CASE DOSSIER settled

Home Depot 56 Million Payment Card Breach (BlackPOS Malware)

Docket: 1:14-md-02583-TWT Court: U.S. District Court for the Northern District of Georgia Opened: 2014-09-08 Sector: Retail & Home Improvement

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$175.0 million
Consolidated class action settlement, bank card reissuance compensation, and state AG penalties.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in U.S. District Court for the Northern District of Georgia.
  • Primary Target Sector: Retail & Home Improvement.
  • Documented Financial Loss: $175.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Historic retail network compromise wherein cybercriminals used stolen third-party HVAC vendor credentials to penetrate Home Depot corporate intranet, deploying custom BlackPOS memory-scraping malware across 2,200 store checkout terminals and exfiltrating 56 million credit and debit card records.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Stolen credentials belonging to an external third-party refrigeration vendor used to access Home Depot corporate network.

Operational & Financial Fallout

56 million payment cards compromised across 2,200 store checkout terminals, resulting in a historic $175 million consolidated class action settlement.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Stolen credentials belonging to an external third-party refrigeration vendor used to access Home Depot corporate network.

Adversary Kill Chain Flow

5 Documented Phases
1
Vendor Perimeter Ingress Compromised Contractor Credential Abuse
MITRE ATT&CK T1078 →

Attackers gained initial network entry using stolen portal credentials belonging to a third-party heating and refrigeration vendor.

Artifacts & Tooling: Vendor portal login logs Stolen contractor account
2
Lateral Traversal Unsegmented Corporate Intranet Pivoting
MITRE ATT&CK T1021.002 →

Adversaries traversed internal corporate networks, escalating privileges to access store register management servers in 2,200 stores.

Artifacts & Tooling: Windows domain privilege escalation Lateral SMB movement
3
Malware Staging BlackPOS RAM Scraper Distribution
MITRE ATT&CK T1003 →

A custom variant of BlackPOS malware was pushed to thousands of self-checkout registers, evading endpoint antivirus detection.

Artifacts & Tooling: BlackPOS memory scraper Checkout register deployment scripts
4
Card Data Theft Magnetic Stripe Track Scraping
MITRE ATT&CK T1056.001 →

Malware captured unencrypted payment card Track 1 and Track 2 data resident in register RAM during card swipes over five months.

Artifacts & Tooling: Scraped Track 2 magnetic stripe data Local encrypted staging
5
Class Action Settlement $175 Million Consolidated Legal Settlement
MITRE ATT&CK T1078 →

Following detection, Home Depot agreed to pay $19.5 million to consumers, $134 million to financial institutions, and state AG penalties.

Artifacts & Tooling: Consolidated MDL docket 1:14-md-02583 Court-approved settlement order
Real-World Blast Radius & Operational Fallout

56 million payment cards compromised across 2,200 store checkout terminals, resulting in a historic $175 million consolidated class action settlement.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce strict multi-factor authentication across all external vendor and contractor remote access portals.
✓ Segment third-party vendor networks completely from corporate intranets and point-of-sale environments.
✓ Deploy Point-to-Point Encryption (P2PE) and EMV chip technology on all checkout registers.
✓ Implement continuous file integrity and in-memory process monitoring across retail store endpoints.

Procedural & Incident Timeline

2014-04-12 incident

Attackers use vendor portal credentials to establish foothold within Home Depot network.

2014-09-02 discovery

Banks detect massive batch of stolen payment card numbers circulating on darknet carding portals.

2016-03-07 settlement

Home Depot agrees to $19.5 million customer settlement and $134 million financial institution settlement.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Attackers gained initial perimeter entry using compromised credentials belonging to a third-party vendor, traversing unsegmented internal networks to access store registers." Consolidated Class Action Complaint ¶ 42, Page 19 reviewed
T1003 OS Credential Dumping
Credential Access
"Custom variant of BlackPOS malware was staged on self-checkout terminals, periodically scraping unencrypted payment card magnetic stripe Track 1 and Track 2 records from memory." Consolidated Class Action Complaint ¶ 54, Page 23 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Home Depot 56 Million Payment Card Breach (BlackPOS Malware), No. 1:14-md-02583-TWT (U.S. District Court for the Northern District of Georgia 2014), https://cybercaselibrary.com/cases/home-depot-pos-perimeter-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/home-depot-pos-perimeter-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>