Skip to Content
Colorado Attorney General

Phil Weiser

Colorado Attorney General

File A Complaint
  • About Us
    • Attorney General Bio & Photos
    • Vision & Values
    • Senior Staff & Organization
    • Colorado Attorney General Annual Report
    • Attorney General Opinions
    • Contact Our Office
  • Sections
    • Administration
    • Business & Licensing
    • Civil Litigation & Employment Law
    • Consumer Protection
    • Criminal Appeals
    • Criminal Justice
    • Natural Resources & Environment
    • Office of Community Engagement
    • Revenue & Utilities
    • State Services
  • Careers
    • Attorney & Other Non-Classified Positions
    • Fellowships
    • Cybersecurity Fellowship
    • Natural Resources & Environment (NRE) Fellowship
    • Internships
    • Classified Staff Positions
  • Media Center
    • Press Room
    • Colorado Open Records Act – CORA
  • Resources
    • Survivors of Childhood Sexual Abuse
    • Victim Assistance
    • Budget & Accounting
    • Code of Colorado Regulations
    • Colorado Revised Statutes
    • Coronavirus Information
    • Data Protection Laws
    • Transparency Online Project (TOPS)
  • Licensing
    • Business Resources
    • Collection Agencies & Debt Collectors
    • Colorado Uniform Consumer Credit Code: Licensing & Notification
    • Debt Management Services Providers
    • Health Club Bonds
    • Repossessors
    • Student Loan Servicers: Licensing
    • Telemarketing
  • Recursos en español

Colorado to receive more than $200,000 in data breach settlement with The Home Depot

Nov. 24, 2020 (DENVER, Colo.)—Attorney General Phil Weiser today announced that the State of Colorado will receive $223,797.22 in a multistate settlement with The Home Depot, following a data breach that exposed the payment card information of about 40 million Home Depot consumers nationwide.

Weiser, along with the attorneys general of 45 other states and the District of Columbia, obtained a total of $17.5 million in the settlement, which resolved a multistate investigation of the 2014 breach.

The breach occurred when hackers gained access to The Home Depot’s network and deployed malware on The Home Depot’s self-checkout system. The malware allowed the hackers to obtain the payment card information of customers who used self-checkout lanes at The Home Depot stores throughout the U.S. between April 10, 2014, and Sept. 13, 2014.

“The Home Depot violated the Colorado Consumer Protection Act in failing to appropriately protect its customers’ data,” Weiser said. “This settlement will help ensure that the business employs proper measures in the future and demonstrates that we take seriously the rights of Colorado consumers.”

In addition to the $17.5 million total payment to the states, The Home Depot has agreed to implement and maintain a series of data security practices designed to strengthen its information security program and safeguard the personal information of consumers.

Specific information security provisions agreed to in the settlement include:

  • Employing a duly qualified Chief Information Security Officer;
  • Providing resources necessary to fully implement the company’s information security program;
  • Providing appropriate security awareness and privacy training to all personnel who have access to the company’s network or responsibility for U.S. consumers’ personal information;
  • Employing specific security safeguards with respect to logging and monitoring, access controls, password management, two factor authentication, file integrity monitoring, firewalls, encryption, risk assessments, penetration testing, intrusion detection, and vendor account management; and
  • Consistent with previous state data breach settlements, the company will undergo a post settlement information security assessment which in part will evaluate its implementation of the agreed upon information security program.

The more than $200,000 Colorado will receive will be used by the Attorney General’s Office for reimbursement of the State’s actual costs and attorneys’ fees, and for future consumer fraud or antitrust enforcement, consumer education, or public welfare purposes.

Consumers affected by the data breach were compensated through a previous settlement.

###

Media Contact:
Lawrence Pacheco
Director of Communications
(720) 508-6553 office | (720) 245-4689 cell
Lawrence.pacheco@coag.gov

Most Recent

Colorado business agrees to pay $70,000 to the State after misleading buyers about masks and respirators, price gouging during COVID-19 crisis  

Jan. 25, 2021 (DENVER, Colo.)—Attorney General Phil Weiser today announced his office has reached a settlement with Denver-based Nationwide Medical Supply Inc., after the business made misleading claims about the masks and respirators it sold and charged unreasonably excessive prices […]

Weiser joins coalition of 18 attorneys general defending key provision of the Voting Rights Act before U.S. Supreme Court

AGs argue that provision removes racial barriers to voting without infringing on state sovereignty Jan. 22, 2021 (DENVER, Colo.) – Attorney General Phil Weiser has joined a coalition of 18 attorneys general urging the U.S. Supreme Court to uphold a ruling […]

Attorney General Phil Weiser leads coalition of 50 state and territorial attorneys general in condemning the violent U.S. Capitol riot, calls for president’s impeachment

 Jan. 13, 2021 (DENVER, Colo.)— Colorado Attorney General Phil Weiser today led a bipartisan coalition of 50 states, territories, and the District of Columbia that sent a letter to Acting U.S. Attorney General Jeffrey A. Rosen, condemning the Jan. 6 […]

Office of the Attorney General
Colorado Department of Law
Ralph L. Carr Judicial Building
1300 Broadway, 10th Floor
Denver, CO 80203

(720) 508-6000

Contact the Office of the Attorney General

Contact

Facebook
Twitter
CORONAVIRUS ALERTS