Home Depot: Hackers stole e-mail addresses
NEW YORK — Hackers stole 53 million e-mail addresses in addition to customers’ card data, Home Depot said Thursday.
The nation’s largest home improvement chain had disclosed the massive, months-long breach of 56 million debit and credit cards in September.
Home Depot’s breach surpassed Target’s pre-Christmas 2013 data theft, which compromised 40 million credit and debit cards and hurt sales and profits. Since late last year, Michaels, SuperValu and Neiman Marcus have been among a string of retailers that have also reported breaches, though they were smaller.
While shoppers appear to have grown numb to the hacks, the breaches are forcing changes in retailing. Target’s breach pushed banks, retailers and card companies to increase security by speeding the adoption of microchips in U.S. credit and debit cards, which supporters say are more secure. Home Depot reiterated Thursday it will be activating chip-enabled checkout terminals at all of its U.S. stores by the end of the year.
The file containing the e-mail addresses did not contain passwords or other personal information, according to Home Depot. However, it said customers should be on guard against phishing scams. Phishing attacks are sent through texts or e-mails and try to trap you into disclosing personal information.
The company is notifying affected customers in the U.S. and Canada.
Home Depot also explained how the hackers got into its system. It said the hackers initially accessed its network in April with a third-party vendor’s username and password. Home Depot said hackers stole information through malware installed on self-checkout systems in the U.S. and Canada. That’s similar to what happened at Target where thieves hacked into the password of a third-party supplier.
Home Depot said its investigation with law enforcement and efforts to further enhance its security measures are ongoing.
On Thursday it confirmed its sales growth estimate for the year and said it still expects annual profit of $4.54 per share. But unclear is how much Home Depot’s future profits will be affected.
Home Depot’s outlook for its fiscal 2014 year includes estimates for the cost to investigate the data breach, providing credit monitoring services to its customers, increasing call center staffing and paying for legal and professional services. However, it doesn’t include any potential losses related to the breach.
