Unless the attacker dumped them all (semi) publicly, the more likely explanation is that the breakin caused people to check their accounts and a statistically normal percentage of them showed fraud from another origin. But anybody who sees it will be sure to get online and find others in a similar situation.
Everybody would be doing themselves a big favor if they stopped treating CC info as the #1 scary OMG data theft. The banks programmed you to care because congress made sure they're liable instead of you. Theoretically you might owe $50 due to fraud but practically you never pay a dime. Sure it's a bit of a pain in the ass to get resolved, but it's not worth stressing about until it happens.
I'd be way more concerned if my hoster lost my contact info, ip logs and identity challenge questions & answers.
I contacted Linode support and they've said in clear terms that they have no evidence that payment information of customers was accessed. I initially signed up for Linode because my friends spoke highly of the tech people working at Linode. Right now amidst all the commotions it's ryan's words (some anonymous dude who joined #linode/irc.oftc.net) vs. an established company's. I'm just going to now stop worrying and get back to my work.
On an interesting note, the big target who actually incurred identifiable damage was seclists.org: http://seclists.org/nmap-dev/2013/q2/3
Well that's a first. They were very evasive about it earlier.
With this lack of transparency, I feel like I had no choice but to block my card.
> In addition, we have found no evidence that payment information of any customer was accessed.
The question isn't transparency, but trustworthiness. Either Linode is telling the truth, and this anonymous IRC person with a pastebin is trolling everyone, or Linode is lying (or alternatively, Linode is incompetent and simply didn't detect the CC access). At the moment I'm going with Linode is telling the truth, because honestly, am I going to believe an anonymous person on IRC over a company I do business with?
Secondly, if they hold that data, it's possible one day someone will find a security breach and will access that data. The best solution is to never hold that data.
Since I don't trust most of the systems I use AND Linode has not denied it holds that data... I'm more inclined to believe in this anonymous IRC guy and err on the side of caution.
If Linode had come out and said "Look, we don't hold your CC number in our database" then I think there would be very little reason to be concerned. However...