Home Depot to Pay $19.5 Million Over Big 2014 Hack Attack More than 50 million cardholders were affected in the breach.

By Reuters

This story originally appeared on Reuters

Home Depot Inc. agreed to pay at least $19.5 million to compensate U.S. consumers harmed by a 2014 data breach affecting more than 50 million cardholders.

The home improvement retailer will set up a $13 million fund to reimburse shoppers for out-of-pocket losses, and spend at least $6.5 million to fund 1-1/2 years of cardholder identity protection services.

Home Depot also agreed to improve data security over a two-year period, and hire a chief information security officer to oversee its progress. It will separately pay legal fees and related costs for affected consumers.

Terms of the preliminary settlement were disclosed in papers filed on Monday with the federal court in Atlanta, where Home Depot is based.

Home Depot did not admit wrongdoing or liability in agreeing to settle. The settlement requires court approval.

"We wanted to put the litigation behind us, and this was the most expeditious path," spokesman Stephen Holmes said. "Customers were never responsible for any fraudulent charges."

Home Depot has said the breach affected people who used payment cards on its self-checkout terminals in U.S. and Canadian stores between April and September 2014.

It has said the intruder used a vendor's user name and password to infiltrate its computer network, and used custom-built malware to access shoppers' payment card information.

The accord covers about 40 million people who had payment card data stolen, and 52 million to 53 million people who had email addresses stolen, with some overlap between the groups.

Home Depot said in November it had incurred $152 million of pre-tax expenses from the breach, after accounting for expected insurance proceeds.

Lawyers for the consumers said the accord compares "favorably" with other data breach class actions, including Target Corp.'s $10 million settlement over a 2013 data breach that compromised at least 40 million cards.

Legal fees and costs for the lawyers could top $8.7 million, court papers showed.

At least 57 proposed class action lawsuits were filed in U.S. and Canadian courts over the data breach. The U.S. cases were consolidated in the Atlanta court.

(Reporting by Jonathan Stempel in New York; Additional reporting by Nate Raymond; Editing by Chris Reese and Richard Chang)

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Making a Change

A One-Time Payment of $20 Gets You Access to 1,000+ Courses Forever

Curated, high-impact courses across business, tech, and more.

Buying / Investing in Business

Former Zillow Execs Target $1.3T Market

Co-ownership is creating big opportunities for entrepreneurs.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

Franchise

She Turned a Temporary Post-College Job Into Starting a Business at 23. Then Some 'Eye-Opening' Advice Helped Her Grow It to $5 Million.

Brooke Wilson turned a part-time, temporary role into a $5 million business with a combination of ambition, team-building and learning to delegate.

Business Solutions

Still Have Windows 10? Upgrade to the Latest OS With Copilot While It's At Its Lowest Price Ever.

Windows 10 is due to be phased out, so now might be the best time to upgrade your OS.

Growing a Business

I Sold My Company for Nine Figures. Here Are 3 Hard Lessons That Got Me There

The learning curve was steep when I founded Briogeo. Avoid these mistakes I made!