carmudgeons.com  

Go Back   carmudgeons.com > Automotive Forums > Car Talk

Reply
 
Thread Tools Display Modes
Old 06-27-2014, 11:14 PM   #1
Terri Kennedy
There and back again
 
Terri Kennedy's Avatar
 
Join Date: Oct 2003
Carmudgeonly Ride: 2003 BMW 325xiT; looking for a new fun car
Location: New York
Posts: 2,939
Ever order anything from getbmwparts.com (or other automotive web sites)?

If so, bad guys may have your credit card number, even if you didn't tell the web site to save it.

I just got a (paper) letter from MileOne Automotive, which operates the getbmwparts.com and subarupartsdepot.com, stating that their web hosting contractor, trademotion.com, was hacked and information downloaded between March 5th, 2014 and May 17th, 2014, and that the information included name / address / email / phone / credit card.

MileOne is offering free 12-month credit monitoring by Experian to affected customers.

The only other TradeMotion customer to have posted a public notice is AutoNation.

However, TradeMotion provides some / all services for MANY other automotive web sites, such as GM Parts Direct. Just enter something like "trademotion honda" into Google to see how deep their tentacles run.
Terri Kennedy is offline   Reply With Quote
Old 06-28-2014, 11:36 AM   #2
equ
Alphanumeric
 
equ's Avatar
 
Join Date: Aug 2005
Carmudgeonly Ride: 981S, 340i
Posts: 9,584
Oh man, I did use getbmwparts/trademotion a bunch of times, but not sure if it was in that period.
equ is offline   Reply With Quote
Old 06-28-2014, 12:07 PM   #3
kognito
older fart than ZBB
 
kognito's Avatar
 
Join Date: Oct 2003
Location: On the road again
Posts: 8,900
should not effect me, but thanks for posting this Terry
__________________
2017 GMC Sierra 1500 SLE
2020 Fusion Titanium
kognito is offline   Reply With Quote
Old 06-28-2014, 12:42 PM   #4
clyde
Chief title editor
 
clyde's Avatar
 
Join Date: Oct 2003
Posts: 26,599
Quote:
Originally Posted by Terry Kennedy View Post
If so, bad guys may have your credit card number, even if you didn't tell the web site to save it.

I just got a (paper) letter from MileOne Automotive, which operates the getbmwparts.com and subarupartsdepot.com, stating that their web hosting contractor, trademotion.com, was hacked and information downloaded between March 5th, 2014 and May 17th, 2014, and that the information included name / address / email / phone / credit card.
Quote:
Originally Posted by equ View Post
Oh man, I did use getbmwparts/trademotion a bunch of times, but not sure if it was in that period.
As I read Terry's post, I took it as the breach occurring during the 3/5-5/17 timeframe and put everyone that had used trademotion knowingly or not) at risk because they were saving everyone's credit card regardless of stated preference. So, if I had ordered something last year and told it to not save my credit card, I would still be at risk.

Then I read equ's post and was going to say, "that's not what he said," but I did a little googling for everyone and found AutoNation's letter to the Maryland AG abotu the breach.

Quote:
Originally Posted by Autonation
...[c]riminal hackers were able to unlawfully access certain credit card information as it was being entered into their systm during the period from March 5, 2014 to May 2, 2014.
Included in the letter are two examples of the form letters they sending to affected customers which doesn't quite say the exact same thing. The differences between the examples are the specific AutoNation stores.

Quote:
Originally Posted by AutoNation
...[c]riminal hackers were able to unlawfully access certain credit card information on TradeMotion systems.
Whether the breach only included CC#s as they were entered or if it included any stored CC#s seems like a major point that should be clear, but it's not as clear as it should be.
__________________
OH NOES!!!!!1 MY CAR HAS T3H UND3R5T33R5555!!!!!!1oneone!!!!11

Team WTF?!
What are you gonna do?
clyde is offline   Reply With Quote
Old 06-28-2014, 02:58 PM   #5
ZBB
Relic
 
Join Date: Oct 2003
Carmudgeonly Ride: A very fast golf cart
Location: The Valley of the Sun
Posts: 12,821
As some of you know, I work with credit cards, although not indirectly.

I'm routinely alerted by our card vendor of specific cards that have been breached someplace. Sometimes its 2-3 cards, other times its thousands.

This problem is huge. We're using a card system developed in the 70s (with authorization networks updated in the 90s). Too many open areas to keep it secure.

Hopefully the US is finally on the path to moving towards chip an pin... When the UK implemented chip and pin in ~'06, they saw a 98%+ drop in fraud within 30 days. Since chip & pin cards work by forcing a 3-way match of the pin (stored on the card, stored on the authorization network, and provided but the cardholder), the only weak link becomes the cardholder. Any un-match causes the transaction to fail (I believe the user gets up to 3 tries before the card is locked...)
__________________
ZBB
ZBB is offline   Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Autox sites closing..... Sharp11 Going Faster 7 04-16-2007 06:03 PM


All times are GMT -4. The time now is 09:59 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Forums © 2003-2008, 'Mudgeon Enterprises - Site hosting by AYN & Associates, LLC