by Mark Alker
March 17, 2011
As some of you may have seen across a number of different bike website forums, there have reports of some kind of card fraud which has been linked with Chain Reaction Cycles and purchases from its site .
We’ve been in contact with CRC regarding the accusations and they have told us that they are taking the matter seriously and going through every conceivable process to ascertain whether there is a problem with either their internal systems or that of an outside provider. Currently nothing has been found.
Here’s CRC’s statement from our own forum
Just want to give you an update as you may have missed our earlier statements.
What do we know?
We know that some of our customers have experienced credit card fraud after placing an order with CRC.
When did we find out?
Senior staff in CRC were alerted to forum comments on Sunday 6th of March. We immediately began our investigations enabling [us] to release information via community forums on Wednesday the 9th, acknowledging that we were actively investigating the situation.
How big is the problem?
So far, we have been contacted by customers who purchased in February and the beginning of March. The contacts we have had both directly and via forums equates to under 0.1% of on-line orders placed In that same time period. However, we understand that for those effected this is of great concern and as we take our customer’s security extremely seriously we are taking all the steps we can to understand what has happened.
What steps have we taken?
CRC has employed one of the UK’s leading internet security companies to carry out immediate and full forensic investigation into CRCs infrastructure. This investigation has so far uncovered no evidence of any breach. We are also fully engaged with our card processing companies and the card schemes. This investigation is still underway.
Purely as a precaution, Card Issuers may make the decision to reissue new cards to recent CRC customers. If your card is reissued it does not mean that your details have been compromised but the banks take an ultra cautious view on this as the cost of re-issuing a card is much smaller than resolving any potential issue in the future.
When will CRC have more information?
We are working round the clock to get an understanding of what has happened; as we get greater understanding we will continue to keep you up to date and intend to issue a further updates over the next week or so.
Can you order safely?
So far the investigation has uncovered no evidence of any breach but if you want to order on CRC without CRC being in contact with your credit card details then choose Pay by PayPal and checkout using your credit card via the PayPal express checkout.
Please contact us directly
We want people who have been directly affected to contact us so we can personally update you by email. Please contact us on +44 (0)2893343758 between 9am – 5.30pm or email firstname.lastname@example.org and we will be glad to help you.
Thanks again for your patience and support
CRC Senior Management
Singletrackworld forum thread is here
If you’ve got any comments, it’s probably better to join in on the existing thread than to add them here, or start a new thread.