Ace Hardware’s October 2023 cyberattack disrupted corporate systems used for ordering, warehouse work and deliveries. Contemporary reports said stores could remain open and that point-of-sale and credit-card processing were unaffected, but those reports described notices circulated during the outage—not a guarantee about every location or later period.
What happened when Ace Hardware was hacked?
Ace said it detected a cybersecurity incident on Sunday morning, October 29, 2023. A notice from CEO John Venhuizen, reproduced in an October 30 post on r/sysadmin, said the incident was affecting most of the company’s IT systems. The notice named ACENET, warehouse-management systems, ARMA, Hot Sheets, invoices, Ace Rewards and the Care Center phone system.
The notice said shipments were disrupted and asked retailers to hold additional orders. It also said scheduled deliveries would not occur on October 30 and that Ace was working with technical forensic experts. Because the notice was reproduced in a retailer discussion rather than published on a currently accessible official incident page, its wording is best understood as a contemporaneous report of what Ace told retailers.
Which operations were disrupted, and what could customers still do?
The disruption affected central business and distribution workflows: retailers faced problems placing or managing orders, and warehouse receiving, picking and shipping depended on servers Ace was working to restore. BleepingComputer and SecurityWeek reported that Ace’s website could still be browsed, but customers could not place online orders. SecurityWeek said online orders remained suspended as of November 3, 2023, with customers directed to physical stores.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Those reports drew a distinction between corporate systems and store-level transactions. SecurityWeek and BleepingComputer said notices circulated during the outage advised that stores could stay open and that point-of-sale and credit-card processing were unaffected. That reported status does not establish that every independent Ace location, connected service or transaction was unaffected.
How much of Ace’s infrastructure was affected?
BleepingComputer reported figures from a November 2 communication by Venhuizen to retailers. According to that report, Ace’s environment included 1,400 servers and networked devices, of which 1,202 were affected. The company was restoring 196 servers to resume receiving, picking and shipping. As of 5:31 a.m. on November 2, 51% of those 196 servers had been restored and were being certified by Ace IT.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
These are dated figures attributed to a retailer communication as reported by BleepingComputer, not a final forensic accounting of the incident. They show the scale of the recovery effort at that point, not the eventual recovery date or the status of systems today. BleepingComputer also quoted Venhuizen describing the disruption as the result of a malicious cyberattack; its report reproduced that statement from the retailer communication.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is known about possible data exposure?
As of November 3, 2023, SecurityWeek reported that Ace had not disclosed the type of cyberattack or whether customer information may have been compromised. The available reporting does not establish that the incident was ransomware, identify a threat actor, or prove that customer data was taken.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
A later Ace notice dated April 1, 2024 described a data-security incident discovered on October 29, 2023. It said an investigation determined that information on Ace’s corporate network may have been accessed between October 27 and October 29, and that local systems at Ace stores were not involved. The notice is a separate disclosure about potential access to corporate-network information; it does not, on its own, explain every operational effect reported during the outage.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
What the reporting does—and does not—establish
- Established: Ace reported detecting a cybersecurity incident on October 29, 2023, and a reproduced retailer notice listed corporate systems affected and shipment disruption.
- Established as a dated snapshot: BleepingComputer reported the device and server-restoration figures from Venhuizen’s November 2 retailer communication.
- Reported during the outage: Contemporary coverage said stores could remain open and store payment processing was unaffected, while online ordering was suspended.
- Not established by these sources: the attack type, a threat actor, whether customer information was taken, the complete recovery date, the operational incident’s financial cost, or current system status.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




