Bulk Reef Supply Security Breach

I just joined this forum to update this thread. Yesterday, I purchased an RO system from BRS, and within less than 24 hours, my credit card company notified me of a fraudulent charge, and subsequently locked my account.

This was my first time purchasing anything from Bulk Reef Supply, and I felt a little nervous using their site, since their software auto-filled my address as I started typing it, despite the fact that I have never bought from them before. I did a quick search using the words, "bulk reef supply fraud," and my search engine suggested, "bulk reef supply fraud alert," which I then searched, and this thread came up.

I thought it would be worth letting you all know that I contacted BRS just this morning to inform them that I'd had this happen within 24 hours of purchasing from them, and that there could be a new (or continued) breach. Jason was very polite and professional on the phone, and he said they would let me know what they find.


Your browser autofills info unless you have turned that off.

As for the timing less then 24 hours would indicate it was not BRS but another method. This isnt a skimmer at a gas station. Most web site breaches take time to actually be utilized. If you research recent breaches there have been quite a few companies recently hacked in the past couple months and as such it is likely it occured there. I think this is more or less a coincidence of timing on your part.
 
Your browser autofills info unless you have turned that off.

As for the timing less then 24 hours would indicate it was not BRS but another method. This isnt a skimmer at a gas station. Most web site breaches take time to actually be utilized. If you research recent breaches there have been quite a few companies recently hacked in the past couple months and as such it is likely it occured there. I think this is more or less a coincidence of timing on your part.

I agree. There are so many vectors for our private information to get stolen it's hard to say with certainty who it is.

I recently did my taxes and I think that this accountant has a copy of all my personal info that is he required to keep. Who knows who works in his office throughout the entire year? That's my whole life!

I recently started looking for a mortgage and i also have to provide a copy of my entire financial holdings - who knows who else is in that realtor's office? Interns ect.

I don't know what happened in MintTerribilis case but the autofill is 100% not BRS (where would they get his info from) - it's a feature of your browser.
 
I just joined this forum to update this thread. Yesterday, I purchased an RO system from BRS, and within less than 24 hours, my credit card company notified me of a fraudulent charge, and subsequently locked my account.

This was my first time purchasing anything from Bulk Reef Supply, and I felt a little nervous using their site, since their software auto-filled my address as I started typing it, despite the fact that I have never bought from them before. I did a quick search using the words, "bulk reef supply fraud," and my search engine suggested, "bulk reef supply fraud alert," which I then searched, and this thread came up.

I thought it would be worth letting you all know that I contacted BRS just this morning to inform them that I'd had this happen within 24 hours of purchasing from them, and that there could be a new (or continued) breach. Jason was very polite and professional on the phone, and he said they would let me know what they find.

As stated the "Autofill" is because of your browser settings.. It has NOTHING to do with BRS website.. That information is stored locally on your computer and done so because you have allowed it to keep that information..
Your browser simply sees a form field named "name" or "email" and gives you the option to fill that form with its known/stored data.

Same for the credit card problems.. Again.. Nothing related to BRS there too more than likely.. They are a very processional/reputable supplier around here.. Don't let this one incident stop you from supporting them..
They are excellent..

I just ordered from them 2 days ago and will continue to do so..
Its a shame that this kind of stuff happens but it happens to everyone.. small and large companies.. Home depot/ Target all have had "security breaches" despite having thousands and thousands of dollars into "internet security" and dedicated "security professionals" monitoring their network traffic..

Sadly there is more money to be made in "illegal hacking" than "Internet Security" jobs protecting us from those "illegal hackers"..

I do websites for numerous online clients and its quite a task keeping everything up to date and secure..
I actually attempt to block specific countries (IP addresses) from many of my websites if they aren't selling to that location but thats easy to get around too..
I also get an email on one of my private servers when people try to "hack" into it and I "ban" them after 5 attempts.. This site gets NO traffic (just a fun page for family,etc...) and its not uncommon to get 100+ hack attempts a day on it through FTP or SSH,etc...
Its mostly what we call "script kitties" that really have no idea what they are doing but found some script on the internet (dark web) that they are running so they are of little harm.. The "good" ones can get into any server at any time no matter what security you have and you never know they were there except deep scanning into access logs,etc.. and they can even get around that..

Welcome to the world as it is today..
Support BRS and just be safe with your information but don't think for a second you are 100% safe.. You never are..
Routinely check your CC statements, bills,etc..
Check your credit scores even routinely..

The faster you see it happening the faster you can stop it..
But its never going to stop..
Well until we just nuke China and Russia :) or take away their internet access (#1 and #2 with the most hackers in the world by far)
 
As stated BRS is certainly a trustworthy company, one of the best around and I buy frequently from them. That said I was caught up in the security breach from a few years ago, nothing directly effecting me but I changed all my CC accounts. Now when I purchase from most anyone I do it through PP which I feel limits my actual CC account info.
 
It could be my browser, but it's never happened anywhere else before. In any case, BRS never got back to me, but I did have to replace that card.
 
It could be my browser, but it's never happened anywhere else before. In any case, BRS never got back to me, but I did have to replace that card.

You never stated if you actually had a unauthorized charge or authorization on your card. You only stated that you have never purchased from BRS before which could be the very reason your card flagged the charge. Most CC companies track your usage vendor/store/categories/locations of purchases, ect so if their software sees a charge that is not in relation to your usually spending habits a lot of times it will raise a fraud alert for security and you will need to verify the charge. This is more than likely what happed here. This is also why many banks ask that you notify them if you are going to be traveling so that they do not block your card for unusual activity when it is detected.
 
Back
Top