{
  "id": "case-home-depot-pos",
  "slug": "home-depot-pos-perimeter-breach",
  "title": "Home Depot 56 Million Payment Card Breach (BlackPOS Malware)",
  "summary": "Historic retail network compromise wherein cybercriminals used stolen third-party HVAC vendor credentials to penetrate Home Depot corporate intranet, deploying custom BlackPOS memory-scraping malware across 2,200 store checkout terminals and exfiltrating 56 million credit and debit card records.",
  "case_number": "1:14-md-02583-TWT",
  "court": "U.S. District Court for the Northern District of Georgia",
  "district": "N.D. Ga.",
  "country": "United States",
  "opened_at": "2014-09-08",
  "status": "settled",
  "victim_sector": "Retail & Home Improvement",
  "victim_country": "United States",
  "loss_amount_usd": 175000000,
  "loss_amount_note": "Consolidated class action settlement, bank card reissuance compensation, and state AG penalties.",
  "first_seen_at": "2014-04-01T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "unattributed-cybercrime",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Attackers gained initial perimeter entry using compromised credentials belonging to a third-party vendor, traversing unsegmented internal networks to access store registers.",
      "evidence_locator": "Consolidated Class Action Complaint \u00b6 42, Page 19",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "In re Home Depot Customer Data Security Breach Litigation",
      "source_url": "https://www.courtlistener.com/docket/4351600/in-re-the-home-depot-inc-customer-data-security-breach-litigation/",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Custom variant of BlackPOS malware was staged on self-checkout terminals, periodically scraping unencrypted payment card magnetic stripe Track 1 and Track 2 records from memory.",
      "evidence_locator": "Consolidated Class Action Complaint \u00b6 54, Page 23",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Class Action Complaint \u00b6 54",
      "source_url": "https://www.courtlistener.com",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2014-04-12",
      "description": "Attackers use vendor portal credentials to establish foothold within Home Depot network."
    },
    {
      "event_type": "discovery",
      "event_date": "2014-09-02",
      "description": "Banks detect massive batch of stolen payment card numbers circulating on darknet carding portals."
    },
    {
      "event_type": "settlement",
      "event_date": "2016-03-07",
      "description": "Home Depot agrees to $19.5 million customer settlement and $134 million financial institution settlement."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Stolen credentials belonging to an external third-party refrigeration vendor used to access Home Depot corporate network.",
    "blast_radius": "56 million payment cards compromised across 2,200 store checkout terminals, resulting in a historic $175 million consolidated class action settlement.",
    "kill_chain": [
      {
        "phase": "Vendor Perimeter Ingress",
        "title": "Compromised Contractor Credential Abuse",
        "description": "Attackers gained initial network entry using stolen portal credentials belonging to a third-party heating and refrigeration vendor.",
        "technical_artifacts": [
          "Vendor portal login logs",
          "Stolen contractor account"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Lateral Traversal",
        "title": "Unsegmented Corporate Intranet Pivoting",
        "description": "Adversaries traversed internal corporate networks, escalating privileges to access store register management servers in 2,200 stores.",
        "technical_artifacts": [
          "Windows domain privilege escalation",
          "Lateral SMB movement"
        ],
        "mitre_technique_id": "T1021.002"
      },
      {
        "phase": "Malware Staging",
        "title": "BlackPOS RAM Scraper Distribution",
        "description": "A custom variant of BlackPOS malware was pushed to thousands of self-checkout registers, evading endpoint antivirus detection.",
        "technical_artifacts": [
          "BlackPOS memory scraper",
          "Checkout register deployment scripts"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Card Data Theft",
        "title": "Magnetic Stripe Track Scraping",
        "description": "Malware captured unencrypted payment card Track 1 and Track 2 data resident in register RAM during card swipes over five months.",
        "technical_artifacts": [
          "Scraped Track 2 magnetic stripe data",
          "Local encrypted staging"
        ],
        "mitre_technique_id": "T1056.001"
      },
      {
        "phase": "Class Action Settlement",
        "title": "$175 Million Consolidated Legal Settlement",
        "description": "Following detection, Home Depot agreed to pay $19.5 million to consumers, $134 million to financial institutions, and state AG penalties.",
        "technical_artifacts": [
          "Consolidated MDL docket 1:14-md-02583",
          "Court-approved settlement order"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce strict multi-factor authentication across all external vendor and contractor remote access portals.",
      "Segment third-party vendor networks completely from corporate intranets and point-of-sale environments.",
      "Deploy Point-to-Point Encryption (P2PE) and EMV chip technology on all checkout registers.",
      "Implement continuous file integrity and in-memory process monitoring across retail store endpoints."
    ]
  }
}