Staples took systems offline after a Cyber Monday intrusion
- Organization
- Staples
- Exploit
- Hacking
- Industry
- Office Supply Retail
Staples took down some of its systems in late November 2023 after detecting an intrusion, disrupting the office supply retailer during one of the busiest shopping weeks of the year. The problems began on Monday, November 27, which was Cyber Monday, and the company confirmed the cause days later.
Staples said its cybersecurity team identified a cybersecurity risk and that it took proactive steps to mitigate the impact and protect customer data. The company said those prompt efforts caused temporary disruption to its backend processing and delivering capabilities, its communications channels and its customer service lines. Employees posting on Reddit, reported by BleepingComputer, described losing access to email, Zendesk, VPN employee portals and phone lines. Physical stores continued trading normally.
The company said no data was encrypted during the incident and credited its quick action with averting more serious consequences. A spokesperson said it was too early to draw definitive conclusions about any impact on data, and that Staples would notify customers if their information proved to be affected, consistent with its legal and contractual obligations.
Most systems were restored by the Wednesday and the remainder by Thursday, with the fulfillment supply chain returning to normal operation. Staples told Cybersecurity Dive it expected to have caught up on all outstanding November orders by the end of that week. No group claimed responsibility and the company did not disclose how the attackers gained access.