International
Home Depot ‘possibly’ hit by major data breach
Home Depot ‘possibly’ hit by major data breach
A close-up of an electronic payment station at a Home Depot store in Daly City, California. The world’s largest home improvement retailer says that it is looking into ‘some unusual activity’ related to customer data but that it could not confirm if it had become the latest retailer to be hit by a large-scale security breach.
Reuters/Chicago/Washington
Customer data could have been stolen from nearly all of Home Depot Incorporated’s stores in the United States, according to new information released on Wednesday by security website KrebsonSecurity.
Brian Krebs, who runs the website, said on Tuesday the problem could affect all of Home Depot’s 2,200 stores in the US.
On Wednesday, he said that he found new evidence that the breach first surfaced on the website Rescator, where customer credit cards were listed according to store ZIP code.
These codes showed a 99.4% overlap with Home Depot stores, he said.
In all, there were 1,939 codes corresponding to Home Depot store locations, Krebs’ website said.
It is not yet clear how many customers were impacted.
Home Depot has not confirmed that a breach occurred. It has said it is investigating “unusual activity” and is working with its banking partners and law enforcement to investigate.
The FBI declined to comment on Wednesday.
However, Home Depot has been in contact with the US Secret Service about the alleged breach, a law enforcement source told Reuters yesterday.
Any investigation by the Secret Service appears to be at a very early stage, the source said.
The Secret Service, which declined comment, usually is the lead agency in federal criminal investigations into complex breaches of credit card and other consumer data.
Another law enforcement source said the FBI, which also sometimes participates in such investigations, does not appear to be involved.
It is unclear whether the US Department of Justice is playing any role.
The retailer sought to reassure customers on Wednesday that they will not be held responsible for any possible fraudulent charges.
It also asked them to closely monitor their accounts and said it will offer free identity-protection services, including credit monitoring, to any customers who may have been affected.
Home Depot could be the latest in a string of retailers to have been hit by security breaches in the recent past.
If confirmed, the Home Depot breach could be among the worst.
US retailers have been slow to adopt chip-reading technology on their terminals as most Americans do not carry chip-enabled cards.
Home Depot spokeswoman Paula Drake said on Wednesday that the retailer is working with IT security firms, including Symantec Corporated and FishNet Security, to investigate whether there has been a data breach.
A Symantec spokeswoman confirmed that Symantec was assisting with the investigation but did not elaborate.
In one of the most serious incidents, hackers last year stole at least 40mn payment card numbers and 70mn other pieces of customer data from Target Corporated.
The largest-known breach at a US retailer, however, was uncovered in 2007, at TJX Cos Incorporated, operator of the TJ Maxx and Marshalls chains, where more than 90mn credit cards were stolen over about 18 months.
In some situations, companies that conduct investigations into data breaches may not be able to come to a definitive conclusion.
For instance, Sears Holdings Corporation said in February that an investigation into a possible data breach did not reveal conclusive information.
Home Depot shares fell 2.4% to close at $89.00 on the New York Stock Exchange on Wednesday.
Its shares were up 1.6% at $90.39 yesterday morning.