PDA

View Full Version : Attention TAD Gear Customers!



Oscar 319
11-18-09, 20:57
Just FYI for those that have purchased gear from TAD's website;


Important Notice
Today at 7:23pm
This notice is to inform our customers of a security incident at TAD Gear. We recently learned that our database was illegally accessed from an external source, and it appears that some customer data were taken, which may include customer names, contact information and credit card data. The possibility of a security breach came to our attention when certain customers notified us that unauthorized charges had appeared on their credit cards. Upon learning of the potential breach of security, TAD Gear immediately initiated an investigation, and took corrective steps based on the advice of an internet security firm. We have also contacted law enforcement.

If you purchased merchandise from TAD Gear on-line between August 6, 2009 and November 16, 2009, and the credit card used to purchase that merchandise is still valid, in order to protect yourself from the possibility of identity theft or misuse of your credit card information, we recommend that you immediately contact the issuer of that credit card and close your account. Tell them that your account may have been compromised. If you want to open a new account, ask your credit card issuer to give you a PIN or password, as this will help control access to the account.

In addition, we recommend that you place a fraud alert on your credit files. A fraud alert lets creditors know to contact you before opening new accounts. Just call any one of the three credit reporting agencies at a number below. This will let you automatically place fraud alerts with all of the agencies. You will then receive letters from all of them, with instructions on how to get a free copy of your credit report from each.

Experian Equifax TransUnion
888 397 3742
www.experian.com
866-640-2273
www.equifax.com
877-701-5276
www.transunion.com


When you receive your credit reports, look them over carefully. Look for accounts you did not open. Look for inquiries from creditors that you did not initiate. And look for personal information, such as your home address and Social Security number, which is not accurate. If you see anything you do not understand, call the credit reporting agency at the telephone number on the report.

If you do find suspicious activity on your credit reports, call your local police or sheriff’s office and file a police report of identity theft. Get a copy of the police report. You may need to give copies of the police report to creditors to clear up your records. Even if you do not find any signs of fraud on your reports, we recommend that you check your credit report every three months for the next year. Just call one of the numbers above to order your reports and keep the fraud alert in place.

For more information on identity theft, we suggest that you visit the web site of the California Office of Privacy Protection at www.privacy.ca.gov, or the Federal Trade Commission at www.ftc.gov/bcp/edu/microsites/idtheft. If there is anything TAD Gear can do to assist you, please email us at action@tadgear.com, a special email address that we have set up to help answer your questions.

On a going-forward basis, in order to help assure the security of your information, all users will be required to recreate their usernames and change passwords upon logging onto our newly redesigned, TAD Gear website. Please note that the password change process is only initiated when you come to the TAD Gear website and as a result an email is sent to you. Do not respond to any other unsolicited emails regarding password changes from TAD Gear. TAD Gear will not contact you by email regarding a password change unless you initiate such a change on the TAD Gear website in accordance with the instructions above.

We are sorry for any inconvenience that this might have caused you. We take the protection of our customers' personal information very seriously. TAD Gear is making additional, significant investments in enhancing the safety and security features on our website so that you may feel confident using it. While no company can completely prevent unauthorized access to data, we are committed to ensuring that our data is protected by the highest levels of security.

If you have any questions or need further information regarding this incident, please do not hesitate to contact us.


Please note that no replies will be available from the TAD Gear Staff in this venue for legal purposes related to our ongoing investigation with Federal Law Enforcement Agencies tasked with cyber-crime.

Thank you.

Belmont31R
11-18-09, 21:24
I was a victim of the SKD breach a few years ago.


Still to this day I do not understand why companies are keeping CC info online once the charge goes through. Its ripe for mass theft.

noops
11-18-09, 22:19
****in-a. I just bought a stealth from them. Great.

Edited: Looks like I'm safe since I used a Shopsafe credit card number.

Ummm...where is this coming from? I can't confirm it was hacked?

Edit again: Found confirmation on their facebook notes page.

Byron
11-18-09, 22:43
Ugh, I just placed an order with them in early October - it was my first ever order with them.

It's really bullshit that this notice wasn't actually sent out to people who placed orders.

I thank you for bringing this to the community here: sucks that I would have to hear this from a forum rather than straight from the horse's mouth.

It also sucks that more details aren't provided in the notice. When exactly was the breach? What do the suspicious charges look like that people have been seeing? When did they get these charges? Were all records accessed? Just some?

The more they tell people upfront, the less stress there would be.

As it stands, I see this as a pretty half-ass attempt though. The notice should be ON the main page. They should temporarily take down their goofy flash intro and you shouldn't have to click through a small text link on the main page to get to it.

SeriousStudent
11-18-09, 22:44
.....


Still to this day I do not understand why companies are keeping CC info online once the charge goes through. Its ripe for mass theft.

You can thank the credit card companies, not the retailers, for that policy.

If a customer disputes a charge, the retailer has to provide the credit card company with proof the transaction occurred as charged. This requires them to retain details such as the credit card number, expiration date (if applicable), etc.

I work for a REALLY large company, with a metric butt-load of credit card numbers locked up. Trust me, we would MUCH rather go to a system where the card approver gives us a unique transaction number or code. That way we have a transaction ID that can be verified, without storing your number.

It costs us millions of dollars a year to keep the data safe, thanks to your issuing card company.

And yes, I get a breach letter about once a year, just like the one the OP put up. And I do this crap for a living. :rolleyes:

SeriousStudent
11-18-09, 23:07
Ugh, I just placed an order with them in early October - it was my first ever order with them.

It's really bullshit that this notice wasn't actually sent out to people who placed orders.

I thank you for bringing this to the community here: sucks that I would have to hear this from a forum rather than straight from the horse's mouth.

It also sucks that more details aren't provided in the notice. When exactly was the breach? What do the suspicious charges look like that people have been seeing? When did they get these charges? Were all records accessed? Just some?

The more they tell people upfront, the less stress there would be.

As it stands, I see this as a pretty half-ass attempt though. The notice should be ON the main page. They should temporarily take down their goofy flash intro and you shouldn't have to click through a small text link on the main page to get to it.

I agree - handling a breach can be done better, in many cases. Several friends of mine make a living doing exactly that - assisting companies with this exact issue.

I am not defending or attacking TAD. But I am aware of several cases where the breach occured when the CCN data was accessed at the company's ISP, or at the credit authorization service.

That is precisely how a company that sells AR supplies was breached last year. They were an innocent victim - their network provider was hacked. The company itself did nothing wrong, but their credit card database was illegally accessed.

Honestly, this stuff is a freaking maze. There are some really talented law enforcement people working on it - USSS, Treasury, IRS, etc.

But there is more money made every year in computer fraud, than illegal drug sales worldwide. Billions and billions of dollars.

And many, many times the breach goes undiscovered until people start reporting that someone is using their PII (Personally Identifiable Information) to get credit in their name.

Get a credit monitoring service, and watch your credit reports and bank accounts like a hawk. I sure as hell do.

Spoon
11-19-09, 08:05
:eek: I just placed an order with them a few days ago

N4LtRecce
11-19-09, 08:13
As it stands, I see this as a pretty half-ass attempt though. The notice should be ON the main page. They should temporarily take down their goofy flash intro and you shouldn't have to click through a small text link on the main page to get to it.

I agree 100%. Besides, however cool the flash into might have been back in the 90's, it's pretty freakin' annoying now.

Spoon
11-19-09, 08:36
I just cancelled the card I used for TAD Gear. Luckily there wasn't any unauthorized charges on my account.

NeverForget
11-19-09, 15:17
Darn you guys beat me to it. I was about to post this up.

I couldn't agree more with you Byron. I posted a comment on their Facebook note regarding the situation saying how they should have, at the very least, sent out a mass email to all their customers. They obviously have all our email addresses. I'm going to shoot them an email about that as well. The only reason I caught wind of this was from it being posted on Soldier Systems. Ridiculous. Their response is a little too nonchalant if you ask me.

I got hit today for $348.99 by "EASYJET". No clue what that is but I subsequently canceled my credit card.

Best of luck to those effected.

redsox20
11-19-09, 18:08
Just tried to log on and I got this:

Temporary Closure:
Our site is under maintenance for upgrades and improvements. The shopping cart and customer login will be unavailable during this period.

While our website will be closed temporarily, you may still call us during our hours of operation, Monday thru Friday from 10:30am to 6:30 pm PST, to place an order or for any inquiries @ 866-613-1386. We apologize for any inconvenience while we make improvements to our website.

We will be back shortly and thank you for your support.