Websites Zappos.com and 6PM.com have been hacked. Initial reports claim that customer addresses, names and phone numbers have been exposed.
It seems the incident took place late last night/early this morning. Online retailer Zappos has been sending emails to its customers regarding the attack. 6PM.com has sent out a similarly worded email to its customers. Both emails confirm that addresses, names, and phone numbers of customers have been compromised by “a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky.”
On the reassuring side of things, Zappos has stated that their database that is host to payment information of their 24 million customers has remained unaffected. The same has been stated in 6PM.com’s email.
Each email has informed customers that their passwords have been reset and that the “criminal” was not able to view full passwords during the breach, only their “cryptographically scrambled password”.
Zappos official statement can be read at the link above or below (abbreviated):
Subject: Information on the Zappos.com site – please create a new password
First, the bad news:
We are writing to let you know that there may have been illegal and unauthorized access to some of your customer account information on Zappos.com, including one or more of the following: your name, e-mail address, billing and shipping addresses, phone number, the last four digits of your credit card number (the standard information you find on receipts), and/or your cryptographically scrambled password (but not your actual password).
THE BETTER NEWS:
The database that stores your critical credit card and other payment data was NOT affected or accessed.
SECURITY PRECAUTIONS:
For your protection and to prevent unauthorized access, we have expired and reset your password so you can create a new password. Please follow the instructions below to create a new password.
We also recommend that you change your password on any other web site where you use the same or a similar password. As always, please remember that Zappos.com will never ask you for personal or account information in an e-mail. Please exercise caution if you receive any emails or phone calls that ask for personal information or direct you to a web site where you are asked to provide personal information.
PLEASE CREATE A NEW PASSWORD:
We have expired and reset your password so you can create a new password…
Leave a Reply