Menu
Browse

Cyber Incident Victim: Bowker

Date:

May 2018

Location:

United States of America

Summary

A breach affecting an ISBN issuance website involved unauthorized charges occurring over several months. The operator discovered the incident and initiated an investigation, which remained ongoing at the time of reporting. The compromise raised concerns about potential impacts to the integrity of the ISBN registry, with industry stakeholders fearing possible diversion of royalty payments due to registry manipulation. The scope and full details of the intrusion were not yet publicly confirmed as the inquiry continued.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In late October or early November 2018, R.R. Bowker publicly disclosed unauthorized activity affecting its ISBN registration website, www.myidentifiers.com. The company's investigation revealed the breach occurred intermittently over a five-month period, beginning on May 1, 2018, and continuing through October 23, 2018. Bowker detected the incident after identifying unauthorized financial transactions conducted through the platform, though the exact method of compromise remained under investigation at the time of disclosure. The company issued a website notice acknowledging the breach but provided limited operational details, citing the preliminary nature of their inquiry. No specific information about the number of affected accounts or individuals was disclosed publicly during the initial announcement period.

Cyber Incident Image

The incident raised significant concerns among publishers, authors, and industry stakeholders regarding potential compromise of the ISBN registry's integrity. Industry professionals expressed particular apprehension that unauthorized access to ISBN assignment records could enable fraudulent royalty diversion schemes if attackers manipulated publication metadata. Bowker confirmed it was examining whether registry data had been accessed or altered but did not release conclusive findings by the November 5 reporting date. The extended breach timeline suggested persistent vulnerabilities in the platform's security controls, though the company did not disclose whether the intrusion involved external attackers, insider threats, or technical exploits. Financial impacts were initially evidenced through unauthorized charges on user accounts, indicating that payment information processing systems were affected. Bowker maintained its investigation was ongoing and committed to providing further updates as more information became available.

Sources
Sources available to members
1 source