Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Massive Breach at Epsilon Compromises Customer Lists of Major Brands
Security Week ^ | April 2, 2011 | Mike Lennon

Posted on 04/02/2011 8:46:19 PM PDT by brytlea

Due to the growing list of brands disclosing that they have been compromised as a result of this breach, I’m going to go ahead and tag this as a massive breach. And I only expect it to get bigger as more announcements come out from Epsilon customers.

Last night we reported on a breach at marketing services provider, Epsilon, the world’s largest permission-based email marketing provider. Initially we wrote that the breach had affected Kroger, the nation's largest traditional grocery retailer. There is a list of companies at the link (but I don't know if that is going to be the full list, it sounds like there may be more yet).

It turns out that Kroger is only one of many customers affected by the breach at Epsilon.

(Excerpt) Read more at securityweek.com ...


TOPICS: Business/Economy; Crime/Corruption; News/Current Events; Technical
KEYWORDS: brookstone; capitalone; chas; chase; citicorp; collegeboard; computer; cyberattack; cybercrime; email; epsilon; hacked; hacker; hacking; hiltonwalgreens; hsn; jpmorgan; kroger; marriott; phishing; ritzcarlton; security; spam; tivo; usbank
Navigation: use the links below to view more comments.
first 1-2021-4041-49 next last
I hope this is ok to post. I didn't find it by searching. I got an email from TiVo tonight, so searched and found this (and other) articles. This seems to be big and maybe getting bigger. There are quite a few companies that appear to be at risk. It seems that only email addresses and names are at risk, (not other info) however, that's enough for the hackers to increase their success at phishing. I had thought it a good idea to get the info out there.
1 posted on 04/02/2011 8:46:25 PM PDT by brytlea
[ Post Reply | Private Reply | View Replies]

To: brytlea

Thanks.


2 posted on 04/02/2011 8:53:51 PM PDT by FreedomOfExpression
[ Post Reply | Private Reply | To 1 | View Replies]

To: brytlea

You would think that an outfit this big — and supposedly professional — would have encrypted this data. Apparently not.


3 posted on 04/02/2011 8:59:04 PM PDT by Nick Danger (Pin the fail on the donkey)
[ Post Reply | Private Reply | To 1 | View Replies]

To: brytlea

We just received a message from the College Board (the folks who run the Advanced Placement exams and the SATs) stating, “We have been informed by Epsilon, the vendor that sends email to you on our behalf, that your e-mail address may have been exposed by unauthorized entry into their system.”


4 posted on 04/02/2011 8:59:40 PM PDT by StayAt HomeMother
[ Post Reply | Private Reply | To 1 | View Replies]

To: StayAt HomeMother

Yeah, sounds basically like what I received from TiVo. Whoever did this apparently now has a LOT of email addresses with names. :(


5 posted on 04/02/2011 9:01:38 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Nick Danger

This is one reason I have stopped giving my email address to almost anyone, if I don’t have to. Seems that every store I buy something in nowadays wants my email address and I just say, “No thank you.” They always seem surprised. Next time I’ll just mention this fiasco.


6 posted on 04/02/2011 9:04:03 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 3 | View Replies]

To: brytlea

Thank you. This is the unpteenth time this has happened in the past year or so, but this sounds like one of the biggest.

Ugh.


7 posted on 04/02/2011 9:05:13 PM PDT by mountainbunny
[ Post Reply | Private Reply | To 1 | View Replies]

To: mountainbunny

I wonder if they EVER catch these creeps?


8 posted on 04/02/2011 9:08:01 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 7 | View Replies]

To: brytlea

I got an e-mail from the college board.


9 posted on 04/02/2011 9:32:15 PM PDT by luckystarmom
[ Post Reply | Private Reply | To 1 | View Replies]

To: brytlea

Thank you for posting. I received an email tonight from collegeboard.com about the epsilon breach, that my first and last name and email were fraudulently accessed. This is why I come to freerepublic when I want breaking news.


10 posted on 04/02/2011 9:42:34 PM PDT by Havisham
[ Post Reply | Private Reply | To 1 | View Replies]

To: Havisham

Got the same email here


11 posted on 04/02/2011 9:44:17 PM PDT by Mom MD (Jesus is the Light of the world!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Havisham; luckystarmom

I just hope names and emails were really all they got.


12 posted on 04/02/2011 9:47:18 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 10 | View Replies]

To: brytlea

Thanks! I have online accounts at some on the list.

Just another reminder to look at the email, then open the site from *FAVORITES* (or even Google it) instead of using the links in the email.

Not that I don’t get sloppy now & then when there’s a good sale at an e-merchant I regularly do business with.


13 posted on 04/02/2011 9:54:29 PM PDT by ApplegateRanch (Made in America, by proud American citizens, in 1946.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

ping!


14 posted on 04/02/2011 9:56:42 PM PDT by bitt ( ..Congress - either investigate Obama ...or yourselves, for complicity)
[ Post Reply | Private Reply | To 1 | View Replies]

To: brytlea

Got an email from US Bank yesterday - they were a target as well.


15 posted on 04/02/2011 9:58:03 PM PDT by TexasNative2000 (Uncertainty: it's the new normal)
[ Post Reply | Private Reply | To 1 | View Replies]

To: brytlea

I don’t know. It doesn’t seem as though they catch these criminals very often.

This sort of thing points to the need for everyone to step up and take responsibility for their own online security. It’s clear that most companies have no intention of helping in any meaningful way.


16 posted on 04/02/2011 9:59:05 PM PDT by mountainbunny
[ Post Reply | Private Reply | To 8 | View Replies]

To: ApplegateRanch

I’ve gotten so paranoid anymore, but it only takes getting sloppy once. It just seems these creepy scoundrels are so pervasive anymore and I guess they are next to impossible to catch.


17 posted on 04/02/2011 9:59:35 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 13 | View Replies]

To: mountainbunny

I agree, it doesn’t seem like they EVER catch them, and it doesn’t seem that there seems to be any desire on the part of the government (altho it may just be that it’s virtually impossible, I don’t know).

The problem is, you can be careful (I am, extremely so) but it seems the bad guys get smarter and better all the time. I don’t know how long we can stay a step ahead of them. I’m not a techie genius. At some point do we just throw in the towel and give up?


18 posted on 04/02/2011 10:02:17 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 16 | View Replies]

To: TexasNative2000

None of my banks have sent me anything. Yet.


19 posted on 04/02/2011 10:02:48 PM PDT by brytlea (A tick stole my tagline....)
[ Post Reply | Private Reply | To 15 | View Replies]

To: brytlea

Yeah, I know exactly what you mean.

I looked (in *Preview*) at an email from my auto insurer a couple of months back, and it looked EXACTLY like what I normally get from them, but didn’t seem ‘right’.

I finally noticed in the small print at the end that they had a letter in the acronym wrong. I deleted it without opening, then did a set of scans just to be safe.

I also web-based email accounts, and when something comes to them, no matter what or from whom, I right click on any links in the *PREVIEW*, and hit *PROPERTIES*, and that shows what the REAL address of the link is, no matter what it says it is. It doesn’t get opened if it’s got bad links.

Have to be careful, and check EACH link, because there are often a couple of real links to main site of the real company in th first part & very end, but the “money links” for the actual “offer” in the body of the message are the redirects.

I’ve googled some of them, and most are well know scam operations located mainly in China, Rumania, or Russia, where there is zero chance of doing anything about them.


20 posted on 04/02/2011 10:15:58 PM PDT by ApplegateRanch (Made in America, by proud American citizens, in 1946.)
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-49 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson