Home Depot Inks $17.5M 2014 Data Breach Settlement
This payment resolves a multistate investigation of a 2014 data breach that exposed the payment card information of approximately 40 million consumers nationwide, including consumers who shopped in 45 Home Depot stores in Massachusetts.
“Retailers must take meaningful steps to protect consumers’ credit and debit card information from theft when they shop,” said Massachusetts AG Healey. “This settlement ensures Home Depot complies with our state’s strong data security law and requires the company to take steps to protect consumer information from illegal use or disclosure.”
The breach occurred when hackers gained access to The Home Depot’s network and deployed malware on the company’s self-checkout point-of-sale system. The malware allowed the hackers to obtain the payment card information of customers who used self-checkout lanes at The Home Depot stores throughout the U.S. between April 10, 2014 and Sept 13, 2014, including 45 in Massachusetts.
In addition to the $17.5 million total payment to the states, The Home Depot has agreed to implement and maintain a series of data security practices designed to strengthen its information security program and better safeguard the personal information of consumers.
Specifically, the company has agreed to the following information security provisions:
The other states participating in this settlement include: Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, District of Columbia, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, and Wisconsin.
For Massachusetts, this case was handled by Assistant Attorney General Sara Cable, Chief of the Data Privacy & Security Division. The AG’s new Data Privacy and Security Division protects consumers and their families from the rise of threats to the privacy and security of their data in the digital economy. The Division aims to empower consumers in the digital economy, ensure that companies are protecting consumers’ personal data from breach, protect equal and open access to the internet, and protect consumers from data-driven technologies that unlawfully deny them fair access to socioeconomic opportunities.