The appropriate response to this whole situation should be cautious. Cancel your card, watch your other accounts, and wait until the full story comes out before you hurt a business that may not be to blame. Thomas still hasn't released any information regarding the processor, and until he issues the final statement claiming responsibility, there is no reason to boycott CSC.
Unfortunately, most of the response here and at Fwoosh is "burn CSC to the ground, I hate them, they raped my innocence, my entire life is over and some hacker from Siberia is going to steal my house."
Good afternoon.
You are receiving this email because there is sufficient reason to believe that the credit card(s) you have used to make recent purchases at CornerStoreComics.com may have been compromised.
Through the assistance of a network analysis company, the company that developed our website, the payment processing company, our staff, and the customers that have been very helpful in providing fraudulent transaction details, we have been able to verify that the primary order database was accessed via a dormant Internet payment gateway port that was being tested during the construction phase of the new site but never actually put into use.
Our research has not been able to determine how much access the perpetrator(s) may have had to the admin server, so we are alerting anyone that has placed an order since the launch of the new site to ensure maximum coverage. Orders from the old site were never attached to the new site, so credit cards used solely on the old site are not at any risk with regard to this situation.
The best recommendation we can offer is to either monitor your cards closely for any suspicious activity or call your credit card company to request that your card(s) be replaced as soon as possible in order to avoid any fraudulent charges. Any orders that were placed via PayPal could not have been impacted by this, so there is no need to monitor or make changes to cards or bank accounts used via PayPal’s system.
From the very moment that we heard there might be a problem, we began making changes to our system to eliminate the risk to new orders. Our entire order server was relocated, every system password was updated, encryption levels were verified, all ports were checked, and logging was expanded to cover every possible avenue of communication flow. Additionally, access to the admin server has been limited to localized IP addresses only and the processing company responsible for the Internet payment gateway has been eliminated altogether. The website has been securely locked down since the evening of March 6th (within an hour of identifying the pattern of fraud via reports from our customers), so all new credit cards provided since that time, whether through new order placement or as updated payment method, are secure and are not impacted by the security breech.
We are absolutely mortified that this could have happened to us and, more importantly, to you. You have our sincere apologies for any inconvenience these events may cause you.
Please feel free to forward any questions you may have, and we will do our best to answer them as quickly as possible.
Sincerely,
Thomas Gaul
President CornerStoreComics LLC
714-626-0082
As you can see, he has all but admitted his part in all of this. So those who refuse to continue doing business with CSC are completely justified.
So I think your argument is....flawed.
I really don't think it was the payment processor or the fraud would have shown up sooner and more random but it's too coincidental that everyone here who has been hit with fraudulent transaction have all done business with CSC and we're all getting hit at once, just weeks after their server migration.
And from your own last post...
"Additionally, access to the admin server has been limited to localized IP addresses only and the processing company responsible for the Internet payment gateway has been eliminated altogether.
Jesus guys, I think it's time everybody took a deep breath and calmed down a bit.
No need for name-calling or personal attacks.
What is it with people that they have to resort to that kind of attitude?
Is it confirmed that CSC will waive the preorder cancellation fee for some people?
The Heartland breach occurred last year. I received a letter about the Heartland breach informing me that my identity may have been stolen within weeks of receiving similar letters from my mortgage company and my stock brokerage firm. This was back in Sept '08. At which time I immediately purchased credit protection and put a freeze on my credit. The letters I received came almost 6 months after the security breaches had actually occurred and the companies involved had been keeping their customers in the dark during their investigation, similar to what CSC has been doing. Now all of the sudden everyone here who has made a purchase at CSC is suddenly hit with fraud at the same time, just weeks after they switched servers and initially admitted they left a vacant port open for testing. Now they are trying to cover their asses and blame it on the credit processor Heartland from the security breach last year which only went public on Jan. 20. Thomas already admitted their fault in this earlier and gave us every reason why we shouldn't trust them with our business. Now he's backpedaling because he has lost our business. I really don't think it was the payment processor or the fraud would have shown up sooner and more random but it's too coincidental that everyone here who has been hit with fraudulent transaction have all done business with CSC and we're all getting hit at once, just weeks after their server migration. This had to be a deliberate hack into their server through that access port they admittedly left open for "testing" and forgot to disable. They got sloppy and we got screwed.
Enter your email address to join: