news4geeks.net
16Jan/120

Non-U.S. customers kept in dark as Zappos cleans up after data breach

Online shoe and apparel shop Zappos.com is advising over 24 million customers to change their passwords following a data breach, but its website is currently inaccessible to people outside the U.S.

Zappos employees received an email from CEO Tony Hsieh on Sunday, alerting them about a security breach that involved the online shop's customer database.

"We were recently the victim of a cyber attack by a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky. We are cooperating with law enforcement to undergo an exhaustive investigation," Hsieh said in the email.

Even though he assured everyone that no credit card details had been compromised, Hsieh revealed that the attacker had accessed customer records including names; email, billing and shipping addresses; phone numbers, and the last four digits of their credit card numbers.

The hacker also gained access to password hashes for the accounts registered on the website, prompting the company to reset everyone's access codes. Zappos is currently in the process of emailing its 24 million customers in order to notify them about the security breach and advise them to change their passwords.


The company also took the decision to shut off its phones, because the expected phone traffic generated by customers calling in would almost certainly exceed what its system can handle. Customer support is currently being provided through email and Twitter.

"Please create a new password by visiting Zappos.com and clicking on the 'Create a New Password' link in the upper right corner of the web site and follow the steps from there," the company said in its email to customers.

However, at the moment, non-US residents cannot access most of Zappos' website, leaving them unable to follow these instructions. "We are currently undergoing some system maintenance that has limited our international customers in accessing our website," the company said via Twitter.

Zappos advised its customers to change their login details on any other websites where they used the same password, to prevent hackers trying to access those accounts using the data they obtained during this breach.

It's not clear whether affected customers will be offered identity theft protection services or not. Zappos, which is a subsidiary of Amazon, did not immediately return a request for comment regarding this possibility.

(Source: computerworld.com)

 

 

Court Forbids Linking to Pirate Bay Proxies
The Court of The Hague has handed down another ruling that restricts access to The Pirate Bay website. The Court has forbidden the Dutch Pirate Party from linking ...
READ MORE
HTC Droid Incredible 4G unveiled; 1.2GHz dual-core Snapdragon S4, 4-inch qHD display, NFC and 8MP camera
  Already teased on the Verizon website via a promotional page, HTC has today confirmed the launch of the Droid Incredible 4G at CTIA Wireless, becoming the ...
READ MORE
There's a website that claims to predict your future tweets based on past ones. Unfortunately, it doesn't always produce the most coherent results. What it does consistently do is ...
READ MORE
Britain's Home Office confirmed Sunday that its website was attacked overnight after hackers claimed responsibility for shutting it down. The hackers also claim they attacked the Justice Ministry website and warned ...
READ MORE
Many companies that rely on OLSB (Office Live Small Business) for their email and website hosting are complaining that a required transition to Office 365 or to a third-party hosting ...
READ MORE
Court Forbids Linking to Pirate Bay Proxies
HTC Droid Incredible 4G unveiled; 1.2GHz dual-core Snapdragon
Website predicts your next tweet … kinda
Hackers claim attack on UK Home Office website
Office Live Small Business users fret over Office

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.