Ace Hardware confirmed that the cyberattack, which is preventing its local stores and customers from placing orders, has affected 196 servers.
See also: Ace Hardware: Stores fell victim to cyberattack

Ace Hardware is a cooperative hardware retailer with 17 distribution centers and 5,700 stores throughout the United States, China, Panama, and the United Arab Emirates. The cooperative employs 12,500 people and has annual revenues in excess of $9 billion.
Reports of a cybersecurity incident affecting the organization surfaced on Reddit on Monday, where someone posted the contents of Ace's announcement to sellers regarding a cyberattack that occurred last weekend.
Scheduled deliveries are affected and merchants are asked to avoid placing additional orders for now, as these cannot be processed.
The company says it has worked with a team of IT experts to help it restore the affected systems, but because they are dealing with "a rapidly evolving, dynamic situation," details about the process and system status cannot be conveyed accurately.
An update on the situation was given late Monday, vaguely saying that the outage would continue.
The new announcement asked merchants to keep their stores open to serve customers, saying that POS systems and in-store credit card processing would not be affected.
See also: BritishLibrary: Services disrupted due to cyberattack
The ability to view and search for products continues to be available in the online store. However, ordering functionality remains disabled, as the systems that process customer orders have not yet been restored.
According to the latest information posted online by Reddit users claiming to be store owners, all internal company systems remain down, making it impossible to order products from warehouses or shipping points.
Unfortunately, while Ace is restoring devices to restore their functionality, the attackers have focused on further exploiting the attack.

Ace Hardware warns that malicious actors are contacting Ace retailers with friendly emails urging them to redirect payments to an “alternative” payment email address until systems are restored. In other cases, attackers are calling Ace stores posing as agents of Epicor Software Corporation, possibly one of Ace’s contractors, asking them to hand over account credentials to their network, supposedly to fix the problems.
See also: Toronto Public Library (TPL): Various services offline due to cyberattack
One of the first resources that individuals and businesses can use to strengthen their digital security is security and IT organizations. These organizations provide training, advice, and practices to protect against cyberattacks. You can contact local security and IT organizations to learn more about the services they provide.
Another useful tool for strengthening digital security is the use of password replacements. Malicious users often exploit weak passwords to gain access to personal or business data. By choosing strong passwords and changing them regularly, you can reduce the risk of your security being compromised.
Additionally, installing up-to-date software and security programs is crucial to protecting digital systems. Software updates usually contain fixes for known security bugs and vulnerabilities. Also, using security programs, such as antivirus, can provide additional protection against malware and cyberattacks.
Finally, user education and awareness are crucial to strengthening digital security. Users need to be aware of cyberattacks and the techniques used by attackers. Education can include recognizing phishing emails, avoiding clicking on suspicious links, and identifying malware.
Source: bleepingcomputer
