Home Depot said attackers entered its network using a third-party vendor’s credentials, gained elevated access, and installed custom-built malware on self-checkout systems. The company estimated that approximately 56 million unique payment cards were put at risk. It later disclosed that separate files containing approximately 53 million email addresses were also taken.
How did hackers get into Home Depot?
According to Home Depot, the attackers used a third-party vendor’s username and password to cross the company’s network perimeter. Those credentials did not provide direct access to point-of-sale devices. The attackers then obtained elevated rights, which enabled them to deploy malware on self-checkout systems.
Home Depot’s SEC filing describes the malware as custom-built and says it was used to access payment-card information on self-checkout systems. The company’s account identifies the vendor credentials as the initial route into the network—not as proof that the supplier itself intentionally participated in the attack.
Home Depot did not name the vendor or identify the attackers in the cited disclosures. Its account of the intrusion path is the company’s reported finding.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
When did the breach happen?
Home Depot said the affected shopping period ran from April through September 2014 at stores in the United States and Canada. The company said it began investigating on September 2, after receiving reports from banking partners and law enforcement.
- September 8, 2014: Home Depot publicly confirmed a breach and said its investigation focused on activity from April onward.
- September 18, 2014: The company said it had eliminated the malware from its U.S. and Canadian networks and estimated that approximately 56 million unique payment cards were at risk.
- November 6, 2014: Home Depot disclosed the vendor-credential entry route and reported that separate files containing approximately 53 million email addresses had been taken.
How many credit cards and email addresses were affected?
Home Depot estimated that approximately 56 million unique payment cards were put at risk. That figure is the company’s estimate of cards at risk, announced on September 18, 2014; it is not the email-address count.
On November 6, Home Depot separately reported that approximately 53 million email addresses had been taken from files distinct from the payment-card data. These are two different data categories, and the company reported them separately.
What information did Home Depot say was not affected?
Home Depot said it had no evidence that debit-card PINs were compromised. It also reported no impact to stores in Mexico or to online shoppers. These are the company’s findings as described in its disclosures, rather than a broader independent assessment of all possible exposure.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What did Home Depot offer affected customers?
Home Depot announced free identity protection, including credit monitoring, for customers who had used a payment card in its stores from April 2014 onward. Later settlement materials described an 18-month Identity Guard Essentials benefit for eligible class members, alongside a $13 million settlement fund. The settlement FAQ describes that fund as a settlement term; it is not a measure of the company’s total losses. These were historical remedies, and the materials do not establish that enrollment is still available.
At the time, then-chairman and CEO Frank Blake said: “We apologize to our customers for the inconvenience and anxiety this has caused and want to reassure them that they will not be liable for fraudulent charges.”
Quick Recap
Best Value
Sources
- Home Depot’s September 18, 2014 update
- Home Depot’s November 6, 2014 disclosure
- Home Depot SEC filing
- Home Depot’s September 8, 2014 announcement
- Home Depot Breach Settlement FAQ
- Settlement materials describing Identity Guard Essentials
- Contemporary report quoting Frank Blake
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

