Transformers Ultimate Fansite
Submit News Contact Us Translate Sign in Join

TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

There is more to Transformers than movies, cartoons, comics and toys. Discuss anything else Transformers here.

Moderators: robofreak, Supreme Convoy, Cyber Bishop

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby Banjo-Tron » Sun Mar 11, 2012 4:52 am

Motto: "My banjo is everything; defeat is ukelele"
1) Billing or Collection Issues - The company has unethical collection practices

It depends what is meant by 'collection' in this context, but you could argue that not making best effort to encrypt customer data falls under ethics

2)
Service Issues - An improper or inferior service


'Improper' because their service broke, 'inferior' because it is such an antiquated UI and Backend

3)
Service Issues - An unauthorized service


Not sure if this could be interpreted to include unauthorised transactions

Of these 3, I would go for number 2, as it seems to fit the best.
User avatar
Banjo-Tron
Headmaster
Posts: 1,056
News Credits: 1
Joined: Wed Oct 19, 2011 7:51 am
Location: UK, Surrey
Watch Banjo-Tron on YouTube
Buy from Banjo-Tron on eBay

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby El Duque » Tue Mar 27, 2012 7:16 pm

Motto: "I ain't got time to bleed!"
Weapon: Gattling Gun
Fun Publications/TFCC have issued the following update regarding their recent security issues.

Image


Here is the latest update on the credit card security investigation.

The firm we have hired to analyze our former ecommerce server and software has preliminarily determined that we did incur a SQL injection code attack sometime before Christmas. Our ISP did have a commercial product installed that was supposed to defeat these types of attacks, but apparently it failed.

This allowed the hackers access to our order information. While it is still unknown exactly what data they were able to harvest (investigation continues) we need to assume that they were able to extract all of our order information. The security firm thinks that this attack has allowed the hackers to come back periodically and harvest more information. However, once the old server was taken out of service (around February 21st) there was nothing left for them to access.

Once this information was stolen, (no matter if it was back before Christmas) there is no time frame as to when the thieves may sell or try to use the information to purport credit card theft.

What does this mean to me?

We are asking again that anyone who has used a credit card in our old online systems in the past year (NOT THE NEW STORE) to get your card replaced immediately. If you have done this already, there is no action required on your part.

We apologize for the inconvenience, we know this whole thing is a pain, but it is better to replace the cards than have to deal with any issues that may result from this theft of data. Even though the amount of fraud has greatly declined, we are still receiving a customer report every few days of someone else (who hasn’t replaced their cards) getting hit. We strongly encourage you to take this step immediately if you have not done so already. Again, this DOES NOT pertain to any cards that have been used in the new store.

What is the plan?

We are still working on all of the issues and are several weeks away from a final resolution. Our new store is currently offline while we complete the entries and audit the data from the renewals we received last week. Just to reiterate, this new store is a totally different piece of software, at a totally different hosting site. There are hundreds of other retailers using this same software as it is hosted by the software creators.

We hope to have the store online and registration system back online sometime next week. When the store comes back online, we will be adding products slowly so it will take some time to have everything back in the store.

Thank you for your patience and support during this trying issue.

Brian
User avatar
El Duque
News Admin
Posts: 8,279
News Credits: 67
Joined: Sun Apr 01, 2007 9:57 pm
Location: tornado alley

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby ubertenorman » Tue Mar 27, 2012 7:44 pm

Weapon: Double Beam Guns
This is the kind of correspondance that should have happened a month ago.
Image
User avatar
ubertenorman
Fuzor
Posts: 224
News Credits: 2
Joined: Sat Sep 11, 2010 6:23 pm
Buy from ubertenorman on eBay
Strength: 6
Intelligence: 8
Speed: 4
Endurance: 7
Rank: 8
Courage: 9
Firepower: 3
Skill: 9

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby triKlops » Tue Mar 27, 2012 7:54 pm

Motto: "I’m the rising sun, I’m the new tomorrow, I’m the skull on the gun, I’m the song of sorrow; I’m the thirteenth arrow, I’m the wisest owl, I’m a soul-eating predator, I’m on the prowl"
Weapon: Requiem Blaster
agreed
Image
User avatar
triKlops
Pretender
Posts: 771
News Credits: 2
Joined: Tue Jan 19, 2010 2:35 am
Location: Rhode Eye Land

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby Emperor Galvatron » Tue Mar 27, 2012 8:28 pm

Weapon: Fusion Cannon
El Duque wrote:Fun Publications/TFCC have issued the following update regarding their recent security issues.

Image


Here is the latest update on the credit card security investigation.

The firm we have hired to analyze our former ecommerce server and software has preliminarily determined that we did incur a SQL injection code attack sometime before Christmas. Our ISP did have a commercial product installed that was supposed to defeat these types of attacks, but apparently it failed.

This allowed the hackers access to our order information. While it is still unknown exactly what data they were able to harvest (investigation continues) we need to assume that they were able to extract all of our order information. The security firm thinks that this attack has allowed the hackers to come back periodically and harvest more information. However, once the old server was taken out of service (around February 21st) there was nothing left for them to access.

Once this information was stolen, (no matter if it was back before Christmas) there is no time frame as to when the thieves may sell or try to use the information to purport credit card theft.

What does this mean to me?

We are asking again that anyone who has used a credit card in our old online systems in the past year (NOT THE NEW STORE) to get your card replaced immediately. If you have done this already, there is no action required on your part.

We apologize for the inconvenience, we know this whole thing is a pain, but it is better to replace the cards than have to deal with any issues that may result from this theft of data. Even though the amount of fraud has greatly declined, we are still receiving a customer report every few days of someone else (who hasn’t replaced their cards) getting hit. We strongly encourage you to take this step immediately if you have not done so already. Again, this DOES NOT pertain to any cards that have been used in the new store.

What is the plan?

We are still working on all of the issues and are several weeks away from a final resolution. Our new store is currently offline while we complete the entries and audit the data from the renewals we received last week. Just to reiterate, this new store is a totally different piece of software, at a totally different hosting site. There are hundreds of other retailers using this same software as it is hosted by the software creators.

We hope to have the store online and registration system back online sometime next week. When the store comes back online, we will be adding products slowly so it will take some time to have everything back in the store.

Thank you for your patience and support during this trying issue.

Brian


So if they have all of our order information, they also have our names, ages, addresses, etc that was stored on their site.

Well, that's just peachy.

Hey, cancel your credit cards, never mind the identity theft potential. Disregard the man behind the curtain. :HEADHURTS:
Image
Emperor Galvatron
Gestalt
Posts: 2,267
News Credits: 3
Joined: Sun Aug 24, 2003 7:06 pm
Buy from Emperor Galvatron on eBay
Strength: 8
Intelligence: 8
Speed: 2
Endurance: 6
Rank: 8
Courage: 9
Firepower: 6
Skill: 8

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby autobot_goldbug » Tue Mar 27, 2012 8:32 pm

There was also this bizarre occurrence...
http://www.tfw2005.com/boards/transform ... ost7449720
User avatar
autobot_goldbug
Mini-Con
Posts: 42
Joined: Sun Apr 04, 2004 4:56 pm

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby Stormrider » Tue Mar 27, 2012 8:49 pm

Weapon: Atom-Smasher Cannon
I am not happy for several reasons. How could their security fail and no one noticed it for several months? I still think they are still down playing the threat. The thieves may have had access to our addresses and DOB. They really should be telling people watch your credit reports like a hawk. Fraudulent charges on your credit card are easy to spot. Identity theft and new credit cards that get opened fraudulently in your name using your stolen DOB is not so easy to spot.
Image
Stormrider
Matrix Keeper
Posts: 7,878
News Credits: 35
Joined: Tue Mar 14, 2006 6:24 am
Location: USA

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby datguy86 » Tue Mar 27, 2012 8:53 pm

Motto: "SHEEAGH!"
You can add me to the growing list of people who've been hit. Card's canceled, all items are not my fault - but all signs point to FunPub.
Image

Actively Searching: Universe 2.0 Ratchet, Universe 2.0 Inferno, Hasbro Masterpiece Starscream
datguy86
Fuzor
Posts: 271
Joined: Tue Jun 14, 2011 1:18 pm
Location: Pennsyltucky
Strength: 5
Intelligence: 7
Speed: 4
Endurance: 5
Rank: 3
Courage: 8
Firepower: 5
Skill: 6

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby Rated X » Tue Mar 27, 2012 8:58 pm

Motto: ""Assumption is the mother of all screw ups.""
Weapon: Saw-Edged Pincer
Emperor Galvatron wrote:
El Duque wrote:Fun Publications/TFCC have issued the following update regarding their recent security issues.

Image


Here is the latest update on the credit card security investigation.

The firm we have hired to analyze our former ecommerce server and software has preliminarily determined that we did incur a SQL injection code attack sometime before Christmas. Our ISP did have a commercial product installed that was supposed to defeat these types of attacks, but apparently it failed.

This allowed the hackers access to our order information. While it is still unknown exactly what data they were able to harvest (investigation continues) we need to assume that they were able to extract all of our order information. The security firm thinks that this attack has allowed the hackers to come back periodically and harvest more information. However, once the old server was taken out of service (around February 21st) there was nothing left for them to access.

Once this information was stolen, (no matter if it was back before Christmas) there is no time frame as to when the thieves may sell or try to use the information to purport credit card theft.

What does this mean to me?

We are asking again that anyone who has used a credit card in our old online systems in the past year (NOT THE NEW STORE) to get your card replaced immediately. If you have done this already, there is no action required on your part.

We apologize for the inconvenience, we know this whole thing is a pain, but it is better to replace the cards than have to deal with any issues that may result from this theft of data. Even though the amount of fraud has greatly declined, we are still receiving a customer report every few days of someone else (who hasn’t replaced their cards) getting hit. We strongly encourage you to take this step immediately if you have not done so already. Again, this DOES NOT pertain to any cards that have been used in the new store.

What is the plan?

We are still working on all of the issues and are several weeks away from a final resolution. Our new store is currently offline while we complete the entries and audit the data from the renewals we received last week. Just to reiterate, this new store is a totally different piece of software, at a totally different hosting site. There are hundreds of other retailers using this same software as it is hosted by the software creators.

We hope to have the store online and registration system back online sometime next week. When the store comes back online, we will be adding products slowly so it will take some time to have everything back in the store.

Thank you for your patience and support during this trying issue.

Brian


So if they have all of our order information, they also have our names, ages, addresses, etc that was stored on their site.

Well, that's just peachy.

Hey, cancel your credit cards, never mind the identity theft potential. Disregard the man behind the curtain. :HEADHURTS:



I would think someone would need your social security number to do any real damage in identity theft. That’s how illegal immigrants get legit jobs.
Image

"It doesn't matter what you think !"

Check out my Customs:

Generations Twincast

generations-twincast-t94088.php

Classics Whirl

http://www.seibertron.com/energonpub/custom-classics-whirl-p1468897.php#p1468897

Collection photos will be updated soon at this link :

http://www.seibertron.com/energonpub/rated-x-s-collection-t55699.php
User avatar
Rated X
City Commander
Posts: 3,743
Joined: Mon Dec 08, 2008 7:25 pm
Location: Miami, Florida
Strength: 5
Intelligence: 8
Speed: 2
Endurance: 10
Rank: 7
Courage: 10+
Firepower: 10+
Skill: 8

Re: TF Community Warning: Check your Credit and Debit Card accounts for recent fraudulent activity

Postby Stormrider » Tue Mar 27, 2012 9:06 pm

Weapon: Atom-Smasher Cannon
You are 100% right. A social security # is needed for most identity theft. But acquiring the SS# is not as difficult as most think. The numbers that make it up represent the year and region that you were born in. The remaining numbers can often be deduced.

It's not too difficult to figure out the place you were born, if I know your DOB and full name.

When my identity was stolen. Initially, the thieves opened several small accounts using my name and DOB. They did not use my SS#. (My theory is that they didn't have it at that time). Three months later, they figured it out and the flood gates were opened.


Ryan, or others that deal with website design - isn't mandatory for companies nowadays to properly store credit card numbers? Have some laws been broken on FunPub's part?
Last edited by Stormrider on Tue Mar 27, 2012 9:09 pm, edited 1 time in total.
Image
Stormrider
Matrix Keeper
Posts: 7,878
News Credits: 35
Joined: Tue Mar 14, 2006 6:24 am
Location: USA

PreviousNext

Return to Transformers General Discussion

robofreak, Supreme Convoy, Cyber Bishop

Users browsing this forum: No registered users and 3 guests

Twincast / Podcast #68
Twincast / Podcast #68:
"ReChrome"
MP3 · iTunes · RSS · View · Discuss · Ask
Posted: Thursday, May 16th, 2013