This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 2322 To_xml

SUMMARY

52000 customers credit card details lost from hacked server
Records 52,000
Record Types CCN NAA
Breach Type Hack
Data Family Electronic
Source Outside
Organization Mitsubishi Corporation
Other Affected/Involved Organizations None
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: kirniki

TIMELINE

DateEvent
None. Add Data Incident Occurred
None. Add Data Incident Discovered By Organization
2009-09-05 Organization Reports Incident
None. Add Data Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
98,000 2001-03-05 Amazon, Bibliofind.com
46,000 2001-04-02 ADDR.com
140,000 2005-11-26 Troy Group, Scottrade
32,000 2006-04-12 Ross-Simons

MAP OF INCIDENT LOCATION

Address: Tokoyo Japan
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

COSTS SUMMARY

Known Actual Costs

No known costs for this incident.

Estimated Costs

Ponemon Institute Direct Costs Estimate 1 $3,120,000.00
  1. Note that these estimates are based on the Ponemon Institute's 2009 direct costs figures from their 2009 Annual Study: Cost of a Data Breach. We multiply $60.00 by the number of records to obtain this figure. Keep in mind that depending on the breach, the direct costs are not always suffered by the breached organizations. In the case of credit card number breaches, the direct costs can often be suffered by banks and card issuers. Also note that this is only an estimate.

COMMENTS

by d2d [Data Loss Maven] on 2009-09-25 (10 months ago)

Translation of notification letter:


September 4, 2009
To whom
Dejitarudairekuto Co.
Unauthorized access to customer information associated with our Like
Apologize for reporting and information flow
This time, our Like "saQwa (?Coeur) Shopping Network" (http://saqwa.jp/) and "fun style shopping (Fansutairushoppingu)" (http://www.fun-ss.com/) ( the "Site" is called) you use your personal information, and acknowledged that the leak was due mainly to multiple unauthorized access attacks from abroad. The customers can We apologize for the inconvenience and worry a lot, and we apologize.
We are regarded with utmost seriousness the incident, and its act together and to restore customer confidence, we will continue working hard. Make a report to the authorities with information found?Shimashita known, our website (http://www.digitaldirect.co.jp/) will from time to time by the public.
Also, For inquiries about this matter, the Postscript "Contact Us exclusive special" thank you so you can call us.
Circumstances of this case to the present, and future support For sure?Shimashita facts are as follows.
?
1, correspond to the background
06/29
Based on the inquiry, and there are concerns about abuse in other shops using your credit card company credit card from our site, results of a survey conducted at the range we can, in fact such respond to the credit card company could not confirm the effect
7.13
, For the record, to start a consulting company specializing in security
11/8
, Again, from the same credit card company, stating that continued contact with the other stores in the event of misuse, undergo reexamination request
08/15
Implement additional security enhancements,
18.8
Sun, August 17 attack was found to be 2 cases (two cases this was blocked by security software added)
20.08
Temporary suspension, and this site, blocking access from the outside (since, still dormant today)
Request a company specializing in log analysis, security
21/08
, Contact the authorities concerned (Ministry of Economy, Trade and Industry (companies) Japan Direct Marketing Association)
, Requested the strengthening of monitoring and consultation for preventing unauthorized use of credit card companies
8.31
Receive a report, and confirmed that the outflow from security specialist
2, other subjects and items of personal information leakage may be accessed by unauthorized
(1) Eligible
VENDOR a non-delivery, our customers and capped his registration or purchase this site
(2) other items
Items may drain, is as follows.
Credit card information, user ID, password, name, gender, birth date, phone number, address, email address
?Shimashita, the number of items found at this time are as follows runoff.
Credit Card Information: about 52,000 cases (including those expired)
Email Information: about 29,000 cases (of Mail Magazine)
, Others are under investigation found more questions.
3, route runoff
Our server was illegally accessed from outside, has been confirmed to have been stolen personal information held by us.
4, support for future
For customers that may be affected by the flow of information, we need to let us start by writing an e-mail sequentially.
Takashi, We advise to you, your credit card statement Presents confirm whether or not the request contains no??Ri us, so thank you note????. The unlikely event you have any request without your??Ri, is located in Sorry, bon appétit to contact your credit card company from you, thank you and more. For the target customer, and work on the credit card company, bypassing the inconvenience I
Wholeheartedly with its strong demand for U.
Also, if the same password for your login password and credit card is to prevent the unauthorized use of credit cards just in case, thank you card to change the password for bon appétit.
5, measures to prevent recurrence
To ensure a more robust and based on the advice of a professional security company, we will continue to do to strengthen systems and management. In the meantime, we will continue the temporary suspension of this site.
More
Again, here, so we're working on our For more information, etc. For how to respond to the progress of the facts found and a new future, the Company's website (http://www.digitaldirect.co.jp/) We are pleased at any time.
For further information regarding this matter, the following "Contact Us exclusive special" thank you to contact bon appétit.
? Contact Us ? dedicated special from you regarding this matter
Call Free: 0120-77-1543
Hours: 9:30 - 18:00 (Mon - Sun including public holidays)
? per case, from our customers by phone, credit card numbers
Expiration date, things you do not ask any personal identification number, etc.

New Comment

simple_captcha.jpg
(type the code from the image)

Sponsored By: Credant_200x51 Tenable Pgp_logo Zecurion
Permission is granted to use this database in non-profit works and research. Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation for commercial interests requires authorization and licensing arrangements. For more information, please e-mail curators@datalossdb.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2010, Open Security Foundation, All Rights Reserved.