A devastating cyberattack has hit Indigo Books & Music, Canada's largest bookstore chain. As a result of the attack, the company took its website offline and made all purchases cash only.

Although the details of what happened have not been revealed, Indigo has not ruled out the possibility that hackers may have penetrated its systems and accessed customer data
Cash payments
On Wednesday, Indigo said technical problems were preventing access to its website and that payments in physical stores could only be made in cash.
See also: Reddit: Hackers stole source code and internal data
Additionally, the company stated that purchases with gift cards were not available and that there was a possibility of delays with online orders.
After a few hours, Indigo said that its digital systems had been attacked and that it had launched an investigation with the help of experts outside the company.
The bookstore chain has not yet provided details about the type of breach, but it is working diligently to identify whether unauthorized individuals were able to gain access and/or steal customer.
According to Indigo, the company is taking steps to immediately restore its systems. It could be any type of attack, including a ransomware. This type of breach is usually combined with a data breach, as hackers often steal data (before encrypting systems) and threaten to publish it if the victim doesn't pay them.

Cybercriminals typically look for “high value” targets. With annual revenues of over CAD $1 billion, Indigo certainly falls into that category.
The range of products the company sells is incredibly wide – from books and magazines to toys, beauty and wellness products, and smart home devices.
See also: Darknet revenue dropped after Hydra shutdown
Indigo has thousands of employees and many stores.
Indigo Books & Music cyberattack: Info-stealing malware
While Indigo has yet to share details of its investigation, BleepingComputer claims that hackers may have exploited data collected by info-stealing malware to infiltrate the company's network. BleepingComputer learned from threat intelligence firm Kela that at least one cybercrime marketplace was selling Indigo credentials stolen by info-stealing malware, including Redline, Vidar, and Raccoon, in February and January .
See also: Dota 2: Malicious game mods infected gamers with malware
Large companies are always in the crosshairs of hackers, so cybersecurity should always be taken seriously. By understanding the different types of cyberattacks and taking preventative measures, such as using strong passwords and keeping all software up to date, you can reduce the chances of falling victim to these malicious threats. Remember, prevention is always better than cure!
Source: www.bleepingcomputer.com
