Back to the archive

The encyclopedia · Software & IT · Operational decision · 2014

Home Depot's breach stole 56M payment cards — the hackers used a vendor's credentials

In 2014, hackers stole 56M payment card numbers from Home Depot using a vendor's credentials. It was the largest retail breach at the time.

Home Depot · 2014-09

What happened

In September 2014, Home Depot disclosed that hackers had stolen approximately 56 million payment card numbers from its point-of-sale systems. The breach, which lasted from April to September 2014, was the largest retail data breach at the time, surpassing the Target breach of 2013.

The hackers gained access using credentials stolen from a third-party vendor, then installed malware on Home Depot's self-checkout systems. The malware captured card data as customers swiped their cards. Home Depot's security team detected unusual activity but did not identify the breach for several months.

Home Depot paid over $200 million in settlements, legal costs and security upgrades. The case illustrated the same supply chain vulnerability as the Target breach: a third-party vendor's credentials became the entry point for a catastrophic breach. The case prompted the retail industry to accelerate the adoption of EMV chip card technology.

Why it happened

  • Hackers used credentials stolen from a third-party vendor to access Home Depot's systems.
  • Malware was installed on self-checkout systems, capturing card data.
  • 56M payment card numbers were stolen over 5 months.
  • Home Depot paid $200M+ in costs.
What it cost56M cards; $200M+ in costscostly

The lesson

Your network is only as secure as your least-secure vendor. Home Depot's hackers walked in through a vendor's credentials, just like Target's. Vendor access is a security imperative.

Aftermath

Home Depot paid $200M+ and overhauled its security. The case accelerated the US retail industry's adoption of EMV chip cards. It is cited alongside Target as an example of supply chain vulnerability in retail.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →