"The malicious software that unknown thieves used to steal credit and debit card numbers in the data breach at Home Depot this year was installed mainly on payment systems in the self-checkout lanes at retail stores, according to sources close to the investigation."
So it's not that Home Depot (i'm not sure this applies to Target) had the credit card info stolen from their servers. It's more that it was skimmed from their self-checkout machines, though by software though rather than hardware.