Ask HN: Altrec security breach letter?
"Altrec was initially contacted by American Express concerning the fraudulent use of a small number of American Express cards that had been previously used at our Website. In collaboration with American Express, we engaged a leading forensic security firm to identify whether our systems had been compromised and to remediate any possible concerns. After a detailed investigation the forensic investigators could not locate any forensic evidence of a security breach. However, we discovered that your American Express account number, expiration date and four digit security code, and associated information (including your name and address) were being stored in our database. If our systems were illegally accessed or used in an unauthorized manner, your personal information could have been compromised sometime between June 2010 and March 2012."
Even though the letter says no evidence was found of a security breach, it goes on to say, "We've addressed the vulnerability found internally and by the forensic investigators, deleted all card information," and etc.
Now, the obvious remedy, if one believes a credit card has been compromised would be to identify the card, e.g., with the last four digits of the card number, so the cardholder could ask to have a new card issued and the card canceled. But oddly the letter does not suggest that, or identify the card in question, but instead goes on to offer a "complimentary one-year membership of Experian's ProtectMyID(TM) Alert."
It seems absurd that either Altrec or Experian would be engaging in a scare tactic mail-order campaign for an identity protection service. Nonetheless, the letter doesn't quite ring true.
It seems possible that people here involved with security issues are aware of the situation. Usually, potential security breaches like this are made public, but I can't find anything about this one.
Is this on the level?