eWeek Security Watch
Advertisement
Advertisement
January 7, 2008 5:54 PM

'Hacker Safe' Site Hacked, Data Stolen



hacker-safe website hacked, data stolen Geeks.com, a Web site that displays ScanAlert's Hacker Safe logo, has been hacked and sensitive customer information may have been stolen.

According to a letter from Genica, the company that runs Geeks.com, the problem was discovered on Dec. 5, 2007 and affected customers' Visa credit card information.

The letter, republished at The Consumerist, reads in part:

[It] is possible that an unauthorized person may be in possession of your name, address, telephone number, email address, credit card number, expiration date, and card verification number. We are still investigating the details of this incident, but it appears that an unauthorized individual may have accessed this information by hacking our eCommerce website.

The company said it reported the breach to local law enforcement authorities, the U.S. Secret Service and other federal authorities, and Visa. Genica said it had also hired a nationally recognized outside security firm to determine how the incident occurred and to determine the extent of the data loss.

Geeks.com is one of thousands of e-commerce sites that display the "Hacker Safe" logo from McAfee-owned ScanAlert to show that it is tested and proven resistant to hacker attacks.

ScanAlert tests and certifies Web sites on a daily basis to "help address concerns about hacker access to confidential data."

However, as this breach shows, there's no such thing as a hacker-safe Web site.

UPDATE: January 8, 2007: In the comments, a ScanAlert representative says:

So far, no one knows exactly what happened, when it happened, or whether this breach occurred on the Geeks.com web site or somewhere else. There is no evidence that this web site was hacked while it was certified HACKER SAFE. In fact, all of the information that ScanAlert has gathered so far indicates that this breach did not happen while Geeks.com was certified HACKER SAFE.
TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12382

Comments (5)

finally :

haha.. finally... just cause someone runs nessus scans against ya doesnt mean your secure.. hopefully they get their pants sued off

ScanAlert's Response to Geeks.com Hacked Article

So far, no one knows exactly what happened, when it happened, or whether this breach occurred on the Geeks.com web site or somewhere else. There is no evidence that this web site was hacked while it was certified HACKER SAFE. In fact, all of the information that ScanAlert has gathered so far indicates that this breach did not happen while Geeks.com was certified HACKER SAFE.

- ScanAlert

Brian Yakura :

I wish web sites would destroy (erase) the credit card information after receiving payment, instead of
keeping it. Yes, it would be a little inconvenient, retyping the credit card number, but at least I know, it's gone. And not sitting somewhere in a database, waiting to be hacked, cracked, stolen or copied.

Just my 2 bits...
Brian

tysticker :

The Editor of this posting should have done it's investigation before putting incorrect information out. That is why you don't write for a major newspaper. I am sure with in the week he wished he had been tighter on what he posted. By the way this posting is not totally correct!!! The truth will be told very soon.

The wave :

hmmm does tysticker work for Hacker safe? If Geeks.com was hacked and deemed "hacker safe" then where is the disconnect?

Post a Comment

 
 
RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise