The giant company Barnes & Noble disclosed that it suffered a cyberattack that may have exposed customer data.
Barnes & Noble is the largest bookseller in the United States, with more than 600 bookstores in fifty states. The company also operates Nook Digital, which is an eBook and e-Reader platform.
Since October 10, users have complained on Nook's Facebook page and Twitter that they could not log in to the eBooks platform.

During this period, Barnes & Noble posted on the Nook Facebook page, stating that they had suffered damage to the system and are trying to restore its systems.
In a statement given to Fast Company earlier today, Barnes & Noble said that it suffered a serious network problem and that it is in the process of restoring its server backups.
“We are experiencing a serious network and are in the process of restoring our server backups,” Barnes & Noble told Fast Company. Rest assured that there is no breach of customer payment information, which is encrypted.
According to GoodReader, store managers said Barnes & Noble had a “virus on its network” that started in the corporate offices and eventually made its way to the stores. When it reached the stores, it affected cashiers and prevented orders from being processed.
Barnes & Noble reveals
In an email sent to customers late Wednesday night, Barnes & Noble revealed that they suffered a cyberattack on October 10, 2020.
As part of this attack, threat actors gained access to corporate systems used by the company.
In a list of frequently asked questions, Barnes & Noble states that no payment information has been exposed, but they are not sure at this time whether the attackers had access to other personal information.
They admit that emails, billing addresses, shipping addresses and purchase history have been exposed.
Possibly a ransomware attack
Although it has not been confirmed, the cyberattack on Barnes & Noble has all the characteristics of a ransomware attack.
The company said it had to restore server backups, which is an example of a ransomware attack .
Finally, the cybersecurity company Bad Packets told BleepingComputer that Barnes & Noble apparently had many VPN Pulse servers that were vulnerable to the CVE-2019-11510 vulnerability.
This vulnerability is popular as it allows hackers to gain access to user credentials stored on the VPN device.
A recent leak of Pulse VPN credentials gathered using this vulnerability contained accounts belonging to Barnes & Noble.
Unfortunately, if they have been subjected to a ransomware attack, it is likely that much more data than Barnes & Noble is disclosing.
