My window to the world

Another server, another 9,000 credit card numbers in the wild

By Mauricio Freitas, in , posted: 16-Feb-2011 09:19

From story on Stuff, Lush has its server compromised...


As many as 9000 New Zealanders may have had their credit card and personal details stolen after the Lush cosmetics website was hacked.

The company has urged its online customers in New Zealand and Australia to contact their banks to discuss cancelling their credit cards.


The article makes it sound like they stored credit card details in the same DB or same server.  Not clear if that's the case, but that would be a big lack of security.


As well as credit card details, the database contained customers' names, addresses, phone numbers and dates of birth.


Sure, everything a scammer needs, in a single place.


Lush was contacting customers by email to inform them of the hacking and was not aware of any whose cards had been used fraudulently.

Of course they are not aware. Unless they monitor the underworld, credit card transactions on the other side of the world, and other things. They would only know if a customer complained, and customers wouldn't know how they information leaked, until now.


Its British website was hacked last month and some customers there reported their cards had been fraudulently used.
Mr Lincoln said he did not know whether the hackers were specifically targeting Lush or the type of software it was using."

It happened before to another server on the same company, but nothing was changed in that month?

It sounds like the Hell Pizza episode, when their site was accessed here in New Zealand, but the Australian one, based on the same application, was still running... Back then it took the company months before admitting to the breach. Lucky it was just email addresses, not credit card. But people receiving the spam weren't happy.



Other related posts:
Microsoft Ignite New Zealand, Microsoft Surface Studio
Geekzone data analytics with Power BI
Now with more fibre






comments powered by Disqus

freitasm's profile

Mauricio Freitas
Wellington
New Zealand


I live in New Zealand and my interests include mobile devices, good books, movies and food of course! 

I'm the Geekzone admin. On Geekzone we publish news, reviews and articles on technology topics. The site also has some busy forums. Also worth visiting is TravelTalk NZ, a community for travelers!

Subscribe now to my blog RSS feed or the Geekzone RSS feed.

If you want to contact me, please use this page or email me freitasm@geekzone.co.nz. Note this email is not for technical support. I don't give technical support. You can use our Geekzone Forums for community discussions on technical issues.

Here's is my full disclosure post.

A couple of blog posts you should read:


Social networks presence

View Mauricio Freitas's profile on LinkedIn


My Blog by tags...

Blog...
Entrepreneurship...
Media...
Personal...
State of Browsers...
Technology...
Viral Marketing...
Web Performance Optimization...
Windows...
Windows Phone...

Other recent posts in my blog

Google crawling Geekzone HTTPS...
Geekzone gone full HTTPS...
Microsoft Ignite New Zealand, ...
If the headlines indicate the ...
Geekzone data analytics with P...
State of browsers Geekzone Mar...
2Cheap Cars discussion...
Now with more fibre...
Unlimited is not unlimited: Vo...
How bad is Vodafone cable at t...

New posts on Geekzone