How Did The Home Depot Breach Happen
102 home depot confirmed thursday that hackers exposed 56 million credit and debit cards during its months long security breach.
How did the home depot breach happen. But while news of the hack has only surfaced today the initial breach may have occurred in the spring. Much like the target data breach home depot s data breach occurred through the point of sale pos systems. Home depot is of course the second major retailer to blame the supply chain for their breach. Stolen credit card price tag.
The hackers compromised meaning they got access to 56 million home depot credit card customers. The data release from some of home depot s customers in canada is unusual in that the breach seems to be the result of an internal system error rather than an external attack saryu nayyar ceo. This is 16 million more cards than target making the home depot breach the largest in history. In the home depot breach not payment card skimmers.
They didn t actually do anything. Because in april 2014 hackers found their way into home depot s security systems and in the process pulled off the biggest retail credit card breach in u s. That s the lesson the home depot learned the hard way. Target s headline grabbing data breach was started through compromised hvac vendor credentials showcasing poor network sequestration and vetting processes.
Payment card data hit the underground cybercrime market. According to an in depth case study the hackers were able to steal a third party vendor s credentials and used this as a way to enter the system. The hackers were then able to use the zero day vulnerability in windows to pivot directly into the home depot corporate network. Eight months after a security breach brought scorn on target and resulted in the resignation of its ceo home depot is now the victim of a nearly identical attack.
Home depot is the latest in a string of u s. An investigation followed in which five states reuters said including california connecticut illinois new york and iowa launched a joint probe into the data breach on the payment card processing systems of home depot inc. Home depot said that 56 million cards were impacted by the incident. Brian krebs broke the news the same day.
Rapid7 s trey ford said the. However the malware would have never been installed on the systems if the attackers did not possess third party vendor credentials and if the payment network was segregated properly from the rest of the home depot network.