Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Data Leaks

November 21st, 2011, 13:05 GMT · By Eduard Kovacs

BBC America Shop Leaks Customer Orders

SHARE:

Adjust text size:


BBC America Shop leaked information of their customers
Enlarge picture
BBC's America Shop website encountered a problem that not only allowed their customers to see each others billing information, but also made simple Google searches take people to the sensitive information containing pages.

According to DataBreaches, one of the customers of the site noticed the issue while googling his own name in the attempt to investigate the reasons for the large number of unsolicited emails he was receiving.

One of the search results led to the page which contained his order, but even more worryingly, by manipulating the URL from the browser's address bar, he could take a look at the orders of other customers who'd placed them starting in June 2011.

Fortunately, there was no credit card information and the records were not cached by Google, but the names, billing addresses, phone numbers, item numbers and email addresses were more than enough for the customers involved to become targets of shady marketers.

Unlike other similar scenarios we've recently witnessed, where an organization's staff doesn't know how to handle data breaches and information security, in this case, the issue was immediately resolved, BBC America Shops call center employees being trained on how to handle such situations.

It's unknown at the time if BBC America Shop plans on alerting the individuals involved in the incident, but they should, since they're probably responsible for a large quantity of spam they must be receiving.

This is what most companies should do in case they're faced with such situations, not like in the case of the Melbourne University hack, where the hacker was asked if he was selling software after he reported a large number of vulnerabilities.

The massive number of websites currently on the web makes it really hard to make sure each one of them has a watertight security and that's why companies should implement policies that regard data breaches and the way they are handled.

TELL US WHAT YOU THINK:

1,070 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Anonymous Leaks Data From Hacked Law Enforcement Agencies

Anonymous Turns Green and Goes After Polluters

Fannie Mae Employee Leaks Details of 1,100 Individuals

16,000 Finns Affected by Data Breach

Lawrence Memorial Hospital Suffers Serious Security Breach

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM