Running Head: A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA
BREACHES
awEGGWW4T4YQY5ATHU6TUHTJYJWY
A Case Study Analysis Target and Home Depot Data Breaches
Name of Student
Institutional Affiliation
A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA BREACHES
A Case Study Analysis Target and Home Depot Data Breaches
Introduction
Data privacy and cyber security are real risks to companies: in the wake of data breach,
most employees may be terminated or face personal liability, the company may face regulatory
investigations, multitude lawsuits, disruption of business, fall of stock price, and the reputation
of the enterprise may weaken. Hacking is a serious issue, a potential threat to every computer
system. Cybercrime or internet hacking, according to Computer Crime Research Center Aghatise
E. Joseph is an internet crime committed using a computer as a tool or a victim targeted (Joseph,
n.d.). Notably, it is much challenging to categorize general internet crimes into distinct groups
since most cyber crimes evolve on a daily basis. However, public relations professionals provide
a proportionate procedure of handling internet security crises to restore the company reputation.
It all counts down on trust of the consumers to the company that their personal information will
be safe despite the crisis. Therefore, how companies respond to data breaches can damage or
build the corporate reputation and hard-earned trust. Since data breaches compromises are often
complex, the procedure of making a rapid communications decisions required to curb the
potential harm of the data breach is often challenging.
The situations are often further complicated owing to the reality that every data breach
differs from the other, and there may be no precedent within the organization to respond to the
crisis. The impact of mishandled breach can reach throughout the business both in short and
long-term; lost sales, bad press, litigation and mitigation alongside uphill battle to rebuild the
company reputation. Apparently, most of the breaches involved compromise or theft of
identifiable information, such as addresses, names, and social security numbers. Many
information security professionals will remember 2104 as the year of the big data breaches, and
A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA BREACHES
with a good reason. Besides the occurrence of numerous high-profile hack attacks, the year
incorporated various lesser known incidents that nevertheless led to significant theft records,
according to a report by Timothy, (2015). Breach crimes went up to a total of 1, 540 representing
46 percent from the increase 1,056 in 2013.
More importantly, the dramatic rise in data records involved in the breaches that jumped
78 percent from approximately 575 million in 2013 to more than one billion in 2014 (Timothy,
2015). Following the time perspective, in 2014 alone, some 2,803,036 data records were stolen
every day, 116,793 every hour and 1,947 every minute and so on (Timothy, 2015). Despite the
growing interest of technological encryption as a security measure to protect privacy and
information, only 58 percent of the data breach incidents in 2014 representing less than 4 percent
of the total involved that was encrypted in fully or partially. However, beyond the numbers were
the economic, social, and political impacts of the breaches. Some of the big data breaches in the
year 2014 names Home Depot and entertainment company Sony Pictures Entertainment. This
reality- based case study will examine two examples of cyber crime that happen in 2013/2014:
the data breach at Target and the one at Home Depot. This study highlights the strengths and
weaknesses of public relations at Target and Home Depot during their recent data breach crises.
The public relations and marketing plans that Target and Home Depot pursued while they were
victims of cyber crime will be analyzed, followed by communications recommendations that
may help keep an already bad situation from becoming worse. The case study prepares a robust
analysis of data breach crisis response using Target and Home Depot. It identifies the data breach
scenario in the company, their response followed by evaluation and recommendation of data
breach response based on public relations literature.
Problem Statement
A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA BREACHES
Cyber attacks make news headlines almost every day these days, essentially, when they
hit global credit card companies, major retailers, and high-tech leaders. Recently, financial data
breaches have exposed a good number of company’s personal information concerning finances,
healthcare, personally identifiable information (PII), and legal issues. The criminal act of cyber
has predominantly been affected by outside hacking computer systems of institutions and the
insiders with or without authorized access to the information. According to Timothy (2015), 78
percent of all records compromised during the initial six months of 2014 were exposed as a result
of the outside hackers. More recently, Target and Home Depot has fallen victims of these
incidences recording huge financial losses. Specifically, Home Depot reported 56 million
customer email addresses and payment cards while Target reported 40 million payment cards
and 70 million records of customer names, telephone numbers, addresses, and emails.
The data of small and middle size companies are increasingly being hacked. Target and
Home Depot is considered one of the worst data breaches in history of American data breach
crimes. Cyber security has been named top five global company risks for companies, according
to World Economic Forum. It is reported that the plethora of new hackers opportunities include
mobile device use, increased use of cloud computing and corporate espionage. Despite the
looming cyber threats, according to Timothy, many senior company managers remain denial and
have not been able to put up robust public relations measures to respond to data breaches crises
through professionalized communication strategies. Accordingly, data breaches that result in
compromising of personal information or disclosure of personally identifiable information from
consumers or employees, in particular, can have a significant impact on the company’s bottom
line. Public relations strategies help prepare the companies for a quick response to data breach
scenarios by ensuring proper communication strategy to mitigate the crisis.
A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA BREACHES
Background of Data Breach
While there are emerging efforts to promote internet security systems, hackers continue
to poke holes in a number of industries, instigating disorder to both the consumers and the
corporations that trust their information will be protected. Definitely, mishandling of consumer
data and inadequate company safeguards can come at a high price from lawsuits and consumer
mistrust, resulting in devalued company stocks. Primarily, the security data breaches at Target
and Home Depot cost the company approximately $248 million and 3 billion dollars
respectively.
Home Depot Data Breach
Home Depot retail references an American based retailer dealing with home
improvement and product services. The company operates numerous big-box format stores
across the U.S. Mexico and all the ten provinces of Canada. The breach against the United States
based home improvement specialty retailer involved financial access attack that mentions 109
million records and scored 10.0 on the risk assessment scale. This was considered on of the
largest attacks of the year based on the records compromised, Hill (2014) reports. According to
the company official statement, its payment data systems got attacked. Notably, the files that
contained the stolen email addresses never contained payment card information, passwords or
other sensitive personal or private information, the report reads. More specifically, in September
2014, the US home improvement retailer, Home Depot, established it experienced a breach in
security that affected approximately 56 million debit and credit cards in United States and
Canada (Hill, 2014). The data breach criminals used unique, custom-built malware to steal the
account numbers from the point of sale systems of Home Depot. The do-it-yourself retailer owns
and operates 180 stores in Canada and more than 2, 200 in the United States. Reports from Home
A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA BREACHES
Depot Company indicated that cyber criminals armed with custom-built malware stole
approximately 56 million cards numbers from the customers from April to September 2014. The
disclosure made the crime the biggest incident card breach on record.
The disclosure that was first released in September indicated that the malicious software
used by the unknown cyber criminals to steal debit and credit cards was mainly installed on the
payment systems in the self-checkout at retail stores. While investigations revealed that the
criminals stole fewer cards in the period of five months breach than they might otherwise. Home
Depot release dated September 18, 2014, through investigations indicated that the cyber thieves
used unique, custom built malware to evade detection. Apparently, the malware had not been
seen previously in other cyber attacks, according to the Home Depot security partners (Home
Depot Security Breach, 2014). It is estimated that the cyber attack put payment card information
at risk for nearly 56 million unique payment debit and credit cards. Hill, (2014) finds that that the
malware is believed to have been present from April to September 2014. Besides, Home Depot
statement established that it had completed a security upgrade that would deter any further
breach of its system in its retail stores in United States and would roll out updated and enhanced
encryption of the stores in Canada. According to Home Depot Security Breach (2014), the
terminals identified with the malware were taken out of service and eliminated from the systems
of the company. Today, the Canadian debit and credit cards have chip technology that protects
the customers. Home Depot subsequently assured the customers that there is no evidence the
cyber criminals gained access to the customers PINs.
Target Data Breach
The Home Depot cyber crime story is no an isolated incident. On December 19, 2013,
United States-based retail giant Target provided a statement indicating that it had suffered a
A CASE STUDY ANALYSIS TARGET AND HOME DEPOT DATA BREACHES
major credit card data breach between November 27 and December 25, 2013. The released
statement confirmed a previous report of the December 18 data breach. A report by In Hardy,
(2014) indicates that Target engaged both the federal law enforcement including private incident
response firm and U.S Secret Service to investigate the nature and scale of the data breach.
However, on December 23, Target suggested that malware installed on point of sale (POS)
terminals provided an edge for the breach, a fact that the statement release of the company
confirmed in early January 2014. However, Target representatives have released little narrative
and technical detail on the attacks, which is often typical for institutions that have suffered cyber
crime incidences.
According to statement released by Target, from November to December 2013,
information on approximately 40 million payment cards, for example, debit, credit, and ATM