GetDotted Domains

Viewing Thread:
"Lush.co.uk website hacked"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Thu 20/01/11 at 21:38
Regular
"I like turtles"
Posts: 5,368
Don't know if this is of interest/concern to anyone on here and apologies in advance if I sound like I have no idea what the hell I'm talking about (that would be because I don't!).

I ordered the Mrs. some smelly bath things for Christmas from a site called Lush.co.uk .About half an hour ago I received an email from them informing me that their site has been 'hacked' and any customers who have shopped online with them between 4th Oct and 20th January should contact their banks 'for advice'.I did this just to cover myself and my credit card company informed me that they must cancel my card with immediate effect? Don't know if this is them just being overly cautious or whether these people have indeed successfully gathered the card details of customers who used this site during the mentioned period? Unless other sites have been effected I doubt this will be of relevance to anyone on here but just thought I'd mention it.
Tue 01/02/11 at 07:14
Regular
"@optometrytweet"
Posts: 4,686
I had a mini-panic when I read this thread, as shopped in Lush a few weeks ago. Bar their obvious web problems, I'd like to point out that their shops and staff are simply amazing.

(I say this as I ended up buying enough solid shampoo to see me through university and possibly through life...all for less than a tenner...happy days!)

But I can see them deserving a sharp rap on the knuckles for allowing this to happen though!
Tue 25/01/11 at 08:54
Staff Moderator
"Freeola Ltd"
Posts: 3,299
Sounds pretty condemning. Probably no more than they deserve, although the 5th point is a bit odd 0_o. I wanna say "they can believe what they want surely", but I got his point :)

Garin wrote....
Bit defensive there, Warhunt. ;)

Really? It wasn't meant to come out that way.
Mon 24/01/11 at 20:08
Regular
"Feather edged ..."
Posts: 8,536
Recent 'reports' suggest:

Looking further into the hack and what has happened, Noa Bar Yosef, Imperva’s Senior Security Strategist, observes:

1. It seems that Lush online application is riddled with vulnerabilities. They even comment on continuing to be a target and so they’re taking the website down. So it’s not just one sole vulnerability that could have been quickly fixed, but lots of security issues which would require a security overhaul.

2. The hacks occurred throughout a 4-month timeframe. Yet, they know the exact dates of start-finish of the hack, which means that they did have some sort of audit during the attack. Yet, there was probably no one responsible to constantly oversee the audits to alert in the case of abnormal behavior.

3. In regards to the audit – Lush mentions that they are informing all “potentially affected” customers. This means that they do not have exact affected customers details. A good audit trail should also provide concrete details regarding who was affected and when.

4. The attack clearly shows that Lush was in breach of PCI DSS compliance.

5. Look at the “We Believe” statements. There’s no talk about belief in making websites secure for customers. They are blaming the attackers and talking about cooperation with law enforcement. However, they should also add a “We Believe” on making the website more secure for their customers.

There you go....what you make of that Garin ;¬)
Mon 24/01/11 at 15:04
Regular
"Devil in disguise"
Posts: 3,151
Bit defensive there, Warhunt. ;)
Mon 24/01/11 at 09:54
Staff Moderator
"Freeola Ltd"
Posts: 3,299
Don't think anyone suggested they deserved credit (as in praise at least) anywhere in the thread. Certainly they don't really.

In relation to my post at least, I was replying to Chris, suggesting they do seem to be taking it seriously now. Whether they took too long to do so or not I'm not commenting on, just the post does seem serious at this point. And apologetic.

Perhaps they should have taken it seriously earlier? Although you don't really know the inside scoop. Maybe it was an inside jobby after all, and that's why it took so long to notice/deal with? Seems a reasonable conspiracy theory :P
Sun 23/01/11 at 17:44
Regular
"Devil in disguise"
Posts: 3,151
The statement they've released says they became aware of hacking attempts on the 20th of december. So thats a whole month they've spent messing about before taking the site down. So not sure they are due any credit for their behaviour.

Hmmm... wrote:
I can't see anyone talking about the 3rd party they use for "secure server for processing credit card transactions" - rather odd.

I suspect the phrasing is a bit of a red herring. They might use a 3rd party for credit card transactions, it doesnt mean they are using it on the front end though. I bet Lush take the CC details and then use the 3rd party when processing the order. So probably nothing to do with the CC processor. It might explain the 3 month (ish) time period as well because when you take CC details you can only keep them for a limited period.
Sun 23/01/11 at 17:27
Regular
"Feather edged ..."
Posts: 8,536
By all accounts, probably a lot more than would care to admit it pete :¬(
Sun 23/01/11 at 13:33
Regular
"I like turtles"
Posts: 5,368
I reckon someone must have left the office window open when they went out for lunch.

Seriously though, how was this allowed to happen ? Credit card details were not supposed to be stored by the site but they quite clearly were. Lush had no other option but to come clean about it at some point but this security breach had apparently been going on for 3 months!. How did the problem go undetected for so long?, or were they aware of the breach but thought they could plug it? Like I said it's not the end of the world but it is annoying and inconvenient for those effected. Lush are a well known and supposedly reputable company and I would imagine that there may well be other online retailers who have been trading in this way?. If that is the case then could there be other sites that have been compromised in a similar fashion?
Sun 23/01/11 at 12:41
Regular
"Feather edged ..."
Posts: 8,536
Couldn't agree more Hmmm...did think it was 'overdue' when pete first broke the 'news'......the 'Happy Monday' video didn't instill confidence either, neither did the request to keep shopping via the telephone :¬(
Sun 23/01/11 at 10:50
Moderator
"Are you sure?"
Posts: 5,000
As if I would make something up! :¬P

Something looks a bit strange to me though...

This has been going on for quite a long time. Further reading shows they might have knew about problems in December but let things run.

I can't see anyone talking about the 3rd party they use for "secure server for processing credit card transactions" - rather odd.

So perhaps it's either an inside job or things weren't setup very well?

They didn't have any choice than to take the site down as they are no doubt in danger of losing their Merchant Account depending on what was going on...

[s]Hmmm...[/s]

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Excellent
Excellent communication, polite and courteous staff - I was dealt with professionally. 10/10
Impressive control panel
I have to say that I'm impressed with the features available having logged on... Loads of info - excellent.
Phil

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.