Home Depot confirmed a vendor exposed employee data leaked by IntelBroker
- Organization
- The Home Depot
- Exploit
- Third-Party Data Breach
- Industry
- Retail
On April 4, 2024 the threat actor known as IntelBroker posted a file on the BreachForums hacking site that it said held records on about 10,000 Home Depot employees. The data consisted of names, work email addresses and internal user or corporate IDs. No customer records, payment card data or financial information were involved.
Home Depot confirmed that employee information had been exposed but placed the cause outside its own systems. Spokesperson Beth Marlowe said a third-party software-as-a-service vendor "inadvertently made public a small sample of Home Depot associates' names, work email addresses and User IDs during testing of their systems." The company declined to name the vendor.
Home Depot also declined to confirm how many associates were affected. The Register noted the gap between the retailer's description of a small sample and IntelBroker's claim of roughly 10,000 records, and said it had not independently verified the leaked file.
Researchers said the practical risk was social engineering rather than direct financial fraud. A verified list of staff names and corporate email addresses gives attackers a ready target set for phishing aimed at harvesting credentials that could open access to internal systems. Home Depot said its own network had not been breached.