Data breach

Status
Not open for further replies.

Phil Herring

Alien
Mar 25, 1997
4,924
- - Bainbridge Island
I want to give you a heads-up on something you'll probably hear about, and we'd rather you hear it from us.

On February 22nd we noticed some unusual activity in our server logs: An ip address from Hanoi was poking around where they shouldn't be. Within a couple hours we had it isolated and stopped, a little less than 24 hours after it started.

Because this was on our ecommerce server we hired a data security firm to do a forensic investigation and sure enough, they found that a pocket of data had been compromised which contained credit card numbers.

It was a relatively small breach, about 1% of the national average, and the first we've experienced in 15 years of online transactions. We reported it to all the card brands as well as the FBI, and sent notification letters to all the customers we could identify as being potentially compromised. (FWIW, most merchants don't do any of that and hope for the best.)

Unfortunately, this kind of activity is so common these days (175,000,000 records compromised in 2011) that there's no way of knowing for certain if any specific card was fraudulently charged as a result of this incident.

The situation begs two questions: "How did this happen?," and "What are you doing about it?"

I can't go into detail about where the vulnerability was, but our former security plan held for 15 years. That was largely due to a security service we hired to regularly "attack" us and report any security holes, which we then closed.

After the breach we made immediate and major changes to avoid similar problems in the future:

1. Online checkout was shut down for three days while we installed a system that uses a method called "tokenization." In short, credit card data is sent directly to a subsidiary of VISA and is stored there. It is no longer stored on our server, nor do we have any way to view it.. So, in the unlikely event we are breached again, there's no sensitive data to find.

2. We installed triple redundant defenses against the attack vector that was used to breach the server.

3. We engaged a nationally-recognized data security firm to analyze our operation, conduct penetration testing, and help us shore up any remaining weaknesses.

It's been a very stressful and emotional few weeks as we worked through all these changes. Bly and I feel nothing short of mortified and are doing everything in our power to make sure nothing like this happens again. We take our responsibility to you very seriously and this is not what we had in mind.

Regardless, we deeply regret any inconvenience you may have been caused and we will work hard to regain your trust.
 

Rick D

.
Jun 14, 2008
7,204
Hunter Legend 40.5 Shoreline Marina Long Beach CA
Don't take it so personally, guys. As one who buys the majority of boat, vehicle and household things on line, stuff happens. I feel far more secure here than many other sites, I assure you. We take our chances every time we give our card to a food server, so the risk isn't just in the electronic marketplace. My security service had contacted me recently about an overseas transaction with the correct card number but bad expiration date. I suspect it was a small dollar probe. It's something we all have to watch out for; lots of bad actors out there!
 

gpd955

.
Feb 22, 2006
1,164
Catalina 310 Cape May, NJ
Phil,

Thanks for being forthcoming about it. You are correct that most companies just write it off as a part of doing business and the consumer never hears from them. Unfortunately data theft and ID theft is so common and one of the best ways to deal with it is to recognize it early and stop it before any real damage is done. The victims were done a great service by having been notified by you.

Keep up the good work!
 
Feb 26, 2008
603
Catalina 30 Marathon, FL
Phil,
Sounds like you guys are taking reasonable steps to keep the gates locked.

Unfortuntely this is part of doing business online.

Thank you for your honesty,
Jim
 
Apr 8, 2010
2,238
Ericson Yachts Olson 34 28400 Portland OR
Phil,
Sounds like you guys are taking reasonable steps to keep the gates locked.

Unfortuntely this is part of doing business online.

Thank you for your honesty,
Jim
I agree with Jim.
"Plus One", as they say....
!
Loren
 

RAD

.
Jun 3, 2004
2,330
Catalina 30 Bay Shore, N.Y.
I was going to email you cause my card was one of the ones used.....I just got a new card with Chase and used it on the SBO site and my credit card was used elsewhere and the credit card company picked up on it and called me or they followed your lead either way they canceled the card and sent me another with new account info
 
Feb 20, 2011
8,062
Island Packet 35 Tucson, AZ/San Carlos, MX
I was going to email you cause my card was one of the ones used.....I just got a new card with Chase and used it on the SBO site and my credit card was used elsewhere and the credit card company picked up on it and called me or they followed your lead either way they canceled the card and sent me another with new account info
Chase has caught two attempts on my card this past year. For such a despicable bank, they've got my respect for quickly contacting us, stopping the fraudulent purchase, and issuing new cards that show up the next day. I know, I should upgrade my online security, too. This Win98SE is most likely a breach waiting to happen.
Thanks for the heads up, Phil.
 

Ross

.
Jun 15, 2004
14,693
Islander/Wayfairer 30 sail number 25 Perryville,Md.
There are several levels of control for credit card use and we have benefited from many of them. We keep our receipts and we record our transactions so that when a bank calls we can immediately know if a transaction is valid or fraudulent. We had someone local use our card for 35 dollar order from a pizza shop that we didn't even know existed. That one we caught on the statement and resolved it.
 
Feb 26, 2004
23,357
Catalina 34 224 Maple Bay, BC, Canada
Thanks for the report, Phil.

WOW, honest salesmen.

Who woulda thought...:):):)
 
Last edited:
Oct 6, 2008
857
Hunter, Island Packet, Catalina, San Juan 26,38,22,23 Kettle Falls, Washington
Phil, You are a class act. Thanks for the info.
Ray
 

LuzSD

.
Feb 21, 2009
1,009
Catalina 30 San Diego/ Dana Point, Ca.
Thanks for such an honest accounting and your willingness to be so forthcoming... but I am not surprised and as always, I am impressed. You guys do a fantastic job. Thank you.
 
Sep 6, 2011
435
Phil don't let it get you down. Honestly once in 15 years are actually great statistics. Many places are much much higher and just don't admit it. I'm not at risk of fraud but wanted to commend you guys for being honest with your customer base. SC
 

geehaw

.
May 15, 2010
231
O-day 25 shoal keel Valdez
Fruad Charges.

Well right after using the store here my card was used elsewhere. Now I know why. It was right about that time, I would have to look to be sure. I was beginning to think it was my puter. I was hit on my Bank card earlier in the month. I check my all my cards usage daily now!! Greg.
 
Dec 19, 2006
5,832
Hunter 36 Punta Gorda
Great Job

You guys are great and don't feel bad,there is not a day that goes by that we don't here about some one has had their credit card missed used by some way or some one.
Nick
 

Scott

.
Sep 24, 1997
242
Hunter 31_83-87 Middle River, Md
Thanks Phil. I was wondering where the March 6, $385.77 from walmart.com, which I have never used originated. I reported it to the bank and filled out a federal form, and they just granted a provisional refund Friday, while the investigation is on-going. Hope they make the refund permanant. I rarely buy on-line.

Thanks again, my wondering is over.
 
Jul 28, 2010
914
Boston Whaler Montauk New Orleans
Thanks for the info, Phil. Great work.
Just a tip for everyone who uses credit cards at all, online or otherwise - check your monthly statements!!! If something doesn't look right, look into it. Easiest thing to do, and it can easily save you a ton of headaches. Again, check your monthly statements!!!
 
Dec 12, 2011
20
Cape Dory 25 Cambridge, MD
My card was compromised on Feb 28. I can not tell from where it was compromised from. 1500 dollars at Recellular, Hatmonster, and DRJFansedge. Overnight shipping to an address in Florida using fake email and phone number. Merchants caught it before the bank because they look twice at overnight shipping orders. Bank credited some, merchant issued credit and several did not send the order.
 

Scott

.
Sep 24, 1997
242
Hunter 31_83-87 Middle River, Md
Just visited my friendly banker to inquire about the "provisional credit" to my account and what it precislely means. Was told that these e-investgations have to be resolved one way or another within 60 days. I have access to the use of my money, but it could be rescinded immediately if they believe I made the purchase. This just recently "wisened" old man will now use a credit card instead of a debit card for on-line purchases. In the event of a fraudulent puchase, personal funds are not tied up during the investigation. Friendly banker suggested that the most secure purchases can be made with prepaid "gift card" for the amount, which the bank issues at no charge. Seems like a good idea..
 
Status
Not open for further replies.