Indigo says ransomware attack breached data of current and former employees | Globalnews.ca

A ransomware attack compromised the data of current and former employees at Canada’s biggest bookstore chain, Indigo Books & Music Inc. says.

In a statement on its website, Indigo said the breach on Feb. 8 left no indication that customers’ personal information, such as credit card numbers, had been accessed, but that “some employee data was.”

The Toronto-based retailer said it has contracted consumer reporting agency TransUnion of Canada to offer two years of credit monitoring and identity theft protection to workers at no cost.

Customers remain unable to make purchases online except for “select books,” after Indigo halted website and app operations in what it referred to last week as a “cyberattack.”

Read more:

Indigo says ‘cybersecurity incident’ has impacted online orders, electronic payments

Read next:

Here’s how interest rates could affect Canada’s housing market in 2023

Story continues below advertisement

When the incident began more than two weeks ago, Indigo was only able to process purchases made in store with cash, but some of its services, including over-the-counter credit and debit payments as well as exchanges and returns, have since been restored.

The company engaged third-party experts to investigate and resolve the matter, but did not publicly acknowledge the incident as a ransomware attack affecting employees until this week.

“Both current and former employees are being notified that their information may have been impacted,” the statement reads.


Click to play video: 'Canadians warned of growing ‘hostile’ cyber threats'


Canadians warned of growing ‘hostile’ cyber threats


 

The federal Office of the Privacy Commissioner confirmed to Global News in a statement Friday that it had received notice of a breach from Indigo and are in communication with the company about next steps.

Story continues below advertisement

A spokesperson for the privacy commissioner said the office has not received any complaints about the matter.

Data breaches have become a familiar feature on the corporate and public-sector landscape, with Canadian retailers experiencing a growing number of cyberattacks in recent months.

Sobeys parent company Empire Co. Ltd. suffered a security breach late last year.

The incident in November left customers unable to fill prescriptions at the chain’s pharmacies for four days, while other in-store functions like self-checkout machines, gift card use and the redemption of loyalty points were off-line for about a week.

Read more:

Telus says it’s investigating claims employee information was posted on ‘dark web’

Read next:

Windfall tax on large Canadian companies needed to recover public funds: report

Empire later said the attack was expected to cost $25 million after insurance recoveries.

The Liquor Control Board of Ontario experienced a “malicious” cybersecurity incident that affected online sales in January, and Toronto’s Hospital for Sick Children saw a ransomware attack disrupt operations in December.

— with files from Global News’s Craig Lord

&copy 2023 The Canadian Press

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TheDailyCheck is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected] The content will be deleted within 24 hours.