EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/home-depot-breach-2014
289/430

File EL-0142HighResolvedData Breach / Payment Card Data Theft

Home Depot Payment Card Breach

Also filed as Home Depot Data Breach · 2014 Home Depot Card Skimming Incident

The Home Depot Payment Card Breach involved the unauthorized theft of payment card data from multiple retail locations across the United States. The attack utilized sophisticated skimming devices placed on point-of-sale (POS) terminals. This incident highlighted systemic vulnerabilities in retail payment processing infrastructure.

  • #pci-dss
  • #payment-card-industry
  • #skimming
  • #retail
  • #data-breach
  • #2014
Notoriety7/10
Event
1 Apr 2014
Disclosed
1 Apr 2014
Target
Home Depot Inc.
Scale
Millions of records
Status
Resolved

01Summary

The breach occurred when criminal actors installed physical skimming devices on the payment terminals at various Home Depot stores. These devices were designed to capture magnetic stripe data and potentially collect PINs. The attackers successfully exfiltrated a large volume of payment card information, estimated to include millions of records. The discovery of the breach led to immediate, large-scale forensic investigations and mandated significant upgrades to the company's payment security infrastructure. The incident underscored the persistent threat of physical point-of-sale compromise in the retail sector.

02Background

The retail sector, particularly large hardware and home improvement chains, relies heavily on physical point-of-sale transactions, making it a prime target for card skimming. Prior breaches, such as those at Target, had already demonstrated the viability and profitability of large-scale payment data theft, setting a precedent for similar attacks.

03Key revelations

  1. 01The successful theft of payment card data from multiple retail locations.
  2. 02The use of physical skimming devices, a common but highly effective retail attack vector.
  3. 03The necessity for major retailers to overhaul their physical and digital payment security protocols.

04Technical analysis

The primary attack vector was physical compromise of the Point-of-Sale (POS) terminals. The attackers installed magnetic skimmers, which read the data from the card's magnetic stripe when swiped. These devices were often paired with hidden cameras or keypad overlays to capture PINs, allowing for the creation of complete card details for fraudulent use.

Attack vector
Physical compromise of Point-of-Sale (POS) terminals
Attack method
Skimming and Data Exfiltration
Initial access
Physical placement of skimming devices
Exfiltration
Physical removal of data storage devices (e.g., memory cards) or remote transmission
Tool / malware
Skimmers (Physical Devices)
Malware type
Stealer

Vulnerabilities exploited

  • Physical Terminal Vulnerability

MITRE ATT&CK techniques

  • T1022

05Threat actor

The perpetrators were highly organized criminal actors, utilizing specialized physical equipment and operational knowledge to target high-volume retail environments. Their focus was purely on maximizing financial yield through the sale of raw payment data.

Aliases

  • Skimmers

MITRE groups

  • T1173

Attribution sources

  • Industry Security Reports

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Payment Card Numbers (PAN)
  • Expiration Dates
  • Service Codes
  • Magnetic Stripe Data

Notable documents

  • Forensic Audit Reports
  • PCI DSS Compliance Failure Reports

08Financial damage

Damage estimate is complex, involving forensic costs, regulatory fines, and potential fraud losses, but no single public figure is universally cited.

09Timeline

  1. 2014-03-01Start of skimming operations at various Home Depot locations.
  2. 2014-04-01Discovery of the breach and initial forensic investigation.
  3. 2014-06-01Completion of major security upgrades and remediation efforts.

10Reaction and fallout

Public reaction

The public reaction was characterized by increased awareness regarding the physical security of payment terminals. Consumers became more cautious about using card readers in public places.

Political impact

The incident put renewed pressure on the Payment Card Industry (PCI) and regulatory bodies to enforce stricter physical and digital security standards across all retail sectors.

11Legal

The company faced significant regulatory scrutiny and was required to undergo costly, mandated security upgrades to maintain PCI compliance.

Civil lawsuits

  • Class-action lawsuits filed by affected cardholders (general trend)

12Aftermath

Policy changes

  • Increased adoption of EMV (chip) technology to mitigate magnetic stripe data theft.
  • Stricter physical security audits for POS terminals across the retail industry.

Regulatory changes

  • Enhanced PCI DSS compliance requirements for physical terminal security.

Security improvements

  • Implementation of tamper-proof and encrypted POS terminals.
  • Mandatory point-to-point encryption (P2PE) for all card transaction data.

13Significance and legacy

Significance

This breach is significant because it demonstrated the continued vulnerability of physical payment infrastructure, even years after major security advancements. It reinforced the shift from relying solely on magnetic stripe data to mandatory chip-based (EMV) transactions, setting a critical precedent for modern retail security.

Legacy

The legacy of the Home Depot breach, alongside others, accelerated the industry-wide migration to end-to-end encryption and chip-based payment systems. It highlighted that security is not solely a software problem but requires physical security measures.

14Disclosure and media

Authentication
Forensic Analysis

Media partners

  • Reuters
  • The Wall Street Journal

Publishing organisations

  • Industry Security Analysts

15Related files

Related events

  • Target Data Breach (2013)
  • WannaCry Ransomware Attack (2017)

16Field notes

  1. 01The use of skimming devices often required the attackers to physically access the terminals, making them vulnerable to detection by staff.
  2. 02The breach contributed to the increased global adoption of EMV chip technology, which is significantly harder to clone than magnetic stripe data.

17Resolution

The company implemented comprehensive security overhauls, including upgrading all POS systems to meet the highest standards of PCI DSS compliance, focusing on encryption and physical tamper resistance.

18Sources

Official documents

  • PCI DSS Compliance Audit Reports

References

  1. [1]Industry Security News Reports
  2. [2]PCI Security Standards Council Advisories
Fact sheetEL-0142

Dates

Event
1 Apr 2014
Started
1 Mar 2014
Ended
1 Apr 2014
Duration
31 days
Discovered
1 Apr 2014
Disclosed
1 Apr 2014
Resolved
1 Jun 2014
Ongoing
No

Target

Organisation
The Home Depot, Inc.
Type
Corporation
Sector
Retail
Country
United States

Actor

Type
Criminal Gang
Motivation
Financial gain through theft of payment card data
Arrested
No
Convicted
No

Data

Volume
Millions of records
Sensitivity
Confidential
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.