+++ to secure your transactions use the Bitcoin Mixer Service +++

 

RSS

Discover news, guides, and products for your business

Follow us on:
Security Alert
Security Alert
Practical security advice » More Security Alert » RSS » All Blogs

  • Recommend:
  • 0 Comments
  • Print

Zappos Hacked: What You Need to Know

Zappos.com – the online source for shoes – was the victim of an attack that compromised account information for millions of customers. Zappos customers need to understand what is at stake, and be on alert for suspicious or malicious activity resulting from the attack.

In a letter to Zappos customers, CEO Tony Hsieh explains that the site was hacked, and that information including names, email addresses, billing and shipping addresses, phone numbers, the last four digits of credit card numbers, and encrypted passwords may have been exposed. The good news, according to Hsieh, is that the database storing actual credit card and payment data was not breached.

Broken padlockAccount data for Zappos' 24 million customers has been compromised by hackers.What Do We Know?

At this early stage, we basically know what few details Zappos has shared with it customers. Neil Roiter, research director for Corero Network Security, says, “We know that some 24 million customer records were breached.”

What Don’t We Know?

There is a lot we don’t know. Roiter explains, “We don’t know how the breach occurred, or when or over how long a period of time it took place.”

Those details may prove helpful for future reference – especially if the attackers exploited a zero day vulnerability, or found a unique attack vector that other organizations should be aware of to adequately defend against. As far as the fallout of this specific event goes, though, the proverbial horse is already out of the barn. Figuring out how the information was compromised won’t uncompromise it.

What Could / Should Zappos Do Differently?

Andrew Storms, director of security operations at nCircle, says, “There’s almost no information about the attack method used to infiltrate Zappos so it’s way too early to point fingers or throw stones at their security practices.”

Storms points out that Zappos’ response to the incident seems to be appropriate so far. It has notified customers, and it reset all passwords to force customers to create new ones to replace those that may be exposed or cracked as a result of the breach.

Roiters agrees that there really isn’t enough information to go on to determine what, if anything ,Zappos may have done wrong. He stresses, however, that data breaches often go undetected for extended period of time.

Roiters says, “Companies such as Zappos should have technology in place that monitors activity on their networks and reports in real time on suspicious activity or activity that does not conform to security policy. The sooner an organization detects a breach, the more quickly it can contain it.”

What Should Zappos Customers Do Now?

nCircle’s Storms says that an incident like the Zappos breach is a poignant reminder for customers to make sure they use different passwords for different Internet sites – especially ecommerce sites that may contain credit card or other financial details. By using unique passwords, you can ensure the damage from a breach is limited to that one site or service.

Zappos has already taken the initiative to reset all user passwords. When creating a new one, users should remember basic password practices and make sure the password they choose is long enough and complex enough to resist cracking attempts.

Roiters says that customers may want to alert any affected credit card companies to be on alert, and adds, “It is advisable for people to use an identity protection service that alerts them if there is an suspicious activity on their accounts.”

It is fortunate the hackers apparently haven’t breached the actual credit card and payment data. That alone minimizes the impact of this attack to some extent. Still, the data that was compromised has significant value and could be used for identity theft, so be vigilant about watching your accounts for suspicious activity.

Was this article useful? Yes 0 No 0
Tony Bradley

You can follow Tony on his Facebook page, his Google+ profile, or contact him by email at tony_bradley@pcworld.com. He also tweets as @TheTonyBradley.

Comments

  • Protect Your PCs in 2012 A race is constantly going on between software vendors identifying and patching security holes, and malicious attackers trying to exploit them. Don't let your company get caught in the middle of that contest. This year, resolve to make it simpler to update and protect your systems.
  • Back It Up in 2012 This year, resolve to find a backup solution that protects your data--and that can restore it with a minimum of delay at a critical time.
  • Work Smarter, Not Harder, to Get Secure Securing your network and all the devices connected to it has never been easy, but it has become harder than ever as new threats and new technologies demand your attention. Make a New Year's resolution to implement a comprehensive security platform and strategy that takes the pain out of securing your environment.
  • Lose the Laptop, Not the Data The same things that make laptops portable and convenient also make them easily lost or stolen. Resolve to make sure the data on your laptops is protected even if the laptop itself falls into the wrong hands.
  • New Year's Resolution: Protect Your Business Data It's that time of the year--the time to reflect on the year gone by, ponder ways to improve your company's performance, and resolve to meet your goals for the coming year. As 2012 arrives, resolve take this opportunity to pledge to do a better job of protecting your critical business data.
  • Cut the Cord Without Cutting Security Notebooks and ultrabooks let users get more work done while on the go, but can be a nightmare when it comes to security. Resolve to protect your mobile PCs and get peace of mind by taking a close look at your mobile security environment in the coming year.
Business News Daily

Get the latest technology news that's important to you and your business, fresh seven days a week.

Featured Webcasts

Free Whitepapers

Software and Services Whitepapers from PCWorld

More whitepapers »

Whitepaper Alerts

Get updates on white papers, case studies, and spotlights on tech products and solutions for your business.