
Staples, a prominent office supply retailer, faced disruptions in its systems following a cybersecurity risk, leading to operational constraints and protective actions to safeguard customer data.
The incident, detected on November 27, compelled Staples to take proactive measures, causing a temporary disruption in backend processes, delivery capabilities, communication channels, and customer service lines, confirmed a company spokesperson to BleepingComputer.
While Staples stores remain open and operational, online orders via staples.com may experience delays due to ongoing system issues. Staples assures customers of efforts to restore normal functionality shortly.
The company emphasized that the cyberattack did not involve ransomware deployment, and no file encryption occurred. Swift action, including network and VPN shutdowns, potentially averted further escalation, preventing the typical final stages of a ransomware attack.
However, concerns persist regarding potential data theft during the breach. Hackers gaining network access might attempt extortion by threatening public data leaks. The situation awaits clarity on whether any data was compromised.
This incident isn’t Staples’ first encounter with system disruptions. In March 2023, Staples-owned distributor Essendant faced similar challenges, while a data breach in September 2020 exposed sensitive customer and order information due to an exploited VPN endpoint vulnerability.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543