NEWS

Wards to Notify Customers Their Information Was Stolen

Written by Ed Dickson
Published June 29, 2008
The Associated Press announced on Friday that old-time retailer Montgomery Ward is the latest victim of a data breach, where at least 51,000 records were compromised. The unfortunate problem now is they failed to notify the victims, which is the law in 44 States.

Since Montgomery Ward declared bankruptcy in 2001, this announcement might sound confusing, but the company was resurrected in 2004 under the name Direct Marketing Services Incorporated. Direct Market Services sells merchandise online under the names Wards.com, SearsHomeCenter.com, SearsShowplace.com, SearsRoomforKids.com, and two more.

 
Allegedly, hackers gained access by going through another Direct Marketing Services site, HomeVisions.com.

When the site discovered the hack in December, they did notify their payment processors, Visa and Mastercard, but failed to notify any individual customers. Of course, they now plan to do so after being asked about it by the Associated Press.

The hat tip in this instance goes to CardCops, a group of cyber sleuths who track stolen payment card data in underground carder forums for financial institutions. CardCops spotted a group of 200,000 card numbers for sale (including CVC data) on one of the forums (chatrooms) they were monitoring. After tracing some of these cards to their owners, they discovered that they had one thing in common—Wards.

 
At this point, it is unclear whether the official estimate of 51,000 missing records is correct, or the hackers misrepresented the number of cards available in their underground forum.

When asked for some commentary, Visa declined to comment, MasterCard stated they warned the issuing banks to watch for suspicious activity, and Discover stated they issued new cards.

Wards is not alone in not notifying their customers or the public promptly when a data breach occurs. This was recently lamented in a post suggesting we are a long way from full disclosure in data breaches.

Even without all the known data breaches, there are many that are never discovered. Besides that, information is stolen all the time on a smaller scale by dishonest employees, phishing and—despite all the shredders—from the trash.

The sad truth is from the criminal perspective, stolen information that hasn't been detected is worth more than information that is known to be "hot."

If you would like to see more information on the known data breaches, the DLDOS database at Attrition.org is a good resource. PogoWasRight is also another place that covers the privacy concerns arising from this problem, which faces us all.

Having worked around financial crimes for a number of years, I noticed they seemed to be on the rise. One reason for this is technology, which grows more rapidly than laws designed to protect us from it. Although the blog is a resource to educate people on identity theft, it also strives to educate the common person on the rapidly growing problem of crimes enabled (made too easy) by technology and the Internet.
Keep reading for information and comments on this article, and add some feedback of your own!
Wards to Notify Customers Their Information Was Stolen
Published: June 29, 2008
Type: News
Section: Sci/Tech
Filed Under: Sci/Tech: Computers, Sci/Tech: Internet
Writer: Ed Dickson
Ed Dickson's BC Writer page
Ed Dickson's personal site
Spread the Word
Like this article?
Email this
Submit to del.icio.us Save to del.icio.us
RSS Feeds
All RSS Feeds (240+)
Comments on this article
BC articles by Ed Dickson
Sci/Tech: Computers
Sci/Tech: Internet
All Sci/Tech Articles
All News articles
All BC articles
All BC Comments

Comments

Want comments emailed to you? No spam, promise! Address:

Add your comment, speak your mind

(Or ping: http://blogcritics.org/mt/tb/78546)

Personal attacks are not allowed. Please read our comment policy.





Remember Name/URL?

Please preview your comment!

Fresh
Articles
Fresh
Comments