Staples Stores Possibly Hit by Credit-Card Thieves

Credit: Staples, Inc.

(Image credit: Staples, Inc.)

Several Staples office supply stores in the Northeastern United States may have been hit with a payment-card data breach. Staples confirmed that it was investigating a potential issue.

Independent security reporter Brian Krebs first broke the story of the possible breach, reporting that sources at multiple U.S. banks had told him about a pattern of recent credit- and debit-card fraud that seems to trace back to specific Staples store locations.

MORE:10 Worst Data Breaches of All Time

The allegedly affected Staples stores are located in Pennsylvania, New Jersey and New York City. It's not clear which specific locations were affected, nor for how long the breaches lasted.

Krebs' sources told him they were investigating fraudulent debit- and credit-card charges that seemed to trace back to 11 separate Staples store locations. The fraudulent charges also occurred at other businesses located in the Northeast, such as supermarkets and other large retail locations.

"This suggests that the cash registers in at least some Staples locations may have fallen victim to card-stealing malware that lets thieves create counterfeit copies of cards that customers swipe at compromised payment terminals," Krebs wrote in a post on his blog.

Alternately, it's possible the retail locations may have been targeted by a "carder" gang, who would buy card numbers from corrupt cashiers. Such relatively low-tech card theft is common in the New York area.

A Staples representative told Krebs that the company is investigating a "potential issue involving credit card data." Staples has also notified law enforcement of the possible issue. 

Even if this breach is confirmed, it's still nowhere as serious as the recent breaches at Target or Home Depot. Staples has more than 1,800 store locations in the United States, but only a handful of Northeastern locations appear to be affected.

Still, if you believe you may have been affected, you should check your bank accounts for any fraudulent or suspicious transactions, and contact your bank. You can also contact each of the three major U.S. credit-monitoring agencies — Experian, TransUnion or Equifax — and request a free credit alert on your card. These alerts expire every 90 days, but you can renew them indefinitely.

You may also consider requesting a credit report. Each of the three agencies are required to give all U.S. residents one free credit report per year.

Jill Scharr is a staff writer for Tom's Guide, where she regularly covers security, 3D printing and video games. You can follow Jill on Twitter @JillScharr and on Google+. Follow us @tomsguide, onFacebook and on Google+.

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
Titus Welliver in Bosch Legacy season 3
‘Bosch’ season 3 preview: 5 things to know before the final season on Prime Video
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
  • turkey3_scratch
    Staples has always been at the bottom of my store list with workers there trying to deceive people telling them that it is nearly impossible to set up a pre-built computer, making them spend $200 on computer setup and virus protection. Apparently they are the ones who need to check out their own protection.

    I don't know if they or the Geek Squad are worse.
    Reply
  • Xivilain
    I prefer Staples over Best Buy. Their customer service may not be "as helpful" because they're not told to be nosey to their customers in order to push more sales to get that bonus. Staples is one of the last few big retail stores that carries computer components in the store shelves too... so when you need an emergency PSU because yours just shorted, you can expect to pick one up from them immediately.

    Too bad they had a data breach. This will hurt their sales I'm sure.
    Reply