Penalty Amount
$17,500,000
Consumers Affected
40,000,000
Home Depot settled for $17.5 million over a 2014 data breach that compromised personal information of over 40 million consumers due to inadequate security at self-checkout kiosks. The settlement requires extensive cybersecurity reforms including an information security program, employee training, and encryption. New Jersey receives $579,623 from the multi-state settlement.
Home Depot must pay $17.5 million and implement cybersecurity measures such as creating an information security program headed by an executive, providing security training for personnel, maintaining encryption protocols, implementing strong password policies, two-factor authentication, and firewall policies.
In-house legal teams should review vendor agreements with third-party payment processors and point-of-sale (POS) system providers to ensure they mandate robust security standards for self-checkout kiosks, including encryption and regular vulnerability assessments. Customer agreements and terms of service should be examined for adequate data protection, breach notification, and audit rights clauses. Employee contracts and training materials must align with mandated cybersecurity training requirements. Changes may include adding specific security controls for POS environments, incorporating settlement-mandated encryption standards, clarifying incident response protocols, and ensuring subcontractor compliance with the required information security program.
Entity
Home Depot
Industry
RetailOfficial Press Release
https://www.njoag.gov/ag-grewal-announces-settlement-with-home-depot-over-data-breach-that-compromised-personal-data-of-millions-nj-to-receive-more-than-579000-share-of-17-5-million-settlement/
The Home Depot AVC
https://www.nj.gov/oag/newsreleases20/The-Home-Depot-AVC.pdf
New Jersey Attorney General Enforcement Page
https://www.njoag.gov/about/divisions-and-offices/division-of-consumer-affairs/
"Home Depot"
"Home Depot will pay $17.5 million"
"inadequate security measures in place when data thieves infiltrated its information systems"
$650K
The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.
On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.
A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.
A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.
Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.
$400.0M
Attorney General Jennifer Davenport joined a coalition of 43 states and territories in announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations of widespread price-fixing and anticompetitive conduct in the generic drug market. Sandoz will pay approximately $469 million total including prior settlements, and has agreed to internal reforms to ensure fair competition.