This incident has 0 proposed changes. Know of details that have changed? Submit them Showing Incident 5049 To_xml

SUMMARY

99 usernames, e-mail addresses, and plain-text passwords dumped on web by hacker
Records 99
Record Types EMA MISC PWD
Breach Type Hack
Data Family Electronic
Source Outside
Organization Math2020.com
Other Affected/Involved Organizations None
Lawsuit? NO/UNKNOWN
Data Recovered? NO/UNKNOWN
Arrest? NO/UNKNOWN
Submitted By: Dissent

TIMELINE

DateEvent
None. Add Data Incident Occurred
None. Add Data Incident Discovered By Organization
2011-11-23 Organization Reports Incident
None. Add Data Organization Mails Notifications
None. Add Data Records Recovered
None. Add Data Lawsuit Filed
None. Add Data Arrest Made

SIMILAR INCIDENTS

recordsdateorganizations
274 2006-03-16 Bananas.com
100 2007-04-20 Albertsons
194 2008-07-01 Houghton Mifflin Harcourt
226 2008-04-25 HSBC Holdings plc

MAP OF INCIDENT LOCATION

Address: Ohio, USA
Have a better address for this incident? Suggest it!

suggest a new reference

REFERENCES

suggest a new attachment

ATTACHMENTS

COSTS SUMMARY

Known Actual Costs

No known costs for this incident.

Estimated Costs

Ponemon Institute Direct Costs Estimate 1 $5,940.00
  1. Note that these estimates are based on the Ponemon Institute's 2009 direct costs figures from their 2009 Annual Study: Cost of a Data Breach. We multiply $60.00 by the number of records to obtain this figure. Keep in mind that depending on the breach, the direct costs are not always suffered by the breached organizations. In the case of credit card number breaches, the direct costs can often be suffered by banks and card issuers. Also note that this is only an estimate.

COMMENTS

by Dissent [DataLoss Archaeologist] on 2011-11-25 (6 months ago)

Curator's note from Dissent:

I contacted Math2020.com to alert them to the breach and they responded promptly. Here is their explanation:

"I want to thank you once more for letting us know about this data breach. I doubt we would have spotted it otherwise.

The problem was caused by two bugs in the Amember membership script. Amember.com is one of the top membership programs, so I'm surprised this happened.

Anyway, the Amember guys provided the fixes. Pastebin took down the file at our request. And our clients got their passwords reset and some instructions on how to stay safe online."

New Comment

captcha
Are you human?

Sponsored By: Rbs Tenable Zecurion
Use of the DataLossDB, and its exports, RSS feeds, reports, or other materials produced on this site by the Open Security Foundation requires authorization and potential licensing arrangements. For more information, please e-mail officers@opensecurityfoundation.org with a brief summary of how you would like to use this information; product, service, research, etc.
© 2005 - 2012, Open Security Foundation, All Rights Reserved.