interesting to see another on line retailer's handling of a similar (although not payment detail related) situation:
Bike Forum
CRC security issues?
-
Posted 1 year ago #
-
I don't like this at all, who ever is behind this is very organised and effective, this will force a lot of business paypals way.
If this happens to more large companies in high profile cases, certain individuals stand to make a lot of money.
Best thing is to simply watch what happens and if you don't have paypal and it's secure, set it up!
Posted 1 year ago # -
Anyone else?
Posted 1 year ago # -
Me too, £800 Tesco.com and 2 lots of £15 on o2, plus £250 to some Paypal account. 9 days after CRC purchase no other action on the card.
Posted 1 year ago # -
play.com have shown crc the way when it comes to handling a security breach. They immediately sent an email warning of the issue and giving details of exactly what had happened. The only info I have received from crc is 1 vague email sent over a week after they were first aware of the issue.
Have they resolved the problem? Is it safe to shop there again? I have no idea so I've just started shopping at Wiggle instead.
Posted 1 year ago # -
I'm not sure why these retailers are holding card information anyway. PCI-DSS is the security standard for merchants and is a reasonably onerous and painful process. Best way for online is to include a payment gateway to a provider that has to deal with all these issues - yes you retain customer info but nothing to do with payments. That's what I always recommend to my clients as while its not bargain basement it does mean the risk is moved to somewhere else which is always nice
Posted 1 year ago # -
I'm not sure why these retailers are holding card information anyway.
It wasn't even an option for us when we set up our site 15months ago.
Simply not allowed to see details and being a scottish company we are not allowed to store them either if we were.
WorldPay deal with all that number stuff and we get a thumbs up or down and an address confirmation to send the goods ordered. Seems pretty safe all in.
Posted 1 year ago # -
well, Play.com have done a reasonable job but not in a terribly timely manner;
We believe this issue may be related to some irregular activity that was identified in December 2010 at our email service provider, Silverpop. Investigations at the time showed no evidence that any of our customer email addresses had been downloaded.
So they knew for 3 months there'd been a security issue and hoped it hadn't affected them.
Posted 1 year ago # -
starsh78 - Member
I'll stick with wiggle,
Babyjack - Member
................Is it worth me mailing CRC..or don't they care??
Wiggle/Merlin for me in future
stuboy2uk - Member
Have they resolved the problem? Is it safe to shop there again? I have no idea so I've just started shopping at Wiggle instead.
You guys do realise - of course - that Wiggle were the centre of similar allegations last time something like this surfaced don't you?
Posted 1 year ago # -
Wiggle were the centre of similar allegations
and frankly did a worse job of managing the situation than CRC.
Wiggle's 'PR' seemed to consist entirely of saying 'not us' and waving lawyers at sites where anyone posted anything to the contrary.
To CRC's credit, they've not shut this thread, or others like it, down.
Posted 1 year ago # -
I wasn't aware of that.
*Goes back to CRC*
Posted 1 year ago # -
No public update from CRC since 17 March? Nothing on their website that I can see.
thebikechain - we use WorldPay as well - seems like a good option.
Posted 1 year ago # -
Maybe it will all turn full circle, and we'll start visiting those buildings in our towns called shops.
I used crc right after this thread started (hadn't read it) and so far touch wood nothing dodgy 'appears' to happening with my bank account. I hope I haven't spoken too soon
Posted 1 year ago # -
Hi Folks,
Since our last communication, we have continued to carry out a full forensic investigation following recent reports and concerns from our customers experiencing credit card fraud after placing an order with CRC.
The independent forensic investigation has shown that our infrastructure was the target of a sophisticated attack which resulted in the theft of card details relating to a number of our customers. Details were being stolen ‘real time’ and only a small proportion of recent CRC customers were affected.
Recent customers of CRC may find that, as a precaution, their credit card company will issue a new card. Be assured that if this does occur it does not indicate that your details have been compromised.
The access point of the theft has been identified and permanently closed off so we are confident that we have fully addressed any weakness in our infrastructure.
We are sincerely sorry for what has happened in recent weeks and would like to thank you for your patience and support throughout this difficult period.
Our site is safe to use and will be continually monitored and tested by independent on-line security experts to ensure your details are safe.
If you have further enquiries about this issue please contact us on +44 (0)2893343758 between 9am – 5.30pm or email enquiries@chainreactioncycles.com and we will be glad to help you.
