Batteries.com hacked

Personal information of customers was exposed and potentially used in identity crimes after a malicious hacker gained access to the server of online battery retailer, Batteries.com for several weeks.

How many victims? Unspecified.

What type of personal information? Names, addresses and credit card information.

What happened? The hacker gained access to the server on February 25; access was diminished “significantly” around March 17 and terminated on April 9.

Batteries.com learned of the breach on March 13 because a customer reported to the company potentially unauthorized activity regarding a credit card account. A “small” number of additional Batteries.com customers have contacted the company to report similar potential credit card fraud.

Details: Batteries.com had firewalls and antivirus protections in place at the time of the incident.

What was the response? The company launched an investigation with internal and external forensic experts to determine what happened. In addition, the company put measures in place to prevent similar incidents from occurring in the future, including limiting the amount of information stored and decreasing the time period it’s stored for.

Batteries.com is working with the U.S. Secret Service and law enforcement to identify those responsible. The major credit card companies (i.e., American Express, Discover, Mastercard and Visa) have been notified.

Affected individuals have been offered 2 years free credit monitoring.

Source: Batteries.com, “A message from batteries.com."
close

Next Article in The Data Breach Blog

Advertisement

How to Prevent Insider Threats!

POLL

More in The Data Breach Blog

Hackers raid Washington state court system to steal 160,000 SSNs, 1M driver's license numbers

Hackers raid Washington state court system to steal ...

After the public website of the Washington state Administrative Office of the Courts was compromised in February, an investigation revealed the severity of the breach in April.

Personal California birth records found in "unsecure" location

The California Department of Public Health announced that the data included names, addresses, Social Security numbers, and medical information.

Investment regulator loses portable device containing personal data

Although the specifics of the lost information is unknown, the Investment Industry Regulatory Organization of Canada has announced that 52,000 clients of 32 brokerage firms have been affected.