Credit cards used on cvsphoto.com may have been compromised
cvsphoto.com
cvsphoto.com
====
We have been made aware that customer credit card information collected by the independent vendor who manages and hosts CVSPhoto.com may have been compromised. As a precaution, as our investigation is underway, we are temporarily shutting down access to online and related mobile photo services. We apologize for the inconvenience and are working diligently to resume service as soon as possible. Your images are saved and you will have access to them once service to CVSPhoto.com is restored. Our in-store photo centers are not affected and remain in service. Film and disposable camera orders are being processed and your CVS/pharmacy will contact you when they are received.
Customers who provided credit card information for transactions on CVSPhoto.com are advised to check their credit card statements for any fraudulent or suspicious activity and to call their bank or financial institution to report anything of concern.
Customer registrations related to online photo processing and CVSPhoto.com are completely separate from CVS.com, optical.cvs.com, cvs.com/MinuteClinic on line bill pay and our pharmacies. Financial transactions on CVS.com, optical.cvs.com, cvs.com/MinuteClinic and in-store are not affected.
Nothing is more central to us than protecting the privacy and security of our customer information, including financial information. We are working closely with the vendor and our financial partners and will share updates as we know more.
For more information, call 1-800-SHOP-CVS.
====
It's useful because the steps a reader would need to take before being secure clicking through to a site identified in the submission title as "hacked" (I notice the title has been clarified since then) are non-trivial. I figured since I'd done them once, I might as well save additional folks the steps if they were just looking for the page contents.
Classic, pure classic. Obviously not.
http://krebsonsecurity.com/2015/07/cvs-probes-card-breach-at...
>Disclaimer 1: Plain Text Offenders Alert is not associated with plaintextoffenders.com, it uses their publicly available database.
Since then, I started to use Virtual numbers. It's a feature that generates a virtual credit card number that I am opting to use per vendor. Hopefully, this will expose the vendors that are leaking this sensitive information.
===
As a result of recent reports suggesting that there may have been a security compromise of the third party vendor that hosts Costcophotocenter.com, we are temporarily suspending access to the site. We take the security of our members’ data seriously, which is why we are taking this precautionary step. This decision does not affect any other Costco website or our in-store operations, including in-store photo centers.
This situation is affecting multiple online photo sites. We are diligently working to determine when we can re-enable the site, but in all likelihood that will not occur until the middle of August. We will update this statement when we have more information.
How do I know the hack was due to their incompetence? PR people need to come up with a better approach.
> security compromise of the third party vendor > collected by the independent vendor <...> may have been compromised
This is the case of "sorry for my friends, I'm doing the best I can", which is entirely different situation than "I accidentally slept with your best friend, but I value our relationship" kind of PR.
It's not like I want to cover up for cvsphoto.com. I just find it ridiculous that if I give my credit card info to N website than the risk that my credit card info get stolen and abused is O(N) instead of O(1).
If the thief is slick he / she may make small charges that you wouldn't immediately notice or at all if you're sharing the card with someone else (e.g. a significant other). It's also a HUGE pain in the ass.
I've had it happen when I'm traveling, and my primary card suddenly stops working. I always carry backups for this reason, but it's still disruptive and potentially embarrassing.
Also if I have a card on file for recurring payments or repeat orders, I have to go find all of those places and update it every time the card gets replaced. When it happens once, it's not so bad. When it happens two or three times a year, it's a headache. I finally took to having a single card that is used for ONLY recurring payments, with the hopes that it wouldn't get compromised and when the others do I wouldn't have to go through this whole exercise again. So far so good.
The bottom line is yeah, it doesn't cost me money, but it does cost me stress and time. I have better things to do with my time and energy than cleaning up after yet another compromise that happened through no fault of my own.
This is a sound plan. Kudos!
For non-recurring payments, I've taken this a step further: I use a debit card for online purchases backed by an account with just a few dollars in it. When I wish to make a purchase, I move the funds for that purchase into that account.
I would rather have a fraudulent purchase be declined than to deal with the hassle -however small- of disputing a charge.
Also most recurring billers use account updater so if your bank supports it, the billers will get the new card #.
That being said, my understanding as somebody with 15 years of working history in the online photo space is that PNI is the host and all of their major customers shut off so I can't imagine that PNI is very healthy right now. If I am mistaken and the individual sites (Rite Aid, Costco, Sam's Club, Tesco, CVS and Walmart Canada) actually store and manage the photos then the data is likely to be fine.
That also being said, never trust your photo storage to an online service even if you are paying for it. Photos generally don't take up that much space. You should have at least two copies on devices that you own if you don't want to lose them.
I think he meant in addition to online storage.