HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedTargetedFINANCIAL_ACCOUNTCREDENTIALSLowContained
BARNES & NOBLE BOOKSELLERS, INC.
bd_bb25a24a77ddb56e · schema v1 · pii pii-v1
Full breach record for BARNES & NOBLE BOOKSELLERS, INC. →Barnes & Noble Booksellers, Inc. disclosed a breach affecting PIN pad devices in 63 retail stores across 9 states. Criminal actors tampered with PIN pads to capture credit/debit card numbers and PINs. The incident was discovered in September 2012, leading to the removal of all PIN pads and cooperation with federal law enforcement. No online or member database data was compromised. Affected data includes financial account numbers and credentials.
California clockDiscovered Oct 24, 2012 → Notified Oct 24, 20120d ✓ CA 60-day OK≤1 day discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-36794
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 24, 2012
- Raw hash
- d6a79bfb525c63d2e4c3bd8c73eb610533c56dd798bec30610778bd4de82e22c
Reporting entity
- Name
- BARNES & NOBLE BOOKSELLERS, INC.norm: barnes noble booksellers
- Industry
- retail_consumer
Victim entity
- Name
- BARNES & NOBLE BOOKSELLERS, INC.norm: barnes noble booksellers
- Industry
- retail_consumer
Incident
- Discovered
- Oct 24, 2012
- Materiality determined
- —
- Notification sent
- Oct 24, 2012
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement authoritiesSupporting a federal government investigation into the matter
- Initial access
- external_remote_services
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 24, 2012→ Notified: Oct 24, 20120d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.