Data breach
HomeDepot (Partial)
- Records
- 10,549,381
- Breach date
- 10 October 2025Estimated
- Added
- 3 October 2025
What was exposed
3 types of data · 1 more reported
- Email addresses1
- Home addresses1
- Phone numbers1
- NamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A group calling itself "Scattered LAPSUS$ Hunters" has claimed the theft of customer data from Home Depot's Salesforce environment, along with data from dozens of other companies. According to DataBreaches.net, the group launched a leak site on October 3, 2025, listing 39 organizations whose Salesforce databases it says it accessed through social engineering, and threatened to publish the data unless Salesforce paid a ransom by October 10, 2025.
Our investigation team indexed 10,549,381 rows associated with this Home Depot listing, which we added to our records on October 3, 2025. The listing is marked as a partial dataset, meaning it may not represent the full scope of the company's exposed records. Our team estimates the incident date as October 10, 2025.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
October 3, 2025: Scattered LAPSUS$ Hunters launched a leak site listing 39 organizations, including Home Depot, and set an October 10 deadline for Salesforce to begin ransom negotiations, according to DataBreaches.net and Help Net Security.
October 6, 2025: Salesforce published a security advisory stating there was no indication its platform had been compromised and that the extortion attempts appeared related to past or unsubstantiated incidents, per Help Net Security.
October 8, 2025: Salesforce confirmed it would "not engage, negotiate with, or pay any extortion demand," a spokesperson told Help Net Security.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, and home addresses.
Reporting by DataBreaches.net, which reviewed sample data from the listing, described a file devoted to government employees that contained names, email and postal addresses, and phone numbers. The outlet noted the individuals were a mix of federal, state, and county employees, and that some records appeared to include home addresses rather than work addresses.
The exact number of affected individuals for each data type is not confirmed in the available sample data.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Contact details combined with home addresses support a range of scams. Criminals can use them for targeted phishing emails, text-message fraud, and phone scams that reference real personal details to appear legitimate. Exposure of home addresses also raises privacy and physical safety concerns, particularly for the government employees named in the reviewed file. Because the listing does not include payment card data or Social Security numbers according to available reporting, direct financial fraud from this dataset alone appears less likely, though it could support identity-related schemes when combined with information from other breaches.
What Should You Do If You Were Affected?
Be skeptical of unexpected emails, texts, or calls that reference Home Depot purchases or personal details. Attackers who hold your contact data can make messages look convincing.
Do not click links or open attachments in unsolicited messages. Go to retailer websites directly by typing the address yourself.
Check your accounts for unusual activity and enable multi-factor authentication where available.
Consider limiting what personal information, such as a home address, you share with retailers when it is not required.
In the news
- SecurityWeek: Hackers Extorting Salesforce After Stealing Data From Dozens of Customerssecurityweek.com (opens in a new tab)
- Help Net Security: Hackers launch data leak site to extort 39 victims, or Salesforcehelpnetsecurity.com (opens in a new tab)
- DataBreaches.net: More Salesforce customer attacks revealed in new leak site by Scattered LAPSUS$ Huntersdatabreaches.net (opens in a new tab)
