to have been present, while April 10 through September 13 was the U.S. self-checkout transaction window used in the consumer settlement. September 2 marked the start of Home Depot’s investigation, September 8 the public confirmation, and September 18 the announcement that the malware had been eliminated. None of those dates establishes the exact day the attackers first entered the network.
