Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 21st, 2011, 16:58 GMT · By

Popular UK Handmade Cosmetics Firm Hit by Credit Card Breach

SHARE:

Adjust text size:


LUSH Cosmetics announces credit card breach and website compromise
Enlarge picture
LUSH Cosmetics, a UK company selling handmade cosmetics products, warned customers about a credit card breach after its website got hacked.

In an announcement posted online, the company said that after discovering the compromise and patching the hole, the website was placed under full-time security monitoring.

Because there was still evidence of attackers trying to break back in, the cosmetics vendor decided to pull the plug on the old website and create an entirely new version.

Unfortunately, there is reason to believe the site has been compromised since the beginning of October and that customer credit card details were stolen.

"For complete ease of mind, we would like all customers that placed ONLINE orders with us between 4th Oct 2010 and today, 20th Jan 2011, to contact their banks for advice as their card details may have been compromised," the company wrote in an email notification sent to affected individuals.

In an unusual move, the cosmetics vendor decided to address the hacker, although in an ironic manner. It praised his "formidable" talents and said it would offer him a job if his morals wouldn't be incompatible with those of its customers.

LUSH also tried to lighten up the spirits by posting a video showing Muppet-like lemmings singing and dancing. The clip was met with mixed reactions by customers.

Reading through the comments left on its YouTube and Facebook pages, it's clear that some people have been affected by the breach and had money stolen from their accounts.

However, aside from announcing the actual compromise and instructing people to contact their banks, LUSH did not provide any other details, like if the incident is being investigated by specialists.

It did mention however that an interim website will be up shortly and will only accept payments via PayPal until the new secure version is created.

TELL US WHAT YOU THINK:

1,065 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Infected Laptop Leads to Data Breach at Pentagon Federal Credit Union

Credit Card Breach at New York Sightseeing Company Affects 110,000 People

Shell Vacations Investigating Credit Card Breach

Credit Card Details Stolen from ECS Learning Systems Customer Database

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM