MSE News: Fraud risk for thousands after Lush website hack

This is the discussion thread for the following MSE News Story:

"Thousands of shoppers who ordered online cosmetics over the past three and a half months could have had their card details stolen. ..."
OfficialStamp.gif

This thread is to discuss this news story. Another thread on the topic was started last night.
«13

Comments

  • ShaneUK
    ShaneUK Posts: 1,094 Forumite
    First Anniversary Combo Breaker
    Congratulations to Lush on taking down the WHOLE website - and stopping all online orders until rectified.

    I love their comment to the hacker as well!!
  • "For complete ease of mind"

    Well if that is its concern, it could share what it knows about how many cards and why just it's UK website - Lush.fr for example is still trading.
  • I love the comment to the hacker too :-)
    If you don't like what I say slap me around with a large trout and PM me to tell me why.

    If you do like it please hit the thanks button.
  • Jesthar
    Jesthar Posts: 1,450 Forumite
    oakhouse13 wrote: »
    "For complete ease of mind"

    Well if that is its concern, it could share what it knows about how many cards and why just it's UK website - Lush.fr for example is still trading.
    Speaking as a professional Systems Administrator, I would say that:

    1. If you are unfortunate enough to suffer a security breach, openly advertising to the hackers just how successful or otherwise they were is NOT a good idea. It tends to encourage both them and others of their ilk.

    2. From the information we have, it sounds like only the UK site has been targetted. The websites in country are almost certainly hosted and maintained independently within that particular company, not all run from one central location. Given that Lush will now know how the attack was executed, they can update and protect the other sites as required to prevent a similar attack from succeeding there. The problem with the UK site now is not protecting it against another similar attack, but that the code of the website itself could have been fatally compromised with backdoors and other snoopware by the hackers. Better to pull it, bin it and start again, even though a lot of work is involved in that.

    And Lush have done just that, so kudos to them for handling a nasty situation with both decisiveness and a sense of humour! :)
    Never underestimate the power of the techno-geek... ;)
  • corbyboy
    corbyboy Posts: 1,169 Forumite
    First Anniversary
    Getting your website hacked is just one of those things that happens now and again.

    But if I were a Lush customer I would be demanding to know why credit card numbers are being stored on their database. What business do they have keeping a record of these numbers?
  • Well I'm one of those affected - this morning someone, somewhere added £1,000 to my credit card balance - according to my card provider it was from a clothes shop (though they didn't stipulate which one). They've suspended my card and the fraud team will be contacting me tomorrow to discuss it.

    Though mistakes happen it seems to have taken lush the best part of a month to tell it's customers. Looks like this second round of attacks attracted the attention of someone there who thought it might be wise to mention it. Incompetent muppets.
  • vikingaero
    vikingaero Posts: 10,920 Forumite
    First Post First Anniversary Combo Breaker
    Jesthar wrote: »

    And Lush have done just that, so kudos to them for handling a nasty situation with both decisiveness and a sense of humour! :)

    So "decisiveness" is over 3 weeks in the IT industry? Seems like Lush knew for a while and didn't want to compromise their Xmas and New Year sales. Any other company and they would be slated, but because it's "ethical and lovely" Lush they can do no wrong?
    The man without a signature.
  • The other day I posted on the o2 scam page as money had been taken from my account. As I ordered online with Lush in December, I wonder if they are linked?
  • I got one of their warning emails and am a bit out out that they didn't shut it straight away.
    I wonder if this problem is linked in any way with when they shut the website down when the sale was on.
    Not sure I shall want to buy online form them again after this. However much they are/aren't to blame.
    It's certainly made me think twice about online shopping in general.
    I check my cc balance everyday as it is and shall be continually doing now.
  • gould300 wrote: »
    Well I'm one of those affected - this morning someone, somewhere added £1,000 to my credit card balance - according to my card provider it was from a clothes shop (though they didn't stipulate which one). They've suspended my card and the fraud team will be contacting me tomorrow to discuss it.

    Though mistakes happen it seems to have taken lush the best part of a month to tell it's customers. Looks like this second round of attacks attracted the attention of someone there who thought it might be wise to mention it. Incompetent muppets.

    hope it all gets sorted for you quickly
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 342.9K Banking & Borrowing
  • 250K Reduce Debt & Boost Income
  • 449.6K Spending & Discounts
  • 235K Work, Benefits & Business
  • 607.7K Mortgages, Homes & Bills
  • 172.9K Life & Family
  • 247.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards