Actually, what's more likely is that some naughty feller's been spoofing mail. It's ridiculously easy to make mail look like it came from Staples or anyone else. Look at the full headers of the message, and find out where it REALLY came from. If it came from staples.com, it wasn't forged.
Still, the spoofer would have had to get information about your order..... Hmmmm...... Might be a hacker, but it could also have been your little brother.