CSIDB logo
Incident

Bowker

Incident posture

Attack window
May 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
Bowker
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A breach affecting an ISBN issuance website involved unauthorized charges occurring over several months. The operator discovered the incident and initiated an investigation, which remained ongoing at the time of reporting. The compromise raised concerns about potential impacts to the integrity of the ISBN registry, with industry stakeholders fearing possible diversion of royalty payments due to registry manipulation. The scope and full details of the intrusion were not yet publicly confirmed as the inquiry continued.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late October or early November 2018, R.R. Bowker publicly disclosed unauthorized activity affecting its ISBN registration website, www.myidentifiers.com. The company's investigation revealed the breach occurred intermittently over a five-month period, beginning on May 1, 2018, and continuing through October 23, 2018. Bowker detected the incident after identifying unauthorized financial transactions conducted through the platform, though the exact method of compromise remained under investigation at the time of disclosure. The company issued a website notice acknowledging the breach but provided limited operational details, citing the preliminary nature of their inquiry. No specific information about the number of affected accounts or individuals was disclosed publicly during the initial announcement period.

The incident raised significant concerns among publishers, authors, and industry stakeholders regarding potential compromise of the ISBN registry's integrity. Industry professionals expressed particular apprehension that unauthorized access to ISBN assignment records could enable fraudulent royalty diversion schemes if attackers manipulated publication metadata. Bowker confirmed it was examining whether registry data had been accessed or altered but did not release conclusive findings by the November 5 reporting date. The extended breach timeline suggested persistent vulnerabilities in the platform's security controls, though the company did not disclose whether the intrusion involved external attackers, insider threats, or technical exploits. Financial impacts were initially evidenced through unauthorized charges on user accounts, indicating that payment information processing systems were affected. Bowker maintained its investigation was ongoing and committed to providing further updates as more information became available.

Sources

Sources available to members: 1 source.

CSIDB