ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Amazon subsidiary admits security breach

Troy Wolverton CNet

Published: 06 Mar 2001 10:49 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Amazon.com-owned book service Bibliofind.com restarted its Web site yesterday in the wake of a hacker attack that compromised some 98,000 customer records and forced the company offline.

Bibliofind, which links buyers and sellers of hard-to-find and out-of-print books, discovered last week that a hacker had broken into its Web servers sometime in October and had continued to access the company's site since then, Bibliofind spokesman Jim Courtovich said. The hacker downloaded customer records from the site, including customers' names, addresses and credit card numbers, Courtovich said.

In response to the discovery, Bibliofind, a wholly owned subsidiary of Amazon, shut down its Web site on Friday and removed customers' credit card information and addresses from its servers, he said. Courtovich declined to say whether Bibliofind had identified a suspect in the attack, saying only that the company notified the Federal Bureau of Investigation, which is looking into the matter.

"Bibliofind has just learned of a security violation on its site that compromised the security of credit card information used on Bibliofind's servers," the company said in an e-mail message to customers. "We are working to bring the Bibliofind service back into operation shortly. We apologize for any inconvenience this may cause you."

Although Bibliofind has notified credit card companies of the attack, the company does not have any indication that the numbers have been used, Courtovich said.

The fact that a hacker had access to Bibliofind's records for four months without Bibliofind discovering the breach is simply a case of the company not keeping a good eye on its site, said Richard Power, editorial director of the Computer Security Institute. With that much time and access to Bibliofind's systems, the hacker could possibly have found much more than customer records; he might have been able to find a backdoor into Amazon.com, Power said.

"It's going to take awhile for them to figure out how much damage was really done and who else may have been compromised by being connected by their sites," Power said.

Amazon spokeswoman Patty Smith said the Seattle-based e-tailer's servers were not affected by the attack on Bibliofind. Amazon does not share customer information with Bibliofind and no Amazon customer information was compromised by the breach, she said.

"They operate on different platform than what our server is running on," Smith said. "The integrity of Amazon's systems was never in question."

The Bibliofind breach is only the latest in a string of security breaches at leading e-commerce sites. A breach at Columbia House's Web site left open some 3,700 customer records last month. And in January, a security hole at Travelocity.com exposed the personal information of up to 51,000 customers.

Meanwhile, a breach at Egghead.com in December potentially exposed all of its 3.7 million customer database.

By shutting down its Web servers, Bibliofind also closed down access to Musicfile.com, which shares the same server as Bibliofind. Musicfile's customer records were not affected by the breach, Courtovich said. Bibliofind went back online Monday afternoon.

Amazon acquired both companies when it bought Exchange.com in April 1999.

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 85 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Developer C++ / C# - Credit derivatives - London

Title: Developer C++ / C# - Credit derivatives (London) Location: Central London, City, South East UK Salary: Competitive Type: Permanent Developer ...

Credit Risk/ Basel II Business Analyst

I have an excellent opportunity for a credit risk analyst with Basel II experience to join a Blue Chip Financial Organisation in Yorkshire to work as ...

Records Managment / EDRMS expert wanted now

I am looking for a Records Management / EDRMS expert for my government sector client. I am looking for someone to implement the findings of the joint ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains