ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Online blackmailer leaks hacked data

Greg Sandoval CNet

Published: 12 Oct 2001 08:58 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An online gift certificate company said a hacker that blackmailed it for weeks after pilfering its customer information has apparently carried out threats of disclosing the data to its customers.

Webcertificate.com customers reported getting an email message that included their home and email addresses.

"I hate to inform you that your account has been hacked," said the email, viewed by this reporter, from someone identified as Zilterio.

Webcertificate, a unit of electronic-payment company Ecount, was hacked on 21 August, a representative said. Shortly afterward, the hacker, who also claimed to have stolen credit card numbers of 350,000 of the company's customers, contacted Philadelphia-based Ecount and tried to extort the company, said Matt Gillin, Ecount's chief executive. The caller demanded $45,000 (£31,500) in exchange for not disclosing the information.

The company refused to meet the demands, Gillin said.

After notifying the FBI, Ecount informed customers on 28 August that the break-in had occurred, and it assured them that their credit card information was safe. Because the company stores credit card information offline, it would be impossible for the hacker to steal it electronically.

What the hacker thought were credit card numbers were really 16-digit serial numbers used to identify gift certificates. Ecount has cancelled those codes. "There is no financial liability to the company or our customers," Gillin said.

The FBI could not be reached for comment.

Hackers continue to plague the Internet even as technology companies have poured millions of dollars into developing security technology. But the costs of fortifying a Web site with the latest security technology can be enormous, and often hackers prove to be more than a match for the electronic barricades.

Companies such as Amazon.com-owned book service Bibliofind.com, Creditcards.com and Egghead.com, which recently filed for bankruptcy protection, have seen their sites broken into and customer information--in some cases, credit card information--swiped by thieves.

Executives of Ecount said they anticipated the hacker would email customers whose information was stolen. Last week, the company tried to pre-empt the hacker when it warned customers to expect a message from the hacker and informed them why the company would not agree to the hacker's demands.

In the email to Webcertificate customers from Zilterio, the author declares that the security breach was a result of "weak security", an apparent attempt to embarrass the company.

Ecount said the attempt to undermine the company's relationship with its customers failed; most customers support the company in its fighting against Internet thieves. But some damage may have been done. One customer told this reporter that she would no longer use Webcertificate.

"This disturbs me, that this guy has all of my personal information," said Nancy Parker, a frequent Webcertificate customer over the past two years who was shocked to see her personal information in the email. "What's from keeping it from happening again?"

Gillin said that immediately after the attacks, the company began bolstering the site's security.

"We're doing all we can to make sure that this never happens again," he said.

See the Viruses and Hacking News Section for the latest headlines.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

See the Internet News Section for full coverage.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
39 out of 92 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Lead Clinical Data Manager - South East - 6 month contract

Input to and review of clinical trial database design including User Acceptance Testing Responsible for the validation and planning of meetings for ...

Document Image Processing (DIP) Architect Required

They pride themselves on being highly respected within the SAP market and provide end to end solutions across a wide section of industries. My client ...

SUPPORT ENGINEER - HERTS - c25k - ELECTRONIC FUNDS TRANSFER

Opportunity for a Support Engineer with previous experience of providing 1st line support of Electronic Funds Transfer & Payment Systems / Payment ...

Discussions

319762 319762

Eve of Distraction

Saturday 26 July 2008, 4:37 AM

1 comment

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal