Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Epsilon's epic fail: The numbers don't add up (Customer list included)

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » General Discussion Donate to DU
 
Renew Deal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:02 AM
Original message
Epsilon's epic fail: The numbers don't add up (Customer list included)
Edited on Fri Apr-08-11 10:05 AM by Renew Deal
Note from me: If you've received even one of these warnings, you should read this post.
______________________________________________________________________

If you haven't yet received an email message from a major company, warning that your email address may have been compromised, you will.
<snip>

On April 1, online marketing firm Epsilon Data Management -- InfoWorld curmudgeon-in-residence Robert X. Cringely calls them "spammers in expensive suits" -- sent out a press release saying that "a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system. The information that was obtained was limited to email addresses and/or customer names only. A rigorous assessment determined that no other personal identifiable information associated with those names was at risk. A full investigation is currently underway."

On April 4, Epsilon updated the press release, adding this puzzling footnote: "The affected clients are approximately 2 percent of total clients and are a subset of clients for which Epsilon provides email services." I'll talk about that in a moment.
<snip>

Epsilon is also mum on the question of whether the stolen data could be associated with a specific Epsilon customer. Having a list of 100,000 email addresses is one thing. Having a list of 100,000 valid email addresses from JPMorgan customers opens up an entirely different realm of possibilities.

That raises yet another question. If zillions of email addresses were stolen, and the thief or thieves can't tell which Epsilon customer they came from, what is Epsilon doing, sitting on a big pool of undifferentiated email addresses and names?
<snip>

http://www.infoworld.com/t/phishing/epsilons-epic-fail-the-numbers-dont-add-177

Epsilon Breach Raises Specter of Spear Phishing

Security experts are warning consumers to be especially alert for targeted email scams in the coming weeks and months, following a breach at a major email marketing firm that exposed names and email addresses for customers of some of the nation’s largest banks and corporate brand names.
<snip>

Rod Rasmussen, chief technology officer at Internet Identity and the industry liaison for the Anti-Phishing Working Group, believes that the Epsilon breach will lead to an increase in “spear phishing” attacks, those that take advantage of known trust relationships between corporations and customers by crafting personalized messages that address recipients by name, thereby increasing the apparent authenticity of the email.
<snip>

List of known Epsilon customers:

■1800-Flowers
■Abe Books
■Air Miles CA
■Ameriprise Financial
■Barclays Bank of Delaware
■Beachbody
■Bebe Stores Inc.
■Benefit Cosmetics
■BestBuy
■Brookstone
■Capital One
■Charter Communications (Charter.com)
■Chase
■Citibank
■City Market
■The College Board
■Crucial.com
■Dell Australia
■Dillons
■Disney Vacations
■Eurosport/Soccer.com
■Eddie Bauer
■Food 4 Less
■Fred Meyer
■Fry’s
■Hilton Honors
■The Home Shopping Network
■Jay C
■JP Morgan Chase
■King Soopers
■Kroger
■LL Bean
■Marks & Spencer (UK)
■Marriott Rewards
■McKinsey Quarterly
■Moneygram
■New York & Co.
■QFC
■Ralphs
■Red Roof Inns Inc.
■Ritz Carlton
■Robert Half
■Smith Brands
■Target
■TD Ameritrade
■TIAA-CREF
■TiVo
■US Bank
■Verizon
■Viking River Cruises
■Walgreens
■World Financial Network National Bank

http://krebsonsecurity.com/2011/04/epsilon-breach-raises-specter-of-spear-phishing
Printer Friendly | Permalink |  | Top
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:04 AM
Response to Original message
1. K&R
Thank you for the list. :hi:
Printer Friendly | Permalink |  | Top
 
xchrom Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:04 AM
Response to Original message
2. this whole thing is horrifying. nt
Printer Friendly | Permalink |  | Top
 
snappyturtle Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:05 AM
Response to Original message
3. Yep. Got one yesterday from Capital One for my emergency credit card
which I don't use. The subject line said it was an important message. I figured they were cutting me off but it was this instead.
Printer Friendly | Permalink |  | Top
 
Vadem Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:16 AM
Response to Original message
4. I got one from Verizon......n/t
Printer Friendly | Permalink |  | Top
 
Lyric Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:19 AM
Response to Original message
5. Got one from Best Buy nt
Printer Friendly | Permalink |  | Top
 
CountAllVotes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:20 AM
Response to Original message
6. several
US Bank, LL Bean, Abebooks ... probably some others too I'm thinking. :mad:

:argh:

:kick: & recommend.

Printer Friendly | Permalink |  | Top
 
asjr Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:25 AM
Response to Original message
7. Mine came from U.S. Bank and I still
do not know what the hell happened. The only card I possess is a debit card from them.
Printer Friendly | Permalink |  | Top
 
Renew Deal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:28 AM
Response to Reply #7
9. That's more than enough.
If they have your email address, you're on the list even if you are set up as "do not email."
Printer Friendly | Permalink |  | Top
 
asjr Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:39 AM
Response to Reply #9
13. Thanks. I am just too old to go
through this crap. The wolf is at my front door now and does not need any more help getting in.
Printer Friendly | Permalink |  | Top
 
CantAffordBootstraps Donating Member (38 posts) Send PM | Profile | Ignore Fri Apr-08-11 10:25 AM
Response to Original message
8. State of CT recently started using Chase to issue
unemployment using either direct deposit from Chase or a Chase EBT card. I wrote to my rep and the State Dept of Labor when this started and noted, among other things, that Chase has been breached before. I just resent that email (sort of a "see, told you so") and asked them for what information Chase and/or Epsilon has been given about me (and others on UI). Do you think I'll get a reply? Hmmm...
Printer Friendly | Permalink |  | Top
 
Renew Deal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:29 AM
Response to Reply #8
11. Welcome to DU
:hi: Good luck getting that reply. :)
Printer Friendly | Permalink |  | Top
 
Fuzz Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:29 AM
Response to Original message
10. I've gotten 3 warning emails
Printer Friendly | Permalink |  | Top
 
enlightenment Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:31 AM
Response to Original message
12. Did they get phone numbers, also? Because
a friend just told me that after using her Capitol One card the other day, she got an automated phone call telling her there was a problem with her account. It told her to 'push a button' to continue . . . she hung up instead and called the card company directly.

They told her there was no problem with her card and she has had no charges on it. It was very strange.

Printer Friendly | Permalink |  | Top
 
Renew Deal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 10:47 AM
Response to Reply #12
14. They didn't admit to losing phone numbers but...
Edited on Fri Apr-08-11 10:48 AM by Renew Deal
If they know the name of the person and the companies they use, it's not hard to get a phone number. That scam goes on in general.
Printer Friendly | Permalink |  | Top
 
nc4bo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-08-11 05:06 PM
Response to Original message
15. Got mine from Charter. wtf. nt
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 07:42 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » General Discussion Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC