Home Depot data breach could be the largest yet

  • Copyright 2014 New York Times News Service (via Peninsula Daily News)
  • Tuesday, September 9, 2014 10:05am
  • News
The security breach at Home Depot continued

The security breach at Home Depot continued

Copyright 2014 New York Times News Service (via Peninsula Daily News)

NEW YORK —

Home Depot has confirmed that hackers had broken into its in-store payments systems, in what could be the largest known breach of a retail company’s computer network.

The retailer said the exact number of customers affected was still not clear.

But a person briefed on the investigation said the total number of credit card numbers stolen at Home Depot could top 60 million. By comparison, the breach last year at Target, the largest known attack to date, affected 40 million cardholders.

The breach may have affected any customer at Home Depot stores in the

United States and Canada from April to early last week, said Paula Drake, a company spokeswoman. Customers at Home Depot’s Mexico stores were not affected, nor were online shoppers at HomeDepot.com. Personal identification numbers for debit cards were not taken, she said Monday.

Home Depot has not yet confirmed other details.

The retailer operates 1,977 stores in the United States and 180 in Canada. That is about 400 more than Target had when it was compromised.

Target’s breach went on for three weeks before the company learned about it, while the attack at Home Depot went unnoticed for as long as five months.

“Honestly, Home Depot is in trouble here,” said Eric W. Cowperthwaite, vice president of Core Security, an Internet-security consulting company. Mr. Cowperthwaite noted that it was a security blogger, Brian Krebs, not the company, that first reported the breach.

“This is not how you handle a significant security breach, nor will it provide any sort of confidence that Home Depot can solve the problem going forward,” Mr. Cowperthwaite said.

Last week, before Home Depot confirmed the attack, customers in Georgia had already filed a class-action lawsuit against the retailer for failing to protect customers from fraud and not alerting them to the breach in a timely manner.

Home Depot said it would offer free identity protection and credit-monitoring services to any customer who had used a credit or debit card at any of its affected stores.

Since the breach at Home Depot first came to executives’ attention last Tuesday, the company said it had been working with two security companies, Symantec and FishNet Security, to investigate.

Home Depot is unlikely to be the last big retailer to suffer a breach of its cash register systems. Hackers have for some time been scanning merchants’ networks for ways to gain remote access, such as through outside contractors who have access to a computer network. Once they find that opening, they install so-called malware that is undetectable by antivirus products.

The Department of Homeland Security and the Secret Service recently estimated that more than 1,000 businesses in the United States had been infected with malware that is programmed to siphon payment card details from cash registers in stores.

They believed that many of these businesses did not even know they were sharing customers’ credit card information.

Besides Home Depot and Target, among the companies that have been hacked are U.P.S., Goodwill, P. F. Chang’s, Sally Beauty, Michael’s and Neiman Marcus.

Security experts believe that the same group of criminals in Eastern Europe is behind the attacks, according to several people briefed on the results of forensics investigations who were not allowed to speak publicly because of nondisclosure agreements.

Buried in the malware used in the Home Depot attack were links to websites that reference the United States role in the conflict in Ukraine.

In each case, the entry point has differed, according to one law enforcement official. At Target, it was thought to be a Pennsylvania company that provided heating, air conditioning and refrigeration services to the retailer. The entry points for the other businesses are still unknown.

Studies have found that retailers, in particular, are unprepared for such attacks.

A joint study by the Ponemon Institute, an independent security research firm, and DB Networks, a database security firm, found that a majority of computer security experts in the United States believed that their organizations lacked the technology and tools to quickly detect database attacks.

Only one-third of those experts said they did the kind of continuous monitoring needed to identify irregular activity in their databases, and 22 percent acknowledged that they did not scan at all.

After Home Depot confirmed the breach on Monday, a retail lobbying group in Washington said it was time the industry worked together to combat such threats.

“Any organization connected to the debit and credit card ecosystem faces constant and evolving threats,” said Sandy Kennedy, president of the Retail Industry Leaders Association.

“The public and private sector must continue to work together to improve debit and credit card security, identify threats and share information to best defend against cyberattacks.”

More in News

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend, volunteer at the Martin Luther King Day of Service beach restoration on Monday at Fort Worden State Park. The activity took place on Knapp Circle near the Point Wilson Lighthouse. Sixty-four volunteers participated in the removal of non-native beach grasses. (Steve Mullensky/for Peninsula Daily News)
Work party

Sue Long, left, Vicki Bennett and Frank Handler, all from Port Townsend,… Continue reading

Portion of bridge to be replaced

Tribe: Wooden truss at railroad park deteriorating

Kingsya Omega, left, and Ben Wilson settle into a hand-holding exercise. (Aliko Weste)
Process undermines ‘Black brute’ narrative

Port Townsend company’s second film shot in Hawaii

Jefferson PUD to replace water main in Coyle

Jefferson PUD commissioners awarded a $1.3 million construction contract… Continue reading

Scott Mauk.
Chimacum superintendent receives national award

Chimacum School District Superintendent Scott Mauk has received the National… Continue reading

Hood Canal Coordinating Council meeting canceled

The annual meeting of the Hood Canal Coordinating Council, scheduled… Continue reading

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the rotunda of the old Clallam County Courthouse on Friday in Port Angeles. The North Olympic History Center exhibit tells the story of the post office past and present across Clallam County. The display will be open until early February, when it will be relocated to the Sequim City Hall followed by stops on the West End. The project was made possible due to a grant from the Clallam County Heritage Advisory Board. (Dave Logan/for Peninsula Daily News)
Post office past and present

Bruce Murray, left, and Ralph Parsons hang a cloth exhibition in the… Continue reading

This agave grew from the size of a baseball in the 1990s to the height of Isobel Johnston’s roof in 2020. She saw it bloom in 2023. Following her death last year, Clallam County Fire District 3 commissioners, who purchased the property on Fifth Avenue in 2015, agreed to sell it to support the building of a new Carlsborg fire station. (Matthew Nash/Olympic Peninsula News Group file)
Fire district to sell property known for its Sequim agave plant

Sale proceeds may support new Carlsborg station project

As part of Olympic Theatre Arts’ energy renovation upgrade project, new lighting has been installed, including on the Elaine and Robert Caldwell Main Stage that allows for new and improved effects. (Olympic Theatre Arts)
Olympic Theatre Arts remodels its building

New roof, LED lights, HVAC throughout

Weekly flight operations scheduled

Field carrier landing practice operations will be conducted for aircraft… Continue reading

Workers from Van Ness Construction in Port Hadlock, one holding a grade rod with a laser pointer, left, and another driving the backhoe, scrape dirt for a new sidewalk of civic improvements at Walker and Washington streets in Port Townsend on Thursday. The sidewalks will be poured in early February and extend down the hill on Washington Street and along Walker Street next to the pickle ball courts. (Steve Mullensky/for Peninsula Daily News)
Sidewalk setup

Workers from Van Ness Construction in Port Hadlock, one holding a grade… Continue reading