AfterDawn: Tech news

Home Depot data breach also led to 53 million email addresses being stolen

Written by Andre Yoskowitz @ 07 Nov 2014 11:32

Home Depot data breach also led to 53 million email addresses being stolen

Home Depot has confirmed that their high-profile data breach was worse than expected, with 53 million email addresses being stolen in addition to the 56 million credit and debit card numbers taken.
In April, the company confirmed that hackers were able to breach their systems by accessing the password of a vendor. That small access allowed the attackers to get deep into the home improvement store's networks through a Windows exploit and take personal info. Even though Microsoft quickly patched the exploits, the hackers were already in and were running through the company's point-of-sale systems using high-level employee permissions.

While the email leak is actually on the smaller side compared to others of the past five years, Home Depot warned users to expect more phishing attacks, in which attackers will try to secure more sensitive information (such as bank accounts or other logins) via purporting to be real companies in fake emails.

Home Depot did not seem too apologetic, claiming that their network design was not at fault but did concede that the company should have placed data security higher in its "mission statement."



The data collection was ongoing for months, and they hackers were only detected after they decided to sell a giant block of credit card numbers on the underground forum Rescator. The U.S. Secret Service then informed Home Depot. On the same day, Capital One called the company to inform them that the only common thread between a giant batch of fraudulent charges from a group of cards was Home Depot. Home Depot, banks and government agencies all tried to buy the cards at that point to take them off the market, and the traffic actually took the site down. In the next few days, the company was able to acquire some cards and began backtracking, eventually finding the "patient zero" server at a store in Miami.


Source:
WSJ

Previous Next Write a comment
Comments have been disabled for this article.

Latest news

GitHub Copilot to train its AI with users' prompts, code - here's how to opt out GitHub Copilot to train its AI with users' prompts, code - here's how to opt out (30 Mar 2026 3:49)
GitHub, the world's largest code repository for software development projects, owned by Microsoft, will start using user interactions to train its AI models.
Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.

News archive