Deprecated: Function create_function() is deprecated in /home2/blogwebhostingbu/public_html/wp-content/plugins/facebook-like-box-responsive/facebook-like-box.php on line 29
{"id":547,"date":"2009-04-09T15:50:07","date_gmt":"2009-04-09T15:50:07","guid":{"rendered":"http:\/\/www.webhostingbuzz.com\/blog\/?p=547"},"modified":"2014-10-08T12:48:52","modified_gmt":"2014-10-08T12:48:52","slug":"webhostingtalk-database-breach-credit-cards-stolen-lessons-learned-for-web-hosts-everywhere","status":"publish","type":"post","link":"https:\/\/blog.webhostingbuzz.com\/2009\/04\/09\/webhostingtalk-database-breach-credit-cards-stolen-lessons-learned-for-web-hosts-everywhere\/","title":{"rendered":"WebHostingTalk Database Breach, Credit Cards Stolen: Lessons Learned for Web Hosts Everywhere"},"content":{"rendered":"

A very wise man, George Washington, once said\u00a0“If we don’t\u00a0learn<\/em>\u00a0our\u00a0history<\/em>, we’re doomed to repeat it.” \u00a0This quote is certainly true in the security industry, as you must always be watching and learning – adapting as situational changes occur all around us. \u00a0It is essential to look at the mistakes of others and learn from them.<\/p>\n

I would like to make clear that we are not interested in propagating rumors or beating this issue to death. \u00a0There are very serious issues that arose here that can be used as a learning experience for all of us in the web industry and it is vital that these lessons be brought out.<\/p>\n

It is fair to say that this situation has shown the ideal way not<\/strong>\u00a0to handle a data breach incident. \u00a0There have been numerous failures among many different individuals along the road, and some inexcusable negligence on the part of those involved. \u00a0This should be used as a learning experience, guiding all of our incident response plans to better our reaction to these issues in the future. \u00a0This example is exactly why we must always have these plans in place, refined, and practiced in case they are ever needed, as it is more a matter of when, not if, we will have to use them.<\/p>\n

<\/p>\n

Background<\/h3>\n

Roughly two weeks ago, it was first made public that \u00a0the popular site WebHostingTalk.com was compromised from a very unique attack – by having their backup servers exploited and destroyed. \u00a0At the time, it was reported by the parent company, iNet, that absolutely no credit card information was involved in the breach, but close to 5,400 pages of account information (username, email address, and encrypted passwords) were stolen.<\/p>\n

This week, however, we reported that there was credit card information stolen from this same database and it was posted on various BitTorrent sites, forums, and other places around the Internet with the complete table of unencrypted credit card information. \u00a0WebHostingBuzz’s COO Matt Russell was affected and notified users in our forums and on the blog as soon as he could. \u00a0We did a little additional investigation and found some very troubling information as to what data was taken and the type of data that was involved.<\/p>\n

The data stolen included:<\/p>\n