<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: stedmans]]></title>
    <link>http://securityratty.com/tag/stedmans</link>
    <description></description>
    <pubDate>Sat, 22 Mar 2008 21:37:57 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Intrusion at Stedmans.com exposes credit card information]]></title>
      <link>http://securityratty.com/article/b843fad19d119230af985462a5bfdc22</link>
      <guid>http://securityratty.com/article/b843fad19d119230af985462a5bfdc22</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/10/08

Organization
Wolters Kluwer

Contractor/Consultant/Branch
Lippincott Williams &amp; Wilkins
Stedman's
Bixler Incorporated

Victims
Customers who...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wolters.jpg" align="right" height="45" width="201"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/10/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.wolterskluwer.com/WK/">Wolters Kluwer</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.lww.com/index.html">Lippincott Williams &amp; Wilkins</a> <br><a href="http://www.stedmans.com/">Stedman's</a> <br><a href="http://bixler.com/">Bixler Incorporated</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Customers who made online purchases from Stedman's between August 30th, 2007 and February 27th, 2008<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*There were 25 New Hampshire residents affected.&nbsp; The total number affected is expected to be much larger.<br></font><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, telephone numbers, email addresses, credit card numbers, expiration dates, and card verification numbers.<br><br><span style="font-weight: bold;">Breach Description:</span><br>"On February 27, 2008, Lippincott Williams &amp; Wilkins, a Wolters Kluwer business was informed by the company that hosts one of our websites, <a href="http://www.stedmans.com,">www.stedmans.com,</a> that personal information collected from consumers through the website may have been compromised through an unauthorized intrusion into the server that stores information from individuals who purchased products at our website."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/wolters.pdf">The New Hampshire State Attorney General breach notification</a> <a href="http://doj.nh.gov/consumer/pdf/wolters.pdf%3Cbr%3E%3Cbr%3E%3Cspan"><br><br><span></span></a><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>On February 27, 2008, Lippincott Williams &amp; Wilkins, a Wolters Kluwer business was informed by the company that hosts one of our websites, <a href="http://www.stedmans.com,">www.stedmans.com,</a> that personal information collected from consumers through the website may have been compromised through an unauthorized intrusion into the server that stores information from individuals who purchased products at our website.<br><span style="font-style: italic;">[Evan] The company that hosts stedmans.com is </span><a style="font-style: italic;" href="http://bixler.com/portfolio.cfm/Life%20Sciences/6">Bixler Incorporated</a><span style="font-style: italic;">.</span><br><br>The personal information that may have been comprised may include names, addresses, telephone numbers, email addresses, credit card numbers, expiration dates, and card verification numbers of individuals who made purchases at the site from approximately August 30, 2007 to February 27, 2008.<br><span style="font-style: italic;">[Evan] Storing card verification numbers is a violation of the Payment Card Industry (PCI) Data Security Standard.&nbsp; According to Requirement 3: Protect stored cardholder data, Section 3.2.1 "NEVER store the card verification code or value or PIN verification value data elements." and 3.2.2 "Do not store the card-validation code or value (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transactions"&nbsp; Stedmans.com was not compliant with the standard.&nbsp; Why wasn't the site compliant, and what vulnerability was exploited?</span><br style="font-style: italic;"><br>The company has contacted the three major national credit reporting agencies, and the company mailed a notice to consumers who may have been affected by this incident on March 10, 2008<br><span style="font-style: italic;">[Evan] It would be a better idea to contact Visa and Mastercard than it would be to contact the credit reporting agencies.&nbsp; If the information was limited to what was reported, then there is not a high risk of immediate identity theft (no Social Security numbers in particular).&nbsp; There is a medium to high risk of credit card fraud, which is much different.</span><br style="font-style: italic;"><br>We are working with our website hosting company on additional security measures for the Stedmans.com website<br><span style="font-style: italic;">[Evan] It would be a good idea to work with information security professionals (third-party review).</span><br><br>we have arranged with Equifax Personal Solutions to provide potentially affected consumers with an opportunity to enroll in the Equifax Credit Watch Gold identity theft protection product at no cost to them for one year<br><span style="font-style: italic;">[Evan] Again, this is not really an identity theft issue.&nbsp; It is a credit card fraud issue.&nbsp; Two related but different issues.</span><br><br>Lippincott Williams &amp; Wilkins is committed to maintaining and protecting the confidentiality of our customers' personal, private, and sensitive information. We regret that this situation has occurred, and we will be working to reduce the risks of a similar situation happening in the future.<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach certainly affects much more than the 25 New Hampshire residents mentioned in the breach notification to the New Hampshire State Attorney General.&nbsp; I am disappointed by appearance that stedmans.com was not VISA/PCI DSS compliant and the response that shows a misunderstanding of risks.&nbsp; Stedmans.com customers are mostly people in the medical field, so I am guessing that many of these credit cards have limits that exceed mine. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/23/wolters.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 22 Mar 2008 21:37:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit cards">credit cards</category>
      <category domain="http://securityratty.com/tag/equifax credit">equifax credit</category>
      <category domain="http://securityratty.com/tag/report credit">report credit</category>
      <category domain="http://securityratty.com/tag/stedmans">stedmans</category>
      <category domain="http://securityratty.com/tag/information security professionals">information security professionals</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/03/23/wolters.aspx">Intrusion at Stedmans.com exposes credit card information</source>
    </item>
  </channel>
</rss>
