On 2 September 2014 a card shop, rescator[dot]cc, put up a fresh batch of stolen American cards under the name "American Sanctions", with a companion batch of European cards labelled "European Sanctions" — the criminals' joke about the measures then being taken against Russia over Ukraine. Banks that bought samples back found the same shop behind every one: The Home Depot. Brian Krebs published the finding that day, and the retailer's spokeswoman, Paula Drake, would say only that "I can confirm we are looking into some unusual activity and we are working with our banking partners and law enforcement to investigate." The alarm, in other words, was a criminal's stock list. By the following day the underground data indicated that nearly every American store was involved.

The company confirmed a breach on 8 September and filed the number on the 18th: approximately 56 million unique payment cards from stores in the United States and Canada, between April and September 2014, beating Target's 40 million of nine months earlier and the at least 45.7 million TJX had admitted to before that. The malware was custom-built and had not been seen before, Home Depot said. Trend Micro had described a new BlackPOS variant on 29 August that read card data from a terminal's memory and hid itself as a component of the antivirus product on the machine. The rollout of payment encryption to every American store finished on Saturday 13 September; banks told Krebs that cards were still being stolen until the 7th, five days after the theft became public.

How the intruders got in was not disclosed until November: Home Depot said they had used a third-party vendor's user name and password to get inside the network, then acquired elevated rights; the Wall Street Journal reported that the escalation used a Windows flaw patched after the breach began. The choice of till, on the same reporting, was almost administrative: the intruders went for the 7,500 self-checkout lanes because the company's own systems named them as payment terminals, while the 70,000 ordinary registers carried only a number. Former staff told the New York Times that they had warned about the network for years, that the tills ran a Symantec product from 2007, and that a manager had brushed off a request for money by saying the company sold hammers — their account, not the company's.

In early November Home Depot added that 53 million email addresses had been taken as well, in files holding no passwords or card data, and warned customers to expect phishing. It was not the month's only card theft: on 16 September a payment systems vendor, C&K Systems, disclosed that intruders had been inside its systems for more than eighteen months, affecting over 330 Goodwill locations, and on 24 September Jimmy John's confirmed a vendor breach at 216 stores, widened two days later to almost a hundred more independent restaurants. The bill arrived slowly and in public. By the close of its 2015 financial year the company had recorded $261 million of pre-tax gross expenses related to the breach, partially offset by $100 million of expected insurance proceeds.

Also that month · 24 September

Twenty-five years in a shell

On 12 September 2014 Stéphane Chazelas told Chet Ramey, the maintainer of GNU Bash, that the shell would execute whatever followed a function definition inside an environment variable. The flaw dated to 5 August 1989 and shipped in Bash 1.03 that September; every version to 4.3 carried it. Disclosure came on 24 September as CVE-2014-6271, and within an hour machines were being compromised. The first patch was incomplete: Google's Tavis Ormandy found a way past it, which became CVE-2014-7169, and four more identifiers followed by 30 September. Anything that passed a request into a shell was exposed — CGI web servers above all, but also DHCP clients, OpenSSH forced commands and IBM's hardware management console. Worms appeared within a day. One count on 26 September recorded 17,400 attacks on over 1,800 domains; by the 30th CloudFlare was seeing around 1.5 million attacks and probes a day, and Apple shipped its OS X patch on the 29th. Nicholas Weaver of the International Computer Science Institute gave the durable verdict that week: it would be with us a long time, because it would sit in embedded systems nobody updates.

Also that month · 5–10 September

Two answers and a scare

Apple spent the first week answering for the last one. Private photographs taken from celebrities' iCloud accounts had been posted over the Labor Day weekend; the company said the accounts had been picked off individually rather than through any breach of its systems. On 5 September Tim Cook told the Wall Street Journal that Apple would begin alerting users when a password changed, when iCloud data was restored to a new device or when a device signed in for the first time, and would press two-step verification with iOS 8. Four days later it announced Apple Pay alongside the iPhone 6, a scheme in which the shop never handles the card number. On 10 September a file of 4.93 million Gmail addresses and passwords, posted to a Russian forum the day before, was reported as a Google breach. It was not one: the pairs had been gathered from other sites over years, and Google said fewer than two per cent would have opened an account. Salesforce had told administrators on 3 September that a partner had found the Dyre banking trojan turning towards its users, with no evidence any customer was affected.

India desk · September 2014

Thirty million new cards

India spent September 2014 doing the opposite of what Atlanta was doing: issuing payment cards as fast as banks could print them. The Pradhan Mantri Jan Dhan Yojana, launched on 28 August 2014, opened 15 million accounts on its first day and 18,096,130 in the week to 29 August, a total Guinness World Records certified; by September the count across public sector banks stood at about 30.2 million. Each account came with a RuPay debit card. Most of the accounts were empty — 76.8 per cent held a zero balance that September — but the cards were real, and they carried a magnetic stripe, the same static and copyable strip of oxide whose contents the malware in Home Depot's self-checkout lanes had been sitting in memory to collect.

The Reserve Bank of India had already started moving the other way. A direction of 28 February 2013 gave banks until 30 June that year to convert to EMV chip-and-PIN the card of every customer who had used one abroad even once, and to have the terminals standing on merchants' counters certified to the card industry's security standards. In May 2015 the central bank told banks to issue only chip-and-PIN cards from 1 September 2015, a date later moved to 31 January 2016 for everything except Jan Dhan cards, and set 31 December 2018 as the day the last magnetic-stripe-only card stopped working. The United States reached its own chip deadline on 1 October 2015, and it was a liability shift rather than a rule. What India did not have in 2014 was any obligation to tell anyone when data went missing — the gap that CERT-In's six-hour direction of 2022 and the DPDP Act of 2023 eventually closed.

AI Tech desk · September 2014

Twenty-two layers deep in Zurich

The results of the ImageNet Large Scale Visual Recognition Challenge were presented at a workshop in Zurich on 12 September 2014, and they were not close. Classification went to GoogLeNet, a twenty-two-layer network from Google, at 6.66 per cent top-five error; Oxford's Visual Geometry Group took localisation with a plainer stack of small convolutions and came second at classification. Both papers were posted that month, Oxford's on the 4th and Google's on the 17th, and the line ran on to the 152-layer residual network of December 2015. Ten days before the workshop Andrej Karpathy, then a graduate student at Stanford, had published his own score on a sample of the test set, 5.1 per cent, with the caution that human accuracy "lives on a tradeoff curve" rather than sitting at a point. Two quieter papers carried further: Bahdanau, Cho and Bengio's attention mechanism on the 1st, and Sutskever, Vinyals and Le's sequence-to-sequence translator on the 10th, at 34.8 BLEU against a phrase-based system's 33.3. Attention became the Transformer three years later.

Digital Guard desk · September 2014

Nine products and a permanent chief

On 23 September 2014 Symantec put Norton Security on sale in North America at $79 a year for five devices, one subscription in place of the nine consumer products it had been selling, Norton AntiVirus and the several editions of Norton 360 among them. Two days later, after a six-month search of more than a hundred candidates, Michael A. Brown was made chief executive outright, having held the post on an interim basis since March; he was the third permanent chief in three years, and on 9 October the company announced it would separate into two public companies, one for security and one for information management. On the 3rd AVG had agreed to buy Location Labs for $140 million and up to $80 million more on performance, its chief executive Gary Kovacs praising a firm that had "cracked the code for mobile monetization"; the last week of the month went on emergency Bash signatures and free scanners. Brown was gone by April 2016, and AVG and Norton now sit inside one company, Gen Digital.

⏳ Time capsule — September 2014

  • On 15 September Microsoft announced an agreement to buy Mojang, the Swedish studio behind Minecraft, for $2.5 billion; the acquisition was completed on 6 November.
  • On 18 September Scotland voted on independence, rejecting it by 2,001,926 votes to 1,617,989 — 55.30 per cent to 44.70 — on a turnout of 84.59 per cent, with 16- and 17-year-olds voting for the first time.
  • On 19 September Alibaba began trading on the New York Stock Exchange under the ticker BABA at $68 a share, raising about $25 billion in the largest initial public offering to that date.
  • On 24 September, at 02:10 UTC, India's Mars Orbiter Mission entered orbit around Mars at a cost of about ₹450 crore, making ISRO the second space agency to succeed at Mars on its first attempt after the European Space Agency in 2003; contact was finally lost in April 2022.
Where it stands today — 2026

The strip that had to go

A decade on, September 2014 is the month the retail card breach stopped being an anomaly and became a category. Target, in December 2013, could still be argued away as one badly run network; 56 million cards from the largest home-improvement chain in America — taken through a supplier's password and tills the company's own directory had labelled for whoever got in — could not. The chip-card liability shift of 1 October 2015 followed, and with it the slow retirement of the swipe. The settlements arrived long after the cards were cancelled: at least $19.5 million to consumers in 2016, $25 million to financial institutions in 2017, and $17.5 million to 46 states and the District of Columbia in November 2020.

Card theft did not stop; it moved. Once the number was harder to lift off a shop floor, it was taken where it is still typed by hand, and by September 2018 twenty-two lines of JavaScript on an airline's checkout page were enough to read payment details out of the browser. Shellshock aged differently. The patches came within days, the follow-on identifiers within a week, and the internet-facing web servers were largely fixed inside a few months — but the bug is still turned up in 2026 in the equipment nobody updates, the routers and cameras and industrial boxes that ship a shell and never a patch. Weaver's warning in that first week is the part of the month that held.