Home Depot’s 2014 breach resembled Target’s in its broad outline: attackers used vendor-related access to move through a retailer’s network and reach payment systems. But the available accounts do not establish that the two attacks used identical methods or were carried out by the same operation. Home Depot said intruders used stolen vendor credentials, later gained elevated access, and installed custom malware on self-checkout systems.
How did hackers get into Home Depot’s network?
In its 2014 disclosures, Home Depot said attackers entered its network perimeter using a third-party vendor’s username and password. The credentials did not, by themselves, give the intruders direct access to point-of-sale devices. The company said the attackers later acquired elevated privileges, moved through parts of the network, and installed custom-built malware on self-checkout systems in the United States and Canada. Home Depot’s SEC filing and company updates describe that sequence.
Home Depot said the malware was designed to evade antivirus detection and had not been seen in earlier attacks, according to its security partners. That description supports a distinction between the initial foothold and the later compromise of checkout systems: vendor credentials opened a path into the network, while additional access and malware were needed to reach payment data.
What information was stolen in the Home Depot breach?
Payment-card data
Home Depot said it believed the malware was present from April through September 2014 and estimated that approximately 56 million unique payment cards were put at risk across its U.S. and Canadian stores. The company’s figure is an estimate of unique cards at risk, not a count that should automatically be treated as a count of consumers.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
A later account gives a different measure. In announcing a 2020 multistate settlement, the Colorado Attorney General described card information belonging to about 40 million consumers as exposed, and specified that the state’s account covered self-checkout purchases at U.S. stores from April 10 to September 13, 2014. That figure is not a correction or direct equivalent of Home Depot’s 56 million-card estimate: the sources use different wording and scopes. The Colorado announcement does not establish a like-for-like methodology between the two figures.
Email addresses
In a separate disclosure, Home Depot said files containing approximately 53 million email addresses had been taken. It said those files did not contain passwords, payment-card data, or other sensitive personal information, and warned customers to watch for phishing attempts. An exposed email address can still make a convincing scam easier to deliver, so an unexpected message claiming to be from a retailer or bank should be checked through a known official channel rather than by following its links.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
What the company said was not affected
Home Depot reported at the time that it had no evidence debit PIN numbers were compromised, that Mexico stores or online customers were affected, or that HomeDepot.com or HomeDepot.ca were impacted. These are the company’s statements about its investigation, not independent guarantees about every possible exposure.
How was the Home Depot data breach similar to Target’s?
Both incidents were major retail payment-data breaches in which attackers moved from vendor-related or network access toward point-of-sale systems. A 2018 U.S. House hearing cited 110 million affected in Target’s 2013 breach and 56 million in Home Depot’s 2014 breach. Those are figures cited by the hearing; they should not be read as identical measures of the same thing. The hearing record provides the comparison.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
| Dimension | Target, 2013 | Home Depot, 2014 |
|---|---|---|
| Entry and movement | Congressional Research Service (CRS) describes access escalating from vendor billing and invoicing access into Target’s point-of-sale system. CRS report | Home Depot said a third-party vendor’s credentials provided network entry, but not direct POS access; attackers later gained elevated rights and reached self-checkout systems. SEC filing |
| Payment systems and channel | CRS describes compromise of Target’s POS system. The sources cited here do not specify further channel detail. | Custom malware was deployed on self-checkout systems at U.S. and Canadian stores, according to Home Depot. |
| Reported scale | 110 million affected, as cited by the 2018 House hearing. | 56 million, as cited by the same hearing; Home Depot’s own 2014 disclosure described approximately 56 million unique payment cards at risk. |
| Malware comparison | CRS reported that security blogger Brian Krebs attributed Home Depot’s breach to malware also used against Target. This is an attributed claim, not an official investigative conclusion established by the cited sources. CRS report | |
The comparison is useful for understanding the shared risk: a vendor relationship can provide a foothold that attackers try to turn into access to payment infrastructure. It does not show that the two retailers had the same access sequence, compromised the same systems in the same way, or faced the same attackers.
How did Home Depot respond, and what followed?
On September 18, 2014, Home Depot said it had eliminated the malware, closed the method of entry, and completed enhanced payment-data encryption in U.S. stores. It also said it was rolling out EMV chip-and-PIN technology in U.S. stores; Canadian stores already had EMV. A November update said the entry method had been closed and the malware removed. These are remediation steps the company reported, not proof that every risk associated with the incident had disappeared.
Rank #4
Home Depot offered free identity-protection services, including credit monitoring, to customers who had used a payment card at a store from April 2014 onward. That was a historical offer in the company’s 2014 disclosures; the cited sources do not establish that enrollment remains available. The company’s CEO, Frank Blake, said in its September 18 disclosure: “We apologize to our customers for the inconvenience and anxiety this has caused, and want to reassure them that they will not be liable for fraudulent charges.”
In November 2020, Colorado’s Attorney General announced that a multistate investigation had resulted in a $17.5 million payment to states and required Home Depot to maintain security practices. The listed measures included a qualified chief information security officer, staff training, logging and monitoring, access controls, password management, two-factor authentication, file-integrity monitoring, firewalls, encryption, risk assessments, penetration testing, intrusion detection, and vendor-account management. The state’s announcement describes the settlement and its requirements.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
What the comparison means for customers
The incident shows why a retailer’s security depends on more than its own employee accounts: a vendor credential can be a starting point, and access controls must limit how far an intruder can move from that foothold. For customers, the practical distinction is that the payment-card exposure and the separately disclosed email-address theft were described as different data sets. Home Depot said the email files contained no card data or passwords, but warned that phishing remained a concern.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




