It's the talk of the cyber security community.
Forensic specialists from the U.S. Secret Service are leading the investigation, but Home Depot brass -- and millions of customers -- can do nothing but wait as federal agents and security investigators work around the clock to figure out exactly what transpired after a massively mysterious malware attack penetrated the retailers systems' beginning in April.
A Home Depot spokesperson told VentureBeat Wednesday there weren't any updates to the complex investigation, in which a supercharged malware strain called BlackPOS, similar to that used to breach Target's point of sales (POS) machines in December, wormed its way into the Atlanta-based company's POS systems.
This is day 8 of the investigation, and Krebs on Security disclosed that as of Tuesday, Home Depot credit cards continue being dumped on the cyber black market in large batches on the likes of Rescator.cc, a marketplace well known to federal law enforcement, where boosted credit cards and PIN numbers of PayPal accounts are sold.
Are you a Home Depot customer? If so read this from Krebs:
"The card data stolen from Home Depot customers and now for sale on the crime shop Rescator[dot]cc includes both the information needed to fabricate counterfeit cards as well as the legitimate cardholder’s full name and the city, state, and ZIP of the Home Depot store from which the card was stolen."
Many customer credit cards have been used on buying sprees at U.S. retailers, and some of the cards have been reconfigured with user data, like Social Security numbers and addresses, in order to change PIN numbers that enable the withdraws. Incredibly, the U.S. Secret Service has been unable to take Rescator.cc down, despite its flourishing trade.
The Target breach, which saw nearly 70 million customer credit cards lifted for over $100 million in fraudulent purchases, ended up costing then-CEO Gregg Steinhafel his job, albeit with a $15 million exit package.
Since the breach first came to light last Tuesday, Home Depot CEO Frank Blake has addressed the malware attack twice: once last week at a Goldman Sachs retail conference and again on Monday, where he was quoted in a release acknowledging the attack while letting customers know they weren't on the hook for unwanted merchandise bought on their stolen cards.
Questions abound because it was Home Depot's banking partners who first noticed credit cards for sale on the black market and then traced them to the retailer. Also, the hit was so surreptitious that Home Depot security specialists never knew they'd been taken.
This means the cyber criminals were able to use the stolen cards and customer data for the entire summer before the party ended.
For Home Depot, the real story on this BlackPOS hit has yet to be written. And so has the ultimate tally, including whether company security protocols were asleep at the wheel.
