Barnes & Noble hit by debilitating cyberattack, customer data exposed

Zero-day attack
(Image credit: Shutterstock) (Image credit: Shutterstock.com)

US bookseller Barnes & Noble (B&N) has confirmed that the disruption that affected its services this week was the result of a cyberattack.

Initially, the cause of the outages, which affected eBook downloads, app users and even some visitors to the retailer’s physical stores, was unclear. Now it appears that malware was to blame.

Customers first started noticing that something wasn’t right when owners of B&N's Nook tablets found they were unable to download or purchase new titles. The severity of the issue became clearer when some cash registers stopped working within B&N stores.

While the network outage continued, B&N issued statements assuring customers that their payment details remained safe, as they were encrypted and tokenized. It is now clear that the bookseller made such reassurances because other forms of customer information had not received the same safeguards.

Data breach

A few days after the outages, B&N sent an email to customers confirming that it had been the victim of a cyberattack. The retailer also revealed that personal information, aside from payment details, could have been compromised, including names, addresses, telephone numbers and transaction histories.

“Your payment details have not been exposed,” the email read. “Barnes & Noble uses technology that encrypts all credit cards and at no time is there any unencrypted payment information in any Barnes & Noble system. No financial information was accessible. It is always encrypted and tokenized. It is possible that your email address was exposed and, as a result, you may receive unsolicited emails.”

Other details surrounding the attack have not yet been disclosed but it is thought that ransomware could be to blame. B&N customers who may have had information taken during the raid should be particularly vigilant against phishing attacks.

Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does