Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Data Leaks

December 21st, 2010, 09:57 GMT · By

Credit Card Breach at New York Sightseeing Company Affects 110,000 People

SHARE:

Adjust text size:


CitySights NY notified its customers of credit card breach
Enlarge picture
CitySights NY, a company organizing sightseeing tours in New York, notified 110,000 former customers that their credit card details were compromised after unidentified individuals hacked its website.

In a letter [pdf] to the New Hampshire Attorney General's Office, Twin America, CitySights' parent company, revealed that the security breach was the result of an SQL injection attack.

The intrusion occurred on September 26, when hackers exploited a SQLi weakness to upload a backdoor script on its Web server.

The company learned of the compromise on October 25, when a Web programmer spotted the unauthorized code and alerted his superiors.

Twin America notified the FBI and contracted outside experts to investigate the extent of the breach. It was determined that attackers obtained access to the customer database.

Compromised information includes customer names, addresses, emails, as well as credit card numbers, expiration dates and CVV2 security codes. Social Security or drivers' license numbers were not exposed.

The company is offering all affected individuals a one-year free subscription to credit monitoring and theft insurance services from Experian. A 50% discount coupon for one of its tours was also sent along with the notification letter.

Following the breach, Twin America strengthened the security of its infrastructure. Taken measures include changing all administrative passwords and increasing their complexity, restricting access to the server's admin panel to a limited number of IP addresses, identifying scripting vulnerabilities and fixing them, installing a Web application firewall and having an independent penetration test done.

Even though free credit monitoring services are available, we advise affected customers to cancel their credit cards and obtain new ones. Recent reports suggest that cybercriminals can wait over an year before abusing stolen financial information, precisely because they know people monitor their statements following a breach.

TELL US WHAT YOU THINK:

1,419 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Shell Vacations Investigating Credit Card Breach

Credit Card Details Stolen from ECS Learning Systems Customer Database

WellPoint Sued by the State of Indiana over Late Breach Notification

New Credit Card Fraud Technique Proves Hard to Detect for Banks

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM