In March 2026, a ransomware claim by Coinbasecartel against Staples was discovered, with an estimated attack date of December 9, 2023. This claim mentioned infostealer activity compromising 61 employees, 11,853 users, and 47 third-party employee credentials. It is important to note this is distinct from a 2014 payment card breach and a 2023 cyberattack that affected online ordering.
Specifics regarding affected individuals, data types beyond credentials, and any consumer notifications resulting from the 2026 ransomware claim have not been publicly confirmed. For the 2014 breach, approximately 1.16 million payment cards were affected, but no SSN or medical data was involved. The 2023 cyberattack disrupted online ordering, and Staples stated it would notify customers if legally required, though data theft was not confirmed.
Details surrounding the March 2026 ransomware claim are still emerging, and more information may become available. Notifications to affected individuals, if any, may also be delayed.