The Inquirer-Home

Play.com is hit by a security breach

Customer names and emails are compromised
Tue Mar 22 2011, 11:35

ONE OF THE LARGEST online retailers in the UK, Play.com has admitted to having suffered a security breach that compromised customer names and email addresses.

In a vague email sent out to customers this morning, Play.com revealed that a company handling part of its marketing had fallen victim to some kind of hack. It didn't name the company involved, claiming that the issue occurred outside of Play.com and no other customer data has been stolen. The INQUIRER has requested more information from the company, and we'll let you know if anything else turns up.

This isn't the first time a problem of this nature has happened at Play.com, which sells stuff like DVDs, games and gadgets online. Back in 2009 customers reported that Play.com sent them emails reporting the dispatch of orders they did not place. This was due to a system error, according to a statement Play.com made at the time.

This time it is a security breach, and according to Trend Micro insecurity researcher Rik Ferguson the fact that a third party suffered the breach does not stop Play.com from falling afoul of the Data Protection Act, as it is responsible for subcontracted third parties. So far, the Information Commissioner's Office hasn't been informed of the breach.

Sophos researcher Carole Theriault made the point that even though Play.com said no credit card information had been stolen, it is wise to keep an eye on your credit card transactions and consider changing your password details. The situation might turn out to be very costly to Play.com. A recent report said that a data breach can cost a UK company an average of £1.9 million. µ

Share this:

Comments
Thought this was a bit rich

"Customer Advice

Please do be vigilant with your email and personal information when using the internet."

Feckin patronising idiots.

posted by : pete, 22 March 2011 Complain about this comment
Why is keeping credit card details opt-out

and not opt-in

We will just keeep you details here to make it easier for you next time.

To get them to remove your details you have to raise a support ticket to have them deleted. Why is there not a tick box saying 'Do Not Remember'

Because they want you details and make it as difficult as possible for you to delete them.

Don't worry we value your data.

Yes and that is the problem lots of others value my data as well and I want to decide who I share it with.

posted by : donkey, 22 March 2011 Complain about this comment
Thats why I don't shop with them...

I bought something about 2 years ago from them. They required to store my date of birth in their system as well as my visa card information...

I can never see the reason why I should provide such vitally important identity information for storage in their database. What else? Mothers maiden name? PIN number?

Suffice to say I went and made sure my date of birth was incorrect after my order. To me it meant the people involved with this site were clueless.

This news about leaking information out just shows that they are...

posted by : Smid, 22 March 2011 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?