The personal info of what could be Instacart customers is being sold online
buzzfeednews.com
buzzfeednews.com
If you use Instacart to buy from Costco, be aware.
Tag some tech reporters as well for extra fun.
It might be worth sharing with a journalist; potentially the author of the linked article?
We shouldn't have to depend on publicity and shame to force a company to be careful with our data, we should have a neutral agency that investigates every report equally and is able to hand out fines for those companies that don't take our privacy seriously.
(I mean, California is on the right track)
I've tried escalating this with them multiple times, each time they insist that I won't receive any more emails, until the next one arrives. I also tried threatening them with taking it up with whichever authority is relevant if they don't fix it and reminded them about the 20m Euro or 4% of global turnover fine they could incur, yet still keep receiving this poor saps information.
[1]: https://autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/c...
[0]: https://www.t-mobile.nl/Global/media/pdf/privacy-statement.p...
> [A bank's] CS department is scored on number of tickets resolved per hour, and each rep’s incentives are simply to classify you as something requiring no followup and get you off the phone. [...] The legal department (or an analogous group – it is different at every bank) is not scored on cases resolved per week. They are scored on regulatory incidents per quarter, and their target for success is likely zero. Shockingly senior people will be involved to avert regulatory incidents.
src: https://www.kalzumeus.com/2017/09/09/identity-theft-credit-r...
Regardless, it's a very different problem to a bug introduced by the company that leaks customer information.
I think the initial communication is obviously not the fault of the company, but as soon as they are aware and refuse to put right the situation, I think they are very much at fault.
- Full name
- Date of Birth
- Some kind of National ID number
- Bank account details
- Address
If I was of a lesser moral character I'm sure I could have been very naughty with that information.
https://gdpr-info.eu/art-16-gdpr/
The initial issue is probably not a violation of GDPR, and not a reportable data breach. However, not fixing the issue after it was brought to their attention is more likely to be a violation.
The next day I had 6 charges from 2 Fry's in the area of where I was the day before, totalling about $550 at stores I had never been to (and did not appear as instacart charges like they normally would). My bank gave me a fraud warning when they tried to use an atm. I still had the card in my possession. I reported it to Instacart and never got a response. My bank was able to reverse the charges as fraud though, fortunately.
So I don't know how, but at least 1 rogue instacart delivery people was able to get my atm card information and misuse it. If not, the coincidence that accounts for all the evidence is astronomical.
I keep a pre-paid credit card that i will occasionally refill for stuff like this. I keep my actual banking 2-3 steps away from anything online.
All charges go through a credit/charge card (usually amex).
If im particularly skeptical or its a company that requires card info for something that shouldnt (like some intro/free trial) i just use a prepaid card with a minimal amount im willing to lose.
Adorama is a legit store, they've been around for 25+ years.
I've purchased from Adorama in the past without issues and you can call their salespeople for advice, which is unlikely with Amazon.
that service only works because they become the credit card processor and get to pocket the card fee...
If you use Instacart app to order items from Costco the price is actually different. I guess using Costco.com I have my membership benefit.
What is the meaning you are trying to convey here? Genuinely confused by this sentence.
I think "I can care less" is meant to mean "I can care less than most people do, because it doesn't matter to me".
Is this supposed to a be rhetorical question or are you genuinely unable to use Google to discover simple facts?
If I was an Instacart customer, I'd feel a lot more comfortable with a preliminary "we're aware and looking into this" statement from Instacart directly as opposed to doing nothing and telling the press that they don't know anything.
When a data dump like this hits the dark web, are companies even legally obligated to look into it?
Instacart has not yet reported this breach to the California attorney general, like they're supposed to.[2] There's a long list of companies with data breaches there.
[1] https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
If it’s a leaked-passwords attack used to compromise an unknown number of accounts that had insecure passwords, is it possible for Instacart to prove a breach occurred to the degree necessary to trigger the notification requirement?
Is it even a breach at all, in that scenario? How is Instacart at fault?
Is it necessary to integrate with haveibeenpwned to avoid having to publish a new breach notification every day that at least X accounts with an insecure password are accessed without consent? Is this requirement codified in law, or must each business discover it the hard way?
Not certain about what is legally expected however.
Tools like haveibeenpwned typically rely on companies' cooperation to report breaches since "data breach" is a legal term. But since Instacart still hasn't reported this, do the security tools get updated in a timely way, or are there millions of credit cards and passwords sitting up for sale while lawyers figure out how to handle the legal side of this?
https://www.rsaconference.com/usa/us-2020/agenda/human-dimen...
His talk covers a lot of active defense techniques, and goes over some legal points in this area.
Link to the specific section, "Reacquiring Stolen Data": https://youtu.be/CNonofF0_lw?t=2177
It feels to me that a few people got phished, and their accounts are being sold as proof. The rest could just be fake.
(Or, there was a hack, and Instacart handled it badly!)
In fact, my understanding is that generally buying a known ill-gotten item is illegal even in meatspace. Does it having originally been yours change that?
It was interesting because I'd worked at a startup, which used data from the people CSID had hired and that startup was acquired by Experian. At the startup we'd concluded this work was toxic and it'd be crazy to touch the company, we ensured the arrangement was completely at arm's length yet less than ten years later a huge public company felt it was OK to just buy the whole thing and swallow it.
At this scale you'd expect to find clear evidence it was Instacart users e.g. an account with email address dave+instacart@davesdomain.example. If there's nothing like that in the data then it's immediately suspicious, a small site might just not have any users with such breadcrumb trails in their email but a big dump like this should statistically have something because there are lots of people (including me) using a breadcrumb for every account.
This is how I know for sure that one of the banks I used years ago lost all their customer email/ name data even though they denied this at the time when it was news. I get scam emails to the address I gave them even now.
You'd also expect a company that cares about its users data to have plausible looking "watermark" accounts that trip alarms and so they'd be able to confirm this is their data. Even, if they did a proper job, what the source was (e.g. if you send a subset of data to a partner organisation you can add more watermark data and that lets you know if the data is stolen from that partner)
1. Crooks are lazy. Actually humans are lazy and crooks are human, but even more so criminal activity doesn't tend to come with any quality control. Even obvious data cleanup like fixing escaping often isn't done, because there's no incentive.
2. Breadcrumbs tend to be obvious to a human but a variety of schemes might be employed which means automation to strip them would need to be relatively sophisticated or it'll miss many of them. I used to use breadcrumbs of the form emanniamodXX@my-breadcrumb-domain.vanity.example where XX is two digits signifying when I updated this email address, like maybe 14 means May/June 2009. A human can stare at that address, see it says domainname backwards and realise it's a breadcrumb. But a trivial regex match will miss it.
This is about as serious a breach as it gets. To have (or claim) zero knowledge of it is pretty bad.
If the details of the story are correct, it would imply the attackers had full database access. I would not be surprised to learn the attack vector was gaining a privileged user's credentials, similar to the Twitter hack.
I don't think they're claiming zero knowledge. They're doing the exact opposite: they're saying they have complete knowledge, and that it simply didn't happen. I hope, for their sake, that they are correct.
You can’t prove a negative very easily.
Possibly a password leak from another site resulting in a targeted large-scale account access to download customer data from a leaky API? (Baseless commentary.)
Then if people do that, wonder if they also try to signup people? That would explain things maybe... Like some sites don't verify emails for signups, had someone sign me up for Spotify on an email of mine, when I don't have an account using that email. Never verified the email but got login notification emails... I reset the password and deleted the account.
Then I get emails saying they are from Anna at Netflix wants to chat with me "If you’d like to chat before you start your subscription"... Idk if they like typed in my email and never finished signing up or what but creepy... I have heard some sites log uncompleted signups even if you never clicked submit.
Kinda makes me wonder if these people selling breach data sets would sign people up too then if it's a email someone used elsewhere, to bulk up the numbers of users in their so called breach by adding newly created accounts, along with valid email/passwords harvested from other breaches. Then probably an inflated number would make their dataset be worth more money to people trading the datasets on the dark web I'd guess.
I sent an email to legal@ demanding my account be removed and to follow up that it had been done. The support emails stopped but I never heard from Instacart.
Edit: added “very likely;” clarity.
I must've send close to 50 of these emails to different companies / services I've used in the past. My request was always the same; a dump of my data, removal of my account and confirmation that my account was removed. To nobody's surprise, I never received a response to any of these requests.
/s (kind of)
Use coupon code HACKERNEWS for 25% off your first order. We have a contactless delivery option at checkout if needed.
P.S. I'm the CTO and Co-Founder, if you need anything or have questions, email nick@ourharvest.com, or check out my GitHub at https://github.com/niftylettuce