October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How the 2014 Home Depot Breach Echoed Target’s—Without Being the Same Attack

Home Depot’s 2014 breach and Target’s were both major retail payment-data incidents, but the reported entry paths and evidence do not establish identical attacks.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Home Depot’s 2014 breach resembled Target’s in its broad outline: attackers used vendor-related access to move through a retailer’s network and reach payment systems. But the available accounts do not establish that the two attacks used identical methods or were carried out by the same operation. Home Depot said intruders used stolen vendor credentials, later gained elevated access, and installed custom malware on self-checkout systems.

How did hackers get into Home Depot’s network?

In its 2014 disclosures, Home Depot said attackers entered its network perimeter using a third-party vendor’s username and password. The credentials did not, by themselves, give the intruders direct access to point-of-sale devices. The company said the attackers later acquired elevated privileges, moved through parts of the network, and installed custom-built malware on self-checkout systems in the United States and Canada. Home Depot’s SEC filing and company updates describe that sequence.

Home Depot said the malware was designed to evade antivirus detection and had not been seen in earlier attacks, according to its security partners. That description supports a distinction between the initial foothold and the later compromise of checkout systems: vendor credentials opened a path into the network, while additional access and malware were needed to reach payment data.

What information was stolen in the Home Depot breach?

Payment-card data

Home Depot said it believed the malware was present from April through September 2014 and estimated that approximately 56 million unique payment cards were put at risk across its U.S. and Canadian stores. The company’s figure is an estimate of unique cards at risk, not a count that should automatically be treated as a count of consumers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A later account gives a different measure. In announcing a 2020 multistate settlement, the Colorado Attorney General described card information belonging to about 40 million consumers as exposed, and specified that the state’s account covered self-checkout purchases at U.S. stores from April 10 to September 13, 2014. That figure is not a correction or direct equivalent of Home Depot’s 56 million-card estimate: the sources use different wording and scopes. The Colorado announcement does not establish a like-for-like methodology between the two figures.

Email addresses

In a separate disclosure, Home Depot said files containing approximately 53 million email addresses had been taken. It said those files did not contain passwords, payment-card data, or other sensitive personal information, and warned customers to watch for phishing attempts. An exposed email address can still make a convincing scam easier to deliver, so an unexpected message claiming to be from a retailer or bank should be checked through a known official channel rather than by following its links.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

What the company said was not affected

Home Depot reported at the time that it had no evidence debit PIN numbers were compromised, that Mexico stores or online customers were affected, or that HomeDepot.com or HomeDepot.ca were impacted. These are the company’s statements about its investigation, not independent guarantees about every possible exposure.

How was the Home Depot data breach similar to Target’s?

Both incidents were major retail payment-data breaches in which attackers moved from vendor-related or network access toward point-of-sale systems. A 2018 U.S. House hearing cited 110 million affected in Target’s 2013 breach and 56 million in Home Depot’s 2014 breach. Those are figures cited by the hearing; they should not be read as identical measures of the same thing. The hearing record provides the comparison.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Dimension Target, 2013 Home Depot, 2014
Entry and movement Congressional Research Service (CRS) describes access escalating from vendor billing and invoicing access into Target’s point-of-sale system. CRS report Home Depot said a third-party vendor’s credentials provided network entry, but not direct POS access; attackers later gained elevated rights and reached self-checkout systems. SEC filing
Payment systems and channel CRS describes compromise of Target’s POS system. The sources cited here do not specify further channel detail. Custom malware was deployed on self-checkout systems at U.S. and Canadian stores, according to Home Depot.
Reported scale 110 million affected, as cited by the 2018 House hearing. 56 million, as cited by the same hearing; Home Depot’s own 2014 disclosure described approximately 56 million unique payment cards at risk.
Malware comparison CRS reported that security blogger Brian Krebs attributed Home Depot’s breach to malware also used against Target. This is an attributed claim, not an official investigative conclusion established by the cited sources. CRS report

The comparison is useful for understanding the shared risk: a vendor relationship can provide a foothold that attackers try to turn into access to payment infrastructure. It does not show that the two retailers had the same access sequence, compromised the same systems in the same way, or faced the same attackers.

How did Home Depot respond, and what followed?

On September 18, 2014, Home Depot said it had eliminated the malware, closed the method of entry, and completed enhanced payment-data encryption in U.S. stores. It also said it was rolling out EMV chip-and-PIN technology in U.S. stores; Canadian stores already had EMV. A November update said the entry method had been closed and the malware removed. These are remediation steps the company reported, not proof that every risk associated with the incident had disappeared.

Home Depot offered free identity-protection services, including credit monitoring, to customers who had used a payment card at a store from April 2014 onward. That was a historical offer in the company’s 2014 disclosures; the cited sources do not establish that enrollment remains available. The company’s CEO, Frank Blake, said in its September 18 disclosure: “We apologize to our customers for the inconvenience and anxiety this has caused, and want to reassure them that they will not be liable for fraudulent charges.”

In November 2020, Colorado’s Attorney General announced that a multistate investigation had resulted in a $17.5 million payment to states and required Home Depot to maintain security practices. The listed measures included a qualified chief information security officer, staff training, logging and monitoring, access controls, password management, two-factor authentication, file-integrity monitoring, firewalls, encryption, risk assessments, penetration testing, intrusion detection, and vendor-account management. The state’s announcement describes the settlement and its requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the comparison means for customers

The incident shows why a retailer’s security depends on more than its own employee accounts: a vendor credential can be a starting point, and access controls must limit how far an intruder can move from that foothold. For customers, the practical distinction is that the payment-card exposure and the separately disclosed email-address theft were described as different data sets. Home Depot said the email files contained no card data or passwords, but warned that phishing remained a concern.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.