back to article SportPursuit coughs to being hacked. When? What got nicked? They ain't saying

Clothes website SportPursuit was hit by hackers over the Easter weekend, potentially losing customers' bank card details. SportPursuit admitted on Sunday that it had "uncovered evidence" of "an attempted data hack" which "may have affected" what it claims were "a limited number" of its customers. The company's statements to …

  1. quattroprorocked

    "A limited number"

    Every time a journalist sees this in a press release they should automatically follow up with "and of course, by limited number they might well mean limited to EVERYONE".

  2. Anonymous Coward
    Anonymous Coward

    Don't worry - your passwords weren't in clear text...

    but we used this thing called MD5....

    1. Adam 52 Silver badge

      Re: Don't worry - your passwords weren't in clear text...

      They say that they're using salted hashes so I'd expect a reasonably sensible password strategy based on a slow hash function.

      They also say that the hole was introduced during an upgrade, so that suggests that the original design was OK and someone has introduced a cock-up (like leaving the debug logging on).

  3. Mike Shepherd
    Meh

    Crikey! I never took the cake. In any case, it didn't taste very good. Oh, lor....

    SportsPursuit's disaster management manual seems to have been written by Billy Bunter.

  4. Flabbergasted Elk

    Asked for clarification...

    Thank you for your mail.

    It is possible that the data which may have been accessed includes debit or credit card details. It is for this reason we have emailed all potentially affected members to ask them to remain vigilant and report unusual activity to their bank or credit card provider. Importantly, it is not possible that the CVV (Card Verification Value) of the cards in question was accessed from our systems.

    Amazeballs.

  5. nsld
    Facepalm

    how can you update a website

    And accidently start storing card details in encrypted form?

    Sounds like some cut and paste web development to accidently achieve that and then not notice it in any QA of the site.

    Whats the betting the encryption key was stored with the data for ease of access?

    1. Adam 52 Silver badge

      Re: how can you update a website

      My bet is that they log to file at some point and the log aggregator automatically encrypts. Which, if true, is better than ours.

  6. Adam 52 Silver badge

    By most standards SportPursuit have handled this well. They coughed up pretty much as soon as they knew and they've been honest with the details.

    Compare with other retailers who've been hacked - eBay, Warehouse Express, 7dayshop - all of whom deny anything wrong and refuse to answer questions. Or others, where the extent of the leak dribbles out over time.

    I'm a SportPursuit customer.

  7. Anonymous Coward
    Anonymous Coward

    Storing CC details for at least a year...

    I received the email, but looking at other forums not all customers have. What concerns me is that I last used my credit card on SportPursuit 12 months ago - assuming they're not just mailing anyone who ever used a credit card and the recipients are just those customers whose credit card data was inadvertently stored, that means they've been storing card data for 12 months or more.

    Makes you wonder how 'inadvertent' it really was...

  8. Anonymous Coward
    Anonymous Coward

    all orders I've placed with SportPursuit over the last couple of years have been done through PayPal so they shouldn't have any CC details for my cards.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like