Home Depot Inc. , the largest U.S. home improvement retailer , will pay $17.5 million to resolve a 2014 data breach in which hackers accessed payment card data belonging to 40 million customers from multiple states.

The settlement, which involves 46 US and Washington, concerns the breach that took place between April 10, 2014, and September 13, 2014, affecting customers who used checkout terminals at the company's stores in the US and Canada.
The attackers used a supplier's username and password to infiltrate Home Depot's network and developed custom malware to access customers' payment card information.
The Atlanta-based company previously said that at least 52 million people were exposed due to the breach, resulting in their email addresses being leaked, making up a large portion of the customers affected, in addition to those whose payment card data was compromised.

Home Depot, however, did not admit responsibility for accepting the settlement, which requires it to hire a chief information security officer and upgrade security and staff training. The investigation was conducted by the states of Connecticut, Illinois and Texas.
Companies that collect sensitive personal information from customers “have an obligation to protect that information from unlawful use or disclosure,” said Connecticut Attorney General William Tong. “Home Depot failed to take these precautions.”
In a statement, Home Depot said security is a top priority for the company and that since 2014 it has “invested significantly to further secure its systems.” Home Depot had previously recorded $198 million in costs for the breach and had resolved the issues that had arisen with customers, card issuers and banks that claimed to have been affected.
