Home Depot payment card breach involving malware on point-of-sale systems
Home Depot announced findings from its investigation into a data security incident involving malware on its U.S. and Canadian self-checkout point-of-sale systems. The company’s disclosures and subsequent filings described response actions, investigation, and costs associated with the incident. The event resulted in significant remediation and legal expenses, partially offset in some periods by insurance recoveries as disclosed in filings.
First reported September 8, 2014Breachmed overall confidence
Home Depot customers who used payment cards during the affected period
The Home Depot, Inc.
Initial access
unknown
Impact
data_theft
financial_loss
Attribution
unknownlow confidence
Public disclosures in cited sources do not provide definitive public attribution.
CVEs and ATT&CK
No CVE or ATT&CK association is captured in this curated record.
Mitigations
Now
Implement P2PE/tokenization and minimize card data exposure on POS endpointsReduces the value and accessibility of payment card data to malware operating on POS devices.
Soon
Harden POS endpoints (allowlisting, restricted admin access, monitored outbound traffic)Reduces malware execution and increases detection of anomalous exfiltration behavior.
Later
Strengthen third-party access controls and segmentation of payment environmentsLimits pathways attackers can use to reach POS systems and payment networks.
Detection ideas
Detect POS malware indicators and suspicious processes on POS endpoints
Alert on new executables in POS software directories, unexpected memory scraping behavior, or unusual process injection patterns.
Data sources: EDR telemetry, Windows Security Event Logs, Application allowlisting logs
Monitor POS network egress for unusual destinations and volumes
Alert when POS subnets send sustained traffic to rare external IPs/domains or unusual ports.
Data sources: Firewall logs, Proxy logs, NetFlow/flow logs