iTnews

Lush A/NZ credit card details pilfered by "hackers"

By Ry Crozier on Feb 15, 2011 3:48PM
Lush A/NZ credit card details pilfered by "hackers"

Database stolen, PCI DSS rules flouted.

Soap retailer Lush has urged customers in Australia and New Zealand to cancel their credit cards after revealing the brand's local websites were breached.

It pulled its websites offline today and replaced them with a "privacy breach" message indicating that online shoppers' personal information "may have been obtained by the hackers".

Lush Australasia director Mark Lincoln later told ABC News that the company's online customer database had been stolen.

He also told ABC News that customers were not informed that their credit card details would be retained by the company and stored in a database. 

The Payment Card Industry compact to protect cardholders and their banks known as PCI DSS sets basic rules for accepting, storing and handling credit card details. These included keeping the credit card numbers for only as long as is necessary, usually just the time it takes to complete the transaction, and encrypting data as it is transmitted and when it is at rest.

Many online stores use merchant gateways or an intermediary such as PayPal and never see the cardholders' details.

It was unclear if Lush was in breach of its online merchant agreement and would face sanction from its issuing financial institution.

click to view full size image

"Lush is working with the police, forensic investigators and banks and doing all that we can to investigate the breach of privacy," it said.

"We are currently in the process of contacting each of our online customers individually by email."

Lush said it was in the process of carrying out "further security checks" in a bid to determine the extent of the breach.

However, it denied the hack was linked to an attack on the retailer's UK website in late January, other than to say that its site had also been targeted by hackers.

- additional reporting by Nate Cochrane

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
australiacredit carddetailshackhackerslushnew zealandpci dssretailitsecuritystolen

Partner Content

Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • 11th Annual Fraud Prevention Summit 2022
  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Ry Crozier
Feb 15 2011
3:48PM
0 Comments

Related Articles

  • Geolocation threats rise following demonstration of router hacking that can pinpoint a person's home
  • Five-Eyes alliance issues Russian cyber attack alert
  • 7-Eleven disables facial image capture on customer feedback tablets
  • Quad countries to boost CERT cooperation
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

Kmart Australia re-platforms ecommerce site to AWS

Kmart Australia re-platforms ecommerce site to AWS

Digital Nation

CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.