Scale Model Shop

Collapse

Hannants hacked

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • John
    Administrator
    • Mar 2004
    • 4656
    • John
    • Halifax

    #1

    Hannants hacked

    I just got this and have already rang up and cancelled my card

    Dear CustomerWe are very sorry to have to tell you that a number of customers who have used our website have had their card details stolen and used by criminals.

    ALL CUSTOMERS THAT HAVE ENTERED CARD NUMBERS ON OUR NEW WEBSITE PLEASE CHECK YOUR ACCOUNTS FOR SUSPICIOUS CHARGES OR ATTEMPTED CHARGES.

    If you see any please contact your company that issued your card.

    At the moment no one is sure how this has happened. There are several internet security firms investigating everything and we will keep you all updated as soon as we can.

    There is no sign of any intrusion into the server where the card number and expiry date information that we keep is encrypted*. The CVV number is not stored.

    After looking at the information we have received we think this mainly affects some customers who have sent us an order in the last 2 weeks though there are 3 from September.

    We have been contacted by about 40 customers so far but are not sure how many others have had their cards compromised but have not told us yet. If you know your card has been compromised PLEASE tell us. Please send us as much information as you can as soon as you can. We need as much information as soon as possible.

    Please look out for small 'insignificant' test charges of under $5.00 followed by larger charges of varying amounts. Charges have originated from different countries and in different currencies.

    Until we have found out what has caused this problem and it has been fixed we have closed the website. None of the experts can find any problems with it but until the problem is resolved we prefer not to take any risks.

    We have deleted ALL card numbers from the website database. We are aware that a few of you wanted access so you could delete your details but we have done this for everyone.

    Paypal. We have been asked why we do not accept it. There are 2 reasons. Firstly when we started work on the new website 4 (four) years ago we could not get it to work with the fully stock controlled warehouse that we wanted to run. We did some trials but it took too long for payments arrive in our bank account which would seriously have delayed the despatch of orders. Things have now improved. Secondly it was too expensive. 3 times the cost of handling Visa and Mastercard. All our payments are now handled by Sage pay, a large British firm. Recently they have started working with Paypal and our website designers had been doing some work to incorporate it into the website. We are going to speed up the work on this and try to get it incorporated quicker.

    We will re-open the website as soon as we can but will not be rushing into it.

    Thank you for your help and understanding.

    ALL CUSTOMERS THAT HAVE ENTERED CARD NUMBERS ON OUR NEW WEBSITE PLEASE CHECK YOUR ACCOUNTS FOR SUSPICIOUS CHARGES OR ATTEMPTED CHARGES.

    If you see any please contact your company that issued your card.

    * This data is stored so that customers do not have to enter it each time they order and so that we can run a back order service.
    www.scalemodelshop.co.uk
  • Guest

    #2
    Yep I've got the same mail.

    Thanks for the heads up....

    Comment

    • tr1ckey66
      SMF Supporters
      • Mar 2009
      • 3592

      #3
      That is worrying...

      I haven't received that email yet, although I'm a regular shopper there, don't know whether to cancel my card or not.

      Nothing suspicious in my account yet.

      Comment

      • Guest

        #4
        I have had the email but to be honest, I cannot remember buying anything off their website. It does say the 'New Website' and orders in the the last few weeks and I know that I have not done anything on their new site, I cannot stand the way the Hannants site works anyway, so user unfriendly.

        As far as I know, the only thing I have bought from them directly was at Duxford when I got the Valentine. That was using the old swipe and sign docket, no electronic connection so I assume they would not have electronically stored my card details.

        Something to bear in mind John if you go over to cards.....

        Comment

        • colin m
          Moderator
          • Dec 2008
          • 8781
          • Colin
          • Stafford, UK

          #5
          I last used them on the 29th August, and my card does have a 'pending charge' of £1.00 from some strange organisation on it ?? My CC people weren't to concerned by this, but I cancelled it anyway.

          Colin M..........

          Comment

          • Ian M
            Administrator
            • Dec 2008
            • 18272
            • Ian
            • Falster, Denmark

            #6
            And this is why I did not register a credit card with them.

            I will probably get blown out of the water for this but I'm going to say it anyways!!!

            1) I have been given the impression that it is against the law for any shop, Webshop or other wise to keep records of their customers credit cards.

            I say this because I have ordered things from other places and there has been things that where placed on back order. I asked if they could just send me the items when they come in and charge my card. I was told in a very shocked voice that it is illegal to keep credit card numbers of their customers.

            2)In this day and age I would never dream of giving ANYBODY my card details "to ease further payment in the event of a back order". They can bloodywell send an e-mail and tell me its in stock and in my shoping basket if I would like to log in and pay. ANY THING else is asking for trouble.

            I Had an account their. They got my postal address, and name. when I got to the part register you card I just skipped that bit. Should I have needed to buy some thing I would of had to register I guess. Or buy it elsewhere. I choose the latter.

            I do hope that none of you get burned and as some have already done stopped your card.

            Lets hope Hannants get things sorted.

            Ian M
            Group builds

            Bismarck

            Comment

            • John
              Administrator
              • Mar 2004
              • 4656
              • John
              • Halifax

              #7
              I'm sure it's illegal to store credit card details now, not something that I would do, no matter how secure you think your site is there's always someone that could get in if they really want, I've just signed up for RBS worldpay to take payment on the shop but payments are taken by them and nothing is stored.
              www.scalemodelshop.co.uk

              Comment

              • Guest

                #8
                ****** Important Please read!! ******

                Just received this e-mail from Hannants about cards being compromised, Sadly I was one of those cards where three attempts were made. I have copied the e-mail below, but please check your bank accounts and your credit cards if you have one lodged with Hannants!

                (Threads Merged)

                Comment

                • Guest

                  #9
                  I wonder what Hannants will do now? They have obviously overlooked a major security detail when they have been putting their site together best they sign up for something more secure. I for one will not be using them online. A trip to Colindale if needs be, but probably others like John!

                  Andy

                  Comment

                  • Guest

                    #10
                    Wont enforce Hannants shopping confidence from customers,I took out CC protection a few years ago on my card for situations like this, well worth £15 a year for piece of mind, But if they have hacked them then they must have stored card details....and that is a big no no.

                    Never used Hannants, and doubt I will ever now.

                    Comment

                    • Guest

                      #11
                      Do we know if this applies to people who buy online from the website or will it affect those of us who phone our orders through using our hannants account numbers, as credit card details will be held by hannants for this method of ordering.this is scary stuff & hopefully we'll be kept informed.

                      will be checking with my credit card provider in the morning.

                      Comment

                      • tr1ckey66
                        SMF Supporters
                        • Mar 2009
                        • 3592

                        #12
                        I agree, Hannants have just scored an own goal, this will severely knock confidence in them. I've just canceled my card - a major pain in the backside, but better than taking an online hustle! This is my first problem with Hannants so I'm not going to knock them unduly, but a financial security breach like this is a major problem.

                        Comment

                        • Ian M
                          Administrator
                          • Dec 2008
                          • 18272
                          • Ian
                          • Falster, Denmark

                          #13
                          Now for the 64 thousand dollar question. As they have stored credit card details on their server, who is liable in the event of a customers card being used by someone other than the holder.

                          The issuer, the bank or Hannants?

                          In Denmark the issueing bank covers the loss under normal circumstances, provided the 'theft' is reported as soon as it occures but in this kind of case???

                          Ian M
                          Group builds

                          Bismarck

                          Comment

                          • Ian M
                            Administrator
                            • Dec 2008
                            • 18272
                            • Ian
                            • Falster, Denmark

                            #14
                            Originally posted by \
                            Do we know if this applies to people who buy online from the website or will it affect those of us who phone our orders through using our hannants account numbers, as credit card details will be held by hannants for this method of ordering.this is scary stuff & hopefully we'll be kept informed.will be checking with my credit card provider in the morning.
                            As i understand it if you have made a purchase at Hannants and paid with a credit card, you are in the system. Sad to say but I would not be surprised if this also the case if you have been to the shop and paid with a card IN THE SHOP.

                            Ian M
                            Group builds

                            Bismarck

                            Comment

                            • John
                              Administrator
                              • Mar 2004
                              • 4656
                              • John
                              • Halifax

                              #15
                              Originally posted by \
                              I agree, Hannants have just scored an own goal, this will severely knock confidence in them.
                              I am thinking twice if to buy from them again, since starting my shop I've spent 1000's with them, I can't think of anything I get from them that is unique to them, even their paints I can get else where at no extra cost.
                              www.scalemodelshop.co.uk

                              Comment

                              Working...