Breach Reference
Scan your email →
Data breach reference · February 2023

Were you affected by the Indigo Books breach?

Disclosed
Feb 8, 2023
Records affected
60,000
Type
Ransomware
Sector
General SMB

Check if your email appears in this breach.

One-click check against public breach records. No account required.

Takes 60 seconds. We never store your email address.

What happened

Indigo disclosed a ransomware attack in February 2023 that brought down its e-commerce platform for weeks and disrupted in-store payment card processing at more than 200 locations. The threat actor later published stolen data on the dark web after Indigo refused to pay the ransom.<br><br>Personal information belonging to current and former employees was among the leaked data, including names, dates of birth, Social Insurance Numbers, and direct-deposit banking details. Indigo provided affected employees with credit-monitoring and identity-theft protection services.

Indigo disclosed a ransomware attack in February 2023 that brought down its e-commerce platform for weeks and disrupted in-store payment card processing at more than 200 locations. The threat actor later published stolen data on the dark web after Indigo refused to pay the ransom.

Personal information belonging to current and former employees was among the leaked data, including names, dates of birth, Social Insurance Numbers, and direct-deposit banking details. Indigo provided affected employees with credit-monitoring and identity-theft protection services.

Reported impact: Estimated $60M CAD revenue impact

Source: Office of the Privacy Commissioner of Canada

What to do if you were affected

Common questions about the Indigo Books breach

When did the Indigo Books breach happen?
The breach was disclosed in February 2023. Public reporting was carried by Office of the Privacy Commissioner of Canada. The incident is categorized as: Ransomware.
How many people were affected?
Approximately 60000 records were reported affected. Whether your specific data was among them depends on your relationship with Indigo Books during the exposure window.
How do I check if my email was in this breach?
Enter your email in the scan form above. LeakTrace runs a check against known breach records and returns the result in under a minute. No account required.
What should I do if my data was exposed?
• If you are a current or former Indigo employee, monitor your credit file closely.
• Place a fraud alert with Equifax and TransUnion.
• Change your Indigo account password if you have one.
• Watch bank statements for unauthorized transactions.
• Enable two-factor authentication on any account tied to your Indigo email.
Is my data still at risk years later?
Yes. Breach data from years past continues to circulate on active infostealer channels and credential-stuffing marketplaces. The passage of time does not neutralize the exposure. Ongoing monitoring catches new exposures as they land instead of only the ones already disclosed publicly.

Other general smb sector breaches