Skip to main content
Breach Signal

Breach report

Retail

Home Depot

Home Depot: 56M Cards Impacted, Malware Contained

Custom malware on Home Depot's self-checkout and register systems skimmed about 56 million payment cards over five months in 2014, surpassing Target's breach and becoming the largest retail card theft on record at the time.

Reported by Krebs on Security

Records exposed

56M

56 million payment cards and 53 million email addresses

Scale vs. largest on file

When
2014
How they got in
Custom point-of-sale malware via stolen vendor credentials
Sector
Retail

On September 2, 2014, Krebs on Security reported that a large batch of stolen payment cards appearing on an underground market appeared to trace back to Home Depot stores. The home improvement chain confirmed a breach days later, and on September 18 it disclosed the scale: roughly 56 million debit and credit cards used at its U.S. and Canadian stores between April and September 2014 were likely compromised. That figure eclipsed both the Target breach of the previous year and the TJX incident, making it the biggest retail card compromise known at the time.

Home Depot said attackers used custom-built malware that had not been seen in previous attacks, designed to evade antivirus detection. Investigators focused on self-checkout lanes, and the company later explained that the intruders first obtained a third-party vendor's username and password, then escalated privileges to gain access to the retailer's wider network before deploying the card-stealing code to point-of-sale systems. The attackers retained some access until early September, days after the breach became public.

In November 2014, Home Depot added that separate files containing about 53 million customer email addresses had also been stolen, raising the risk of targeted phishing. The company said PINs were not taken and that it had completed a rollout of enhanced payment encryption across its U.S. stores, with Canadian stores to follow. Customers were offered free identity protection and credit monitoring.

The financial consequences stretched over several years. Home Depot agreed to pay at least $19.5 million to settle consumer claims, reached a separate settlement worth more than $25 million with banks and credit unions that had reissued cards, and in 2020 agreed to a $17.5 million settlement with 46 states and the District of Columbia. Its total net costs from the breach ran well above $150 million. Shareholder derivative suits argued that executives had ignored warnings about outdated security.

Coming less than a year after Target, the Home Depot breach showed that retailers had not yet absorbed the lessons of vendor-driven intrusions and unencrypted card data at the register. It added pressure on the U.S. payments industry to adopt chip cards and point-to-point encryption, and on retailers to restrict what supplier accounts can reach. For shoppers, the stolen email list was a reminder that a breach often yields secondary data useful for scams long after cards are replaced.

More from the wire

More in Retail.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.