Forum menu
Might want to reset...
 

[Closed] Might want to reset your wiggle password...

Posts: 4064
Full Member
Topic starter
 
[#11251890]

https://road.cc/content/news/wiggle-hackers-obtained-customer-logins-externally-274571


 
Posted : 16/06/2020 4:24 pm
Posts: 21643
Full Member
 

Again?


 
Posted : 16/06/2020 4:29 pm
Posts: 11846
Full Member
 

Think I might have got lucky, went to check and couldn't log in!

Password reset worked, and no dubious transactions to worry me (although wish I could claim it wasn't me who had ordered the DHB glasses, save me the bother of returning them...).

Annoyingly I have never deliberately saved a card on the site but there was one there in my saved cards anyway. Deleted it but really wish it wasn't the default to save a card to the site...


 
Posted : 16/06/2020 4:29 pm
Posts: 13594
Free Member
 

Good reminder.

Just deleted all our cards from the account and reset my password!

Will just use Paypal in future....


 
Posted : 16/06/2020 4:32 pm
Posts: 27603
Free Member
 

Look on the plus side, this is the perfect time to tell your wife some asshole hacker ordered a new bike through your hacked account that'll turn up next Friday

๐Ÿ˜‰

Password changed.


 
Posted : 16/06/2020 4:34 pm
Posts: 433
Free Member
 

Reading the article, it doesn't look like wiggle have been hacked - just that someone has done a credential spraying attack on their site using credentials from other breaches?

Still, reinforces why unique passwords for each site are important.


 
Posted : 16/06/2020 4:36 pm
Posts: 2237
Free Member
 

Does this apply to the CRC arm of wiggle as well?


 
Posted : 16/06/2020 4:36 pm
 mehr
Posts: 737
Free Member
 

Reading the article, it doesnโ€™t look like wiggle have been hacked

Imagine taking the time to read past the first two words of a headline, instead of rushing here claiming wiggle have been hacked


 
Posted : 16/06/2020 4:38 pm
Posts: 13865
Free Member
 

Yeah, I removed all my cards form them the first time they messed up. Strictly PayPal only.


 
Posted : 16/06/2020 4:39 pm
Posts: 6859
Free Member
 

CRC seem to operate as an entirely separate business (different login accounts, different component selection, different prices etc), despite being owned by the same people.

I got confused recently though, when you use PayPal through CRC, it gets processed as coming from Wiggle.

I recently went through all my online accounts (all 200+ of them which are saved by my computer, probably half of them were shops of some description) - loads of them had shared passwords. I spent a couple of hours tediously changing them all. I would never have remembered every website I've signed up to without that list so I'm sure there are loads of people who are vulnerable to this sort of attack and don't realise it.


 
Posted : 16/06/2020 4:49 pm
Posts: 2237
Free Member
 

Thanks superficial, I wondered as the statement I received with goods Recently says wiggle at the bottom.


 
Posted : 16/06/2020 4:52 pm
Posts: 20663
Full Member
 

Can't remember the last time I used Wiggle. Tried to log on, predictably couldn't remember password but then I'm not sure of the email address I used either.

Anyway, reset and it clearly remembers me cos my address and phone number are there but it's showing no orders or returns in ages so all seems OK.


 
Posted : 16/06/2020 4:57 pm
 nuke
Posts: 5802
Full Member
 

Not heard of https://haveibeenpwned.com/ linked in the article. Have people tried it? At first glance it sounds exactly the sort of site I'd be avoiding


 
Posted : 16/06/2020 5:02 pm
Posts: 8201
Full Member
 

CRC have the same stock as wiggle. There are some quirks that appear to mean stock doesn't appear on the product pages but it does on the list pages.


 
Posted : 16/06/2020 5:05 pm
Posts: 1552
Free Member
 

Sorted thanks


 
Posted : 16/06/2020 5:05 pm
Posts: 840
Free Member
 

Not heard ofย https://haveibeenpwned.com/ /a>ย linked in the article. Have people tried it?

It's legitimate site, well worth checking to see if your email address is on any known hacked user credential lists.


 
Posted : 16/06/2020 5:23 pm
Posts: 14931
Full Member
 

Not heard of https://haveibeenpwned.com/ linked in the article

Genuine site that will show if your password is compromised anywhere


 
Posted : 16/06/2020 5:38 pm
Posts: 6859
Free Member
 

Yes, that website is good. My primary email address has been the subject of 8 data breaches. Annoying.


 
Posted : 16/06/2020 5:47 pm
Posts: 106
Free Member
 

All that data from EasyJet now being tried on market sectors like Cycling, Climbing, snow sports...


 
Posted : 16/06/2020 6:06 pm