Another Major Retailer Breached

The $21 billion office supply chain Staples appears to be the latest retail chain hit by cyberthieves.

On Monday (Oct. 20), Staples issued a statement whose phrasing that has become all too familiar in retail circles these days. “Staples is in the process of investigating a potential issue involving credit card data and has contacted law enforcement,” the chain said in an E-mailed statement, reported The Wall Street Journal.

Krebs On Security had reported on the incident Monday (Oct. 20). “Multiple banks say they have identified a pattern of credit and debit card fraud suggesting that several Staples office supply locations in the Northeastern United States are currently dealing with a data breach. It appears likely that fraudsters have succeeded in stealing customer card data from some subset of Staples locations, including seven Staples stores in Pennsylvania, at least three in New York City, and another in New Jersey.” the Krebs story said. “The fraudulent charges occurred at other (non-Staples) businesses, such as supermarkets and other big-box retailers. This suggests that the cash registers in at least some Staples locations may have fallen victim to card-stealing malware that lets thieves create counterfeit copies of cards that customers swipe at compromised payment terminals.”