Barnes & Noble cyber incident could expose customer shipping addresses, order history
Full article616 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Email addresses and phone numbers may be exposed as well.
Barnes & Noble told customers it was the victim of a cyberattack that led to “unauthorized and unlawful access” of its corporate systems.
Barnes & Noble didn’t detail the entire nature of the “cybersecurity attack” in its email Wednesday, but confirmed that customers’ shipping addresses, billing addresses, email addresses and phone numbers could have been exposed. Payment card information wasn’t compromised as a part of this incident, but customers’ order history may also be exposed, according to Barnes & Noble.
“We currently have no evidence of the exposure of any of this data, but we cannot at this stage rule out the possibility,” the bookseller said in its alert to customers.
Customers’ access to Nook e-readers has also been interrupted, Barnes & Noble said on Twitter.
It was unclear how many customers the incident impacted. Barnes & Noble did not disclose how it discovered the incident, only noting that it was “made aware” of it on Oct. 10.
“We closed down all our networks immediately once a cybersecurity attack was suspected,” a Barnes & Noble spokesperson said in a statement. “We engaged then a firm of cybersecurity consultants to evaluate the nature of the threat. With their guidance, we have cautiously restored our networks which by its nature has taken time.”
It’s a reminder that even as Amazon’s online bookselling has gobbled up a large chunk of the bookselling business in recent years, traditionally brick-and-mortar bookstores — and broadly, brick-and-mortar retail stores — still collect and retain sensitive personal information and have a responsibility to secure it.
Theft of personal data, including email addresses, is the most common type of corporate cybersecurity incident that occurred over the last year, according to Verizon’s annual Data Breach Investigation Report. And while payment data is a ripe target in the retail sector, personal information continues to be the most frequently compromised in the sector, according to Verizon.
More Scoops
Neiman Marcus alerts 4.6 million customers about May 2020 data breach
Hackers accessed user names and passwords, as well as security questions and answers associated with consumer accounts.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/barnes-noble-cyber-incident-customer-data/