On Sept. 8th 2014, Home Depot has officially announced that credit card information was in fact stolen, following their initial report on Sept. 2nd 2014 in which they reported themselves as being "potentially" breached. The amount of cards that were potentially stolen is still unclear. Recall what happened last year to Target. Target operates about 1800 stores in the US. Last November and December in 3 weeks, data from over 40 million cards were stolen. Fast forward to now... Home Depot operates about 2200 stores. Some banks and credit unions are reporting that the Home Depot began to get infected with the same malware as target as far back as April or May of 2014.
My own observation, why did it take them 6 days to decide whether card information had been stolen or not? I would say that this correlates with the length of time they were infected with the malware and how long it went undetected. Why are we just now finding out this information? I wonder how many POS transactions occurred using an electronic payment (credit/debit) between April or May until now. I'm sure that Home Depot receives less card swipes per day, however the
length of time this has gone on unnoticed is astonishing. I'm very
curious to see how much data has been stolen during this lengthy
incident. I would say that someone is obviously going to be losing their job.
My simple advice: Cash is King.
Sources:
The Verge
Naked Security
This was posted today, after my post was published by Rebecca Abrahams on Huffington post. She definitely is thinking the exact same way as myself. I thought this was an interesting piece to add.
ReplyDeleteSomething's Wrong With Home Depot's Explanation of the Hack