THE HOME DEPOT, INC.
ent_019de6022dda76c467e93c9228945eaa
Disclosures
4
Leak Site · State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
—
no filed count in sample
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- THE HOME DEPOT, INC.
- Normalized
- the home depot— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- QEKMOTMBBKA8I816DO57
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- homedepot.com
Disclosure history (4)newest first
- GLOBALLeak Siteas victim2025-09-07
Home Depot is the largest home improvement retailer in the United States. It is a one-stop-shop for tools, construction products, and various services. The company caters to do-it-yourself (DIY) customers, professional contractors, and the construction industry. It offers installation services and tool and equipment rental in addition to selling a litany of home improvement items.
- 🌺Hawaii State AGas victim2014-09-10
The Home Depot, Inc. reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2014/09.10. Breach type: Hackers/Unauthorized Access. Recovered from the Internet Archive after the notice was removed from the OCP table.
- 🐻California State AGas victim2014-09-09
The Home Depot confirmed a breach of payment data systems affecting customers in the U.S. and Canada from April 2014 onwards. Criminals hacked payment systems, compromising cardholder data (names, card numbers, CVVs). No debit PINs or online data were impacted. Home Depot engaged forensic firms and the Secret Service, rolled out EMV chip technology, and offered free credit monitoring to affected customers.
- 🐻California State AGas victim2014-02-10
The Home Depot, Inc. submitted a California SB-44 breach notification regarding an insider threat incident involving three arrested HR associates. Between February 7, 2011, and February 7, 2014, these insiders unlawfully accessed the personal information of current and former associates and candidates. Affected data included names, contact information, Social Security numbers, driver's license numbers, and financial account numbers. The company conducted an internal investigation, cooperated with law enforcement, and provided 12 months of identity protection services to affected individuals.