This company did not secure credit card information on their servers and our credit card was subsequently used without our permission and this company refused to compensate us for our time and trouble. Below is the email they sent to us which was our only notice (which was several months after the issue occurred):
Dear XXX,
We are very sorry to be writing to advise you of a vulnerability that
has been discovered in one of our web servers. We have determined that
an unauthorized party breached our database and gained access to
approximately 10% of our users who stored credit card information in
our database. Although we do not store the credit card security
code in our system, there is a possibility that your credit card number
was compromised and we want to let you know as soon as possible so you
can take the necessary action to prevent any fraudulent activity from
occurring.
We strongly urge you to contact your credit card company, inform them
that your card may be a target for fraudulent use, and determine with
them whether your card should be canceled or placed under a fraud
alert. In addition you should closely monitor your credit card
statement to check for any fraudulent activity.
As a result of this attack, we have added measures designed to thwart
any future attacks on our database as well as employed additional security
experts to scan our site at regular intervals for this and any new
vulnerability that may arise. We no longer allow
ListingDomains.com users to store credit card information for future
purchases and have moved all stored credit card data for RealEstatesites.com
users to a new platform that uses only state of the art encryption
algorithms. We are confident that the changes we have implemented
will prevent this type of breach from occurring again.
Please accept my sincere apology for this unfortunate situation. We
take your privacy and your trust very seriously and are committed to
protecting your information from unauthorized access at every juncture.
If you have any questions regarding this matter or need assistance,
please contact me by phone or email at 800.826.5123, 707.291.3763 or
http://us.mc1805.mail.yahoo.com/mc/[email protected].
|
|
|
Amanda Cornelius
Founder/ CEO |
|