Bloomberg BNA’s Corporate Law & Accountability Report is available on the Corporate Law Resource Center. This news service keeps corporate practitioners informed of legal developments of...
By Yin Wilczek
June 16 — A shareholder has sued Home Depot Inc. for access to records behind the company's data breach that compromised the payment card information of up to 56 million customers.
Home Depot confirmed in September that its payment data systems had been breached. Hackers stole the credit and debit card information of 56 million customers as well as 53 million customer e-mail addresses.
In a complaint filed June 15 in the Delaware Chancery Court, Cora Frohman alleged that the records she sought would show whether Home Depot's officers and directors breached their fiduciary duties and/or took appropriate action in connection with the breach.
“Despite knowledge that such breaches were occurring throughout the retail industry, Home Depot failed to properly protect the sensitive card information from what is now a widely known preventable method of cyber-attack,” Frohman alleged. “There is a credible basis to believe that officers and directors of Home Depot were aware of the risks that the Company faced from a cyber-attack but in breach of their fiduciary duties the Board has failed in its responsibilities to implement systems and internal controls to properly protect the Company from this threat.”
Home Depot spokesman Stephen Holmes told Bloomberg BNA in an e-mail that the company has been “cooperating with and responding to shareholder requests” and will continue to do so moving forward.
“We look forward to resolving the matter,” Holmes said.
The parties stipulated that Home Depot will respond to the complaint by June 23.
The Home Depot incident is one of the largest known attacks on a major retailer. Among other massive incidents, TJX Cos., the parent company of T.J. Maxx, reported a breach in 2007 involving 90 million records.
According to its latest Form 10-Q, Home Depot faces at least 57 class actions in the U.S. and Canada filed by customers, banks, shareholders and others. The U.S. class actions have been consolidated for pre-trial proceedings in the U.S. District Court for the Northern District of Georgia, the filing states.
Frohman's lawsuit was filed under Section 220 of the Delaware General Corporation Law, which allows a shareholder to inspect a company's books and records for “any proper purpose.”
According to Frohman's complaint, in response to her request for records, Home Depot turned over “510 pages” of information in May that was “incomplete, inconsistent, duplicative” and heavily redacted.
• how the company was first notified of the breach and what steps it took after the notification;
• any discussion or analysis regarding how hackers breached its payment data security systems;
• the cost of the company's payment data security system that was in place in April 2014; and
• any discussion or analysis regarding 2013 and 2014 cyber incidents at other major retailers, and whether Home Depot was doing enough to protect customers from similar breaches.
To contact the reporter on this story: Yin Wilczek in Washington at email@example.com
To contact the editor responsible for this story: Ryan Tuck at firstname.lastname@example.org
The complaint is available at http://www.bloomberglaw.com/public/document/Cora_Frohman_vs_The_Home_Depot_Inc_Docket_No_11122_Del_Ch_June_09.
The 10-Q filing is available at http://www.sec.gov/Archives/edgar/data/354950/000035495015000018/hd_10qx05032015.htm#s571C36F0218B6CAF61F5CCF16D7851FA.
All Bloomberg BNA treatises are available on standing order, which ensures you will always receive the most current edition of the book or supplement of the title you have ordered from Bloomberg BNA’s book division. As soon as a new supplement or edition is published (usually annually) for a title you’ve previously purchased and requested to be placed on standing order, we’ll ship it to you to review for 30 days without any obligation. During this period, you can either (a) honor the invoice and receive a 5% discount (in addition to any other discounts you may qualify for) off the then-current price of the update, plus shipping and handling or (b) return the book(s), in which case, your invoice will be cancelled upon receipt of the book(s). Call us for a prepaid UPS label for your return. It’s as simple and easy as that. Most importantly, standing orders mean you will never have to worry about the timeliness of the information you’re relying on. And, you may discontinue standing orders at any time by contacting us at 1.800.960.1220 or by sending an email to email@example.com.
Put me on standing order at a 5% discount off list price of all future updates, in addition to any other discounts I may quality for. (Returnable within 30 days.)
Notify me when updates are available (No standing order will be created).
This Bloomberg BNA report is available on standing order, which ensures you will all receive the latest edition. This report is updated annually and we will send you the latest edition once it has been published. By signing up for standing order you will never have to worry about the timeliness of the information you need. And, you may discontinue standing orders at any time by contacting us at 1.800.372.1033, option 5, or by sending us an email to firstname.lastname@example.org.
Put me on standing order
Notify me when new releases are available (no standing order will be created)