Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

Home Depot to Pay Banks $25 Million for 2014 Breach

Home Depot has agreed to pay $25 million to the financial institutions affected by the massive data breach suffered by the retailer in 2014, when cybercriminals managed to steal email addresses and payment card data belonging to more than 50 million customers.

Home Depot has agreed to pay $25 million to the financial institutions affected by the massive data breach suffered by the retailer in 2014, when cybercriminals managed to steal email addresses and payment card data belonging to more than 50 million customers.

The retail giant will create a $25 million settlement fund that will be distributed among affected financial institutions.

Organizations that submit claims can receive $2 for each of the payment cards for which they received alerts as a result of the breach, without providing any documentation. Companies that do provide documentation can recover up to 60 percent of losses.

In addition, Home Depot is prepared to pay a total of up to $2.250,000 to sponsored entities whose legal claims against the company were released by their sponsor.

As part of the settlement, Home Depot has also agreed to improve its data security practices in an effort to avoid similar incidents in the future, court documents show.

Fortune reported that the retailer has already paid out more than $134 million to Visa, MasterCard and other financial organizations.

Advertisement. Scroll to continue reading.

As for the lawsuit filed by affected consumers, Home Depot last year agreed to pay at least $19.5 million to settle charges, including for reimbursements and identity protection services. The total cost of the breach is at least $179 million.

Home Depot’s investigation revealed that cybercriminals had access to the company’s systems between April and September 2014. The attackers used custom-built malware to steal payment cards and other customer data without being detected.

Related: Target Agrees to $10M Settlement of Breach Lawsuit

Related: U.S. Authorities Reach Settlement With Adobe Over 2013 Breach

Related: Western Union Pays $586 Million to Settle Fraud Charges

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.