Barnes & Nobles customers are being notified of a cyber attack that could be playing havoc on their information technology systems company wide.
After going through five CEOs in seven years, they were sold to Elliott, a giant Hedge Fund that owns the largest book store in the U.K., Waterstones.
Complaints have been fielded indicating troubles with Nook e-reader book access for days. Monday Barnes & Noble said that a “system failure” was interrupting access to content for some users. The bookstore chain said Wednesday that access to the system should be restored “shortly.”
But today their customers are being sent the following email message:
Dear Barnes & Noble Customer,
It is with the greatest regret we inform you that we were made aware on October 10, 2020 that Barnes & Noble had been the victim of a cybersecurity attack, which resulted in unauthorized and unlawful access to certain Barnes & Noble corporate systems.
We write now out of the greatest caution to let you know how this may have exposed some of the information we hold of your personal details.
Firstly, to reassure you, there has been no compromise of payment card or other such financial data. These are encrypted and tokenized and not accessible. The systems impacted, however, did contain your email address and, if supplied by you, your billing and shipping address and telephone number. We currently have no evidence of the exposure of any of this data, but we cannot at this stage rule out the possibility. We give below answers to some frequently asked questions.
We take the security of our IT (Information Technology) systems extremely seriously and regret sincerely that this incident has occurred. We know also that it is concerning and inconvenient to receive notices such as this. We greatly appreciate your understanding and thank you for being a Barnes & Noble customer.
Barnes & Noble FAQ
1. Have my payment details been exposed?
No, your payment details have not been exposed. Barnes & Noble uses technology that encrypts all credit cards and at no time is there any unencrypted payment information in any Barnes & Noble system.
2. Could a transaction be made without my authorization?
No, no financial information was accessible. It is always encrypted and tokenized.
3. Was my email compromised?
No. Your email was not compromised as a result of this attack. However, it is possible that your email address was exposed and, as a result, you may receive unsolicited emails.
4. Was any personal information exposed due to the attack?
While we do not know if any personal information was exposed as a result of the attack, we do retain in the impacted systems your billing and shipping addresses, your email address and your telephone number if you have supplied these.
5. Do you retain any other information in the impacted systems?
Yes, we also retain your transaction history, meaning purchase information related to the books and other products that you have bought from us.