Home Depot 2014 Breach Exposed Millions of Payment Cards and Emails
In 2014, Home Depot suffered a massive data breach that exposed 56 million payment cards and 53 million email addresses. The attack began when hackers used stolen credentials from a third-party vendor to gain access to the retailer’s network. From there, they elevated their privileges and navigated through the internal systems until they reached the self-checkout systems, where they deployed custom malware to capture payment-card information.
The breach unfolded over several months, with key milestones including the presence of malware between April and September 2014, the start of the investigation on September 2, and the public confirmation of the breach on September 8. By September 18, Home Depot had eliminated the malware from U.S. and Canadian networks and disclosed that approximately 56 million unique payment cards were compromised. The theft of 53 million email addresses was reported later, on November 6.
The financial impact of the breach was significant, with Home Depot recording $261 million in gross expenses by January 31, 2016. This figure was partially offset by $100 million in expected insurance recoveries, resulting in a net pretax expense of $161 million. The breach highlighted the vulnerabilities associated with third-party vendor credentials and the importance of robust network security measures.