Categories: SecurityWorkspace

Home Depot Confirms Massive Security Breach

US retailer Home Depot has confirmed a security breach in the payment systems of its stores in North America that resulted in the theft of credit and debit card data,

It has been suggested this could be  largest such incident to date and the company has said customers could have been affected from April until early last week, but added the PINs used to secure the cards did not seem to have been compromised.

The retailer said it has not yet determined the number of customers affected, but the figure could exceed 60 million, according to an unnamed source cited by The New York Times.

The Home Depot 2Biggest to date?

The breach of retail chain Target last year, currently the largest to date, affected about 40 million people, and occurred over a period of about three weeks, while the Home Depot compromise may have lasted for as long as five months.

The chain’s Mexico stores were not affected, nor was its online shop. Home Depot operates 1,977 stores in the US and 180 in Canada, about 400 more than Target had at the time of its breach.

Delayed response

The incident was first reported by blogger Brian Krebs early last week, and it seems to have been this report that alerted the company itself to the situation. The retailer had remained silent until now. Home Depot apologised for the breach, saying it had delayed notifying customers until its own investigation had confirmed the incident.

“We owe it to our customers to alert them that we now have enough evidence to confirm that a breach has indeed occurred,” said chairman and chief executive Frank Blake in a statement. “It’s important to emphasize that no customers will be responsible for fraudulent charges to their accounts.”

Customers in the US state of Georgia filed a class-action lawsuit against the company last week for failing to protect customers and not alerting them sooner. Home Depot said it will offer identity protection and credit-monitoring services to those who used a card at any of its affected stores, adding that it has been working with security companies Symantec and FishNet Security to investigate since last week.

In August, the US Computer Emergency Readiness Team (US-CERT) warned that the point-of-sale systems of about 1,000 retailers had been compromised by the “Backoff” malware, linked to a criminal gang in Eastern Europe. According to some reports, however, the Home Depot breach may have been effected using BlackPOS, the same attack tool used in the Target incident.

Are you a security pro? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

France Fines Apple Over Ad Tracking Feature

Apple fined 150m euros over App Tracking Transparency feature that it says abuses Apple's market…

9 hours ago

OpenAI To Release Open-Weight AI Model

OpenAI to release customisable open-weight model in coming months as it faces pressure from open-source…

10 hours ago

Samsung AI Fridge Creates Shopping Lists, Adjusts AC

Samsung's Bespoke AI-powered fridge monitors food to create shopping lists, displays TikTok videos, locates misplaced…

10 hours ago

Huawei Consumer Revenues Surge Amidst Smartphone Comeback

Huawei sees 38 percent jump in consumer revenues as its smartphone comeback continues to gather…

11 hours ago

China Approves First ‘Flying Car’ Licences

In world-first, China approves commercial flights for EHang autonomous passenger drone, paving way for imminent…

11 hours ago

Microsoft Shutters Shanghai Lab In Latest China Pullback

Microsoft closes down IoT and AI lab it operated in Shanghai tech district in latest…

12 hours ago