The Home Depot data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with Home Depot, it's worth checking whether your data was involved.
What Happened
Home Depot disclosed a major data breach in September 2014 after malware was found on point-of-sale systems across its US and Canadian stores. The malware was active from April to September 2014, making it one of the largest retail data breaches in history at the time, surpassing even the Target breach from the previous year.
What Data Was Exposed
The breach exposed approximately 56 million payment card numbers and expiration dates, along with 53 million customer email addresses that were used to send phishing emails to affected customers afterward.
Why This Still Matters
Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial accounts closely if payment or banking data was involved.
- Watch for phishing — breach data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the Home Depot data breach happen?
Malware was active on Home Depot's point-of-sale systems from April to September 2014. The company disclosed the breach publicly on 8 September 2014 after being alerted by banks and law enforcement to unusual card activity.
What data was stolen in the Home Depot breach?
Approximately 56 million payment card numbers and expiration dates were stolen, along with 53 million customer email addresses, which were later used in follow-up phishing campaigns targeting affected customers.
How did attackers get into Home Depot?
Similar to the Target breach, attackers gained initial access using stolen credentials from a third-party vendor, then deployed custom malware on point-of-sale terminals to capture card data as it was swiped.
How do I check if I was affected by the Home Depot breach?
If you shopped at Home Depot between April and September 2014 using a payment card, you were likely affected. Check your email at Scan My Shadow, and review old bank statements from that period for unfamiliar charges.
What was the settlement for the Home Depot breach?
Home Depot reached a $19.5 million settlement with affected customers and separately settled with banks and payment card networks for tens of millions more, plus a $17.5 million multistate settlement with state attorneys general.