Thanks again for your patience and support,
Michael Cowan
CRC Senior ManagementPosted 1 year ago # -
Thanks for that Michael, the explanation is appreciated
Posted 1 year ago # -
Can you go into more detail about this man in the middle attack?
Posted 1 year ago # -
I've had a fraud attempt on my card. Yes I have used it to buy from CRC (early March, I think was the last time), they attempted to buy something off ebay with it. It's buggered up my 3DS pre-order
Posted 1 year ago # -
I haven't read all 21 pages, so apologies if I'm rehashing something that has already been covered.
It seems CRC have conceded that their systems have been compromised. So, why is the first I hear about this a call from my Bank's fraud prevention dept? Shouldn't CRC to warning the "small proportion of recent CRC customers" that they should be being extra vigilant for any fraudulent activity with their credit card?CRC will need to go that extra mile if they are to regain my trust. There are plenty of alternative places I can shop.
Posted 1 year ago # -
Let's hope the security experts have crawled all over the site looking for further weaknesses. I expect they are very expensive, but clearly worth it.
Posted 1 year ago # -
Seems to me that CRC is behaving very properly and I for one really appreciate them posting updates on here.
Posted 1 year ago # -
need to bring their prices back down again eh
started looking elsewhere now,
Posted 1 year ago # -
I didn't get hit as I use paypal with CRC but I really do appreciate CRC's latest response which seems pretty honest - Good on you and a lesson in how much better it is to do this rather than deny, deny, deny as per the other big online retailer mentioned just above.
Any online retailer can be hit - the fact is there's no such thing as totally secure - and I hope that this episode now means that CRC will be taking this even more seriously than hopefully they did already. It would be good to know what measures (organisation, process, etc rather than specific technical things) are being taken to try and minimise the risk of it happening again.
Posted 1 year ago # -
Whenever they say forensics i always think the computer guys will be wearing those white suits...
Good to see they admitted there was a problem, rather than just deny it. Shame i have no money to buy anything at the mo.
A discount voucher for those of us affected would be nice, seeing at is was such a low number of us
Posted 1 year ago # -
I'm not happy at all with that explanation. I want more details about how card data was obtained and what measures have now been put in place to prevent reoccurance before I trust crc with my card again.
Posted 1 year ago # -
I think what Michael has said is fine - there was a problem, it's resolved and they're keeping an eye on it. Fair play to CRC for not supressing the whole thing and, in time, admitting there was a problem and now confirming it's resolved.
The bloke from their software house who started blaming the victims needs ot be fired, though.
Any expectation that someones goign to publish full details of how their site was hacked is pie int he sky - anyone using the same software is goign to be equally as vulnerable and there's nothign to be gained by detailing what steps have been taken - it only gives any future hackers something to work with.
Posted 1 year ago # -
clubber - Member
Many online retailers pay to have all of this carried out by a 3rd party (such as WorldPay). I'd trust the professionals to get it right.
Any online retailer can be hit - the fact is there's no such thing as totally secure -Posted 1 year ago # -
Does this mean it ok to visit 'dodgy sites' now they are not to blame?
Posted 1 year ago # -
Yeah, like that was going to stop you
Posted 1 year ago # -
Card cancelled as a matter of course...
May or may not be real, but I'm happy to ditch the card I used on their site in the past month and get a new one - good risk aversion.Interestingly I want to buy a load more kit from the site. Perhaps paypal is the way to go...
Posted 1 year ago # -
NZCOL has it.
Not all organisations can hand off CC data (we don't in the main part), but I can testify to PCI-DSS being pretty thorough. We adhere to it, and are audited on it regularly.
And whilst it won't stop your min-wage person stealing the odd card details it does a credible job of preventing bulk theft (as it's designed to).
I wonder if CRC is PCI Compliant? Anyone asked?Posted 1 year ago # -

Nothing like a well placed ad
Posted 1 year ago # -
That's for the fraudsters...
Posted 1 year ago # -
Won't name names, they'll be reading this...
But let my bank know of this thread (post cancelling my card as above) and risk, got a phone call back to say thanks and being handed over to CC fraud dept.
Nice warm feeling at mo for my bank.
Posted 1 year ago # -
21st march £648.27 debited to flight centre in london a week after a transaction from CRC
. Not what i wanted to wake up to in the morning.
Posted 1 year ago # -
DIrty thieving gypsy scumballs
How do you know they're gypsies?
Unwashed, maybe. Thieving, definitely. Scumballs, certainly. But I'm not quite sure how you can ascertain their race from these factors
Posted 1 year ago #
Reply »
You must log in to post.

