Home Depot 56 Million Payment Card Breach (BlackPOS Malware)
Key Facts
- Legal Status: SETTLED in U.S. District Court for the Northern District of Georgia.
- Primary Target Sector: Retail & Home Improvement.
- Documented Financial Loss: $175.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Stolen credentials belonging to an external third-party refrigeration vendor used to access Home Depot corporate network.
Operational & Financial Fallout
56 million payment cards compromised across 2,200 store checkout terminals, resulting in a historic $175 million consolidated class action settlement.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Stolen credentials belonging to an external third-party refrigeration vendor used to access Home Depot corporate network.
Adversary Kill Chain Flow
5 Documented PhasesAttackers gained initial network entry using stolen portal credentials belonging to a third-party heating and refrigeration vendor.
Adversaries traversed internal corporate networks, escalating privileges to access store register management servers in 2,200 stores.
A custom variant of BlackPOS malware was pushed to thousands of self-checkout registers, evading endpoint antivirus detection.
Malware captured unencrypted payment card Track 1 and Track 2 data resident in register RAM during card swipes over five months.
Following detection, Home Depot agreed to pay $19.5 million to consumers, $134 million to financial institutions, and state AG penalties.
56 million payment cards compromised across 2,200 store checkout terminals, resulting in a historic $175 million consolidated class action settlement.
Procedural & Incident Timeline
Attackers use vendor portal credentials to establish foothold within Home Depot network.
Banks detect massive batch of stolen payment card numbers circulating on darknet carding portals.
Home Depot agrees to $19.5 million customer settlement and $134 million financial institution settlement.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Attackers gained initial perimeter entry using compromised credentials belonging to a third-party vendor, traversing unsegmented internal networks to access store registers." | Consolidated Class Action Complaint ¶ 42, Page 19 | reviewed |
| T1003 | OS Credential Dumping Credential Access | "Custom variant of BlackPOS malware was staged on self-checkout terminals, periodically scraping unencrypted payment card magnetic stripe Track 1 and Track 2 records from memory." | Consolidated Class Action Complaint ¶ 54, Page 23 | reviewed |