Daily Local News (West Chester, PA)

Worker data leaked

- By Michael E. Kanell

Private informatio­n for about 10,000 Home Depot employees has been leaked onto a website used by internet hackers, according to the company and reporting by a number of tech industry news organizati­ons.

The leak was accidental and was caused by a software vendor, said Beth Marlowe, a Home Depot spokeswoma­n.

“A third-party software-as-a-service vendor inadverten­tly made public a small sample of Home Depot associates’ names, work email addresses and User IDs during testing of their systems,” she said. “It was not some breach of our system.”

The vendor’s mistake was leaving the informatio­n visible on the web for others to see. It was retrieved by a hacker known as IntelBroke­r, who then posted the data on the illicit forum BreachForu­ms, according to Cybernews.

IntelBroke­r said it had the data for 10,000 Home Depot employees. The company declined to confirm that number, but said it was “a small sample.”

While this data is not highly sensitive, exposing only corporate IDs, names, and email addresses, it could be used by threat actors to conduct targeted “phishing” attacks against Home Depot employees, CyberNews said.

That kind of data can be used to launch waves of messages to unsuspecti­ng consumers in an effort to get them to provide more sensitive informatio­n, such as Home Depot credential­s, which could then be sold to others who might use the informatio­n to breach the company’s network and steal corporate data or deploy ransomware.

The company said it has taken steps to tighten security against any misuse of the data.

Newspapers in English

Newspapers from United States