Here's Thomas' reply:
Good afternoon.
You are receiving this email because there is sufficient reason to believe that the credit card(s) you have used to make recent purchases at CornerStoreComics.com may have been compromised.
Through the assistance of a network analysis company, the company that developed our website, the payment processing company, our staff, and the customers that have been very helpful in providing fraudulent transaction details, we have been able to verify that the primary order database was accessed via a dormant Internet payment gateway port that was being tested during the construction phase of the new site but never actually put into use.
Our research has not been able to determine how much access the perpetrator(s) may have had to the admin server, so we are alerting anyone that has placed an order since the launch of the new site to ensure maximum coverage. Orders from the old site were never attached to the new site, so credit cards used solely on the old site are not at any risk with regard to this situation.
The best recommendation we can offer is to either monitor your cards closely for any suspicious activity or call your credit card company to request that your card(s) be replaced as soon as possible in order to avoid any fraudulent charges. Any orders that were placed via PayPal could not have been impacted by this, so there is no need to monitor or make changes to cards or bank accounts used via PayPal’s system.
From the very moment that we heard there might be a problem, we began making changes to our system to eliminate the risk to new orders. Our entire order server was relocated, every system password was updated, encryption levels were verified, all ports were checked, and logging was expanded to cover every possible avenue of communication flow. Additionally, access to the admin server has been limited to localized IP addresses only and the processing company responsible for the Internet payment gateway has been eliminated altogether. The website has been securely locked down since the evening of March 6th (within an hour of identifying the pattern of fraud via reports from our customers), so all new credit cards provided since that time, whether through new order placement or as updated payment method, are secure and are not impacted by the security breech.
We are absolutely mortified that this could have happened to us and, more importantly, to you. You have our sincere apologies for any inconvenience these events may cause you.
Please feel free to forward any questions you may have, and we will do our best to answer them as quickly as possible.
Sincerely,
Thomas Gaul
President
CornerStoreComics LLC
714-626-0082
I may be wrong but this doesn't sound like it was a credit card processor to me...sounds like this started with CSC's site. Maybe not, maybe the test portal that was set up with the CC processor was the culprit...is that what he is saying?