Home Depot Struck by Same Malware that Rocked Target

By

Late last year, Target was struck by a devastating malware attack that released the personal information of millions of customers including names, addresses and credit card numbers. Now, it appears the same software was used in another attack launched against Home Depot last Tuesday.

Last year's attack on Target exploited security vulnerabilities on the company's point-of-sale (POS) systems, where the retail transactions take place. A malware strain known as “BlackPOS” was able to copy and transmit customer data as the transaction was taking place, and this same software was found within Home Depot's cash registers.

RedSeal Networks, a leading provider of end-to-end network visibility and cyberattack prevention analytics claims that this attack is part of a rising trend. “The similarity of the Home Depot breach to the Target breach is a useful object lesson in how security works nowadays,” said the company's CTO Dr. Mike Lloyd. “Similar to any criminal investigation, it's worth thinking about motive, means and opportunity.”

“Motive hasn't changed much – it's easy to see why some people would steal money, when it's easy enough. Means do change – automated tools are continuously being developed, and largely automated” continued Lloyd.

 This means that when an attack works once, it's likely to work again, and automation allows attackers to sit back and have computers hunt down any other victims who are vulnerable in the same way. And as for the opportunity, the problem there is that our defenses are generally weak. The fact that the same exploit worked at both Target and Home Depot is a reminder of the IT mono-culture, and the serious perils of under-investment in defensive security automation.

By increasing variety in the way POS systems work, businesses will not have to live in fear of BlackPOS attacks. Unfortunately, the current security systems climate is rather homogenous, which increases the effectiveness of repeat attacks like this one.




Edited by Maurice Nagle
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

TechZone360 Contributing Writer

SHARE THIS ARTICLE
Related Articles

Why More Leads Won't Fix a Broken Lead Management Process

By: Contributing Writer    6/23/2026

When sales results start to stall, many organizations immediately look to the top of the funnel for answers. The assumption is simple: if revenue i…

Read More

Your Post-Quantum Readiness Starts at Y2Q Summit

By: TMCnet News    5/27/2026

Y2Q Summit is an executive conference focused on helping enterprises prepare for the coming era of quantum computing disruption, cybersecurity transfo…

Read More

Why Award Marketing Should Be Part of Every B2B Tech Company's Growth Strategy

By: Erik Linask    5/20/2026

Award marketing matters for B2B tech companies because industry recognition can strengthen trust, support sales and partner relationships, improve con…

Read More

Why Email Is Still the Most Underrated Layer of Modern Software Infrastructure

By: Contributing Writer    5/15/2026

Take, for example, the following scenario. A user requests a password reset, waits a few seconds, refreshes their inbox and nothing arrives. They try …

Read More

Jitterbit's Visionary Status Signals a Shift in the iPaaS Market

By: Contributing Writer    4/7/2026

As enterprise ecosystems grow more complex, integration has become less of a backend IT function and more of a strategic driver of business performanc…

Read More