Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Home Depot said attackers entered its network using a third-party vendor’s credentials, gained elevated access, and installed custom-built malware on self-checkout systems. The company estimated that approximately 56 million unique payment cards were put at risk. It later disclosed that separate files containing approximately 53 million email addresses were also taken.

How did hackers get into Home Depot?

According to Home Depot, the attackers used a third-party vendor’s username and password to cross the company’s network perimeter. Those credentials did not provide direct access to point-of-sale devices. The attackers then obtained elevated rights, which enabled them to deploy malware on self-checkout systems.

Home Depot’s SEC filing describes the malware as custom-built and says it was used to access payment-card information on self-checkout systems. The company’s account identifies the vendor credentials as the initial route into the network—not as proof that the supplier itself intentionally participated in the attack.

Home Depot did not name the vendor or identify the attackers in the cited disclosures. Its account of the intrusion path is the company’s reported finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When did the breach happen?

Home Depot said the affected shopping period ran from April through September 2014 at stores in the United States and Canada. The company said it began investigating on September 2, after receiving reports from banking partners and law enforcement.

  • September 8, 2014: Home Depot publicly confirmed a breach and said its investigation focused on activity from April onward.
  • September 18, 2014: The company said it had eliminated the malware from its U.S. and Canadian networks and estimated that approximately 56 million unique payment cards were at risk.
  • November 6, 2014: Home Depot disclosed the vendor-credential entry route and reported that separate files containing approximately 53 million email addresses had been taken.

How many credit cards and email addresses were affected?

Home Depot estimated that approximately 56 million unique payment cards were put at risk. That figure is the company’s estimate of cards at risk, announced on September 18, 2014; it is not the email-address count.

On November 6, Home Depot separately reported that approximately 53 million email addresses had been taken from files distinct from the payment-card data. These are two different data categories, and the company reported them separately.

What information did Home Depot say was not affected?

Home Depot said it had no evidence that debit-card PINs were compromised. It also reported no impact to stores in Mexico or to online shoppers. These are the company’s findings as described in its disclosures, rather than a broader independent assessment of all possible exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What did Home Depot offer affected customers?

Home Depot announced free identity protection, including credit monitoring, for customers who had used a payment card in its stores from April 2014 onward. Later settlement materials described an 18-month Identity Guard Essentials benefit for eligible class members, alongside a $13 million settlement fund. The settlement FAQ describes that fund as a settlement term; it is not a measure of the company’s total losses. These were historical remedies, and the materials do not establish that enrollment is still available.

At the time, then-chairman and CEO Frank Blake said: “We apologize to our customers for the inconvenience and anxiety this has caused and want to reassure them that they will not be liable for fraudulent charges.”

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.