NYC bus tour company's database hacked of credit card info

The credit card details belonging to customers of CitySights NY were stolen when a database belonging to the sightseeing bus tours company was hacked.

How many victims? Approximately 110,000.

What type of personal information? Names, home addresses, email addresses, credit card numbers, expiration dates and CVV2 numbers.

What happened? Thieves exploited a SQL vulnerability to access a database on the company's web server. The hackers launched the SQL script on Sept. 26 and gained access to the database until Oct. 19. Six days later, a web programmer discovered the exploit.

What was the response? CitySights NY notified affected customers and provided them with one year of free credit monitoring and identity theft protection services. In addition, victims received a coupon good for 50 percent off select tours. They were told to purchase online, using the code of "012345."

The company has taken steps to improve its security posture, including tightening password use, closing database vulnerabilities, deploying an application firewall and conducting penetration tests.

Quote: "The company continues to monitor its systems and has reconfigured its systems so that transactions will be processed without storing credit card data on the company's servers," wrote attorney Theodore Augustinos in a letter to the New Hampshire attorney general's office.

Source: Letter to New Hampshire attorney general's office, Dec. 9, 2010.

close

Next Article in The Data Breach Blog

Advertisement

How to Prevent Insider Threats!

POLL

More in The Data Breach Blog

Hackers raid Washington state court system to steal 160,000 SSNs, 1M driver's license numbers

Hackers raid Washington state court system to steal ...

After the public website of the Washington state Administrative Office of the Courts was compromised in February, an investigation revealed the severity of the breach in April.

Personal California birth records found in "unsecure" location

The California Department of Public Health announced that the data included names, addresses, Social Security numbers, and medical information.

Investment regulator loses portable device containing personal data

Although the specifics of the lost information is unknown, the Investment Industry Regulatory Organization of Canada has announced that 52,000 clients of 32 brokerage firms have been affected.