Petco settles FTC charges over security flaws

By

Petco Animal Supplies agreed to settle Federal Trade Commission charges that security flaws in its web site violated privacy claims it made to customers.

According to the FTC, Petco promised customers that it kept their data private and secure on its web site, where it sells pet food and supplies. However, the site was vulnerable to a common web application attacks, such as SQL injection.


A hacker exploited flaws in the site to access credit-card numbers stored in unencrypted clear text, the FTC said. The agency charged that Petco's security claims were deceptive and violated the FTC Act.

The settlement requires that Petco implement a comprehensive infosec program to protect customers' personal data. It also requires that the company undergo biennial audits of its security program by an independent third party.

www.ftc.gov

 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Palo Alto Networks in talks to buy CyberArk

Palo Alto Networks in talks to buy CyberArk

Gov to encourage vuln research, puts insurers and NFPs on notice

Gov to encourage vuln research, puts insurers and NFPs on notice

"Scattered Spider" evolves with new ransomware and social engineering tactics

"Scattered Spider" evolves with new ransomware and social engineering tactics

Allianz Life says majority of US customers' data stolen in hack

Allianz Life says majority of US customers' data stolen in hack

Log In

  |  Forgot your password?