Bulk Reef Supply Security Breach

Got another one today with my address also, but the first and last name was not mine this time eiather.

I don't really understand why some people get so upset over this. It happens, theives will always be one step ahead.
Because its their God given right, some people don't like the idea of criminals having their information. I betcha if you lost thousands of dollars like this your attitude would be different.
 
Because its their God given right, some people don't like the idea of criminals having their information. I betcha if you lost thousands of dollars like this your attitude would be different.

I guess that depends on who you expect to direct the rage at. If at the hackers I am with you. If at the retailer then not with you so long as the retailer had security and such.

In this instance BRS uses Magento which a TON of other companies use as their checkout platform. They also have Verisign which again is pretty standard. Magento was what was hacked and many other companies using the Magento platform were hacked as well.
 
I rage at the criminals.


THen in 100% agreement with you...


Also instances like this are why you should always use a credit card online not linked to a bank acount. That way you have their fraud working for you and it is THEIR money in the wind vs your own money while you fight with the bank to get it back...
 
THen in 100% agreement with you...


Also instances like this are why you should always use a credit card online not linked to a bank acount. That way you have their fraud working for you and it is THEIR money in the wind vs your own money while you fight with the bank to get it back...

Exactly I never use debit cards or bank accounts online unless it is the only option. Use use PayPal or credit cards...much safer, it's much harder to get your money back from a checking account. Credit cards all it usually takes is a chargeback and a new card number.
 
Not sure if it has anything to do with BRS. I have used my card there recently over the last few weeks. Just got 2 Fraud charges from Salt Life each $705 each. Fruad Protection called me to see if I had made the charges. Looks like they denied it since it hasn't hit my account so far. But, still a pain in the *** to have to cancel the card and wait for a new one.
 
I had fraudulent charges back when this first came out, got a new card, and just this weekend i got more fraudulent chargers to the new card from two places in the UK.
Not sure which one is related to the BRS event, but yeesh! Craziness. Not to mention a pain in the butt. Luckily my bank catches these things instantly.
 
I am a victim of this Security Breach. We went through a lot to sort things out. Citibank wasn't nice with us at all! For almost three months they tried to charge us for transactions we never made. We has to fight for each of transaction with Citi one by one for three months! Use Paypal for you purchase. And criminals - they don't care really. They are not afraid to use card for airline fares, big store shopping, car rental etc.
 
I think from now on I am just going to call BRS and place an order. Might do the same with everybody

Does this help? I'm just curious if they are still going to have the credit card data somewhere where it could be hacked. Or is it the electronic transmission where the data is breached? I need to get up to speed on these issues.....yikes. Scary how widespread this issue is!
 
If/when PayPal gets hacked we're screwed. Some solutions are better than others, but none are failsafe. Credit card companies and businesses are simply not sufficiently motivated yet to verify that online or in-person transactions are from the legitimate card holder, and there's not sufficient technology yet to help them.

As long as the losses continue to cost less than developing the technology to ensure safe, secure transactions, it's not going to get fixed.

Recently I got an alert notice from my credit card company that a $900- something charge at Best Buy was denied and I should indicate via a checkmark on the email whether it was legitimate. Of course it wasn't. They locked the account. I waited a few days to see what would happen next. They didn't call me. I tried the card and of course it didn't work. So, I called them. They changed the account number and sent me a new card. This has happened at least 5 times in the last 2 years.

I asked the customer service rep how they determined the charge was illegitimate. All they would tell me is the charge was local and the person presented a physical card. The charge was denied. No reason why. My guess is the business asked for an id and the person couldn't produce one. But wouldn't they ask for an id before they ran the charge? Did they call the police? No. Was this person detained? No. The only consequence was my account was locked. The business didn't care - they lost no money. The card company didn't care - they lost no money. Slight inconvenience for all, except me!

Nothing will get fixed until there's sufficient motivation, i.e unacceptable costs. And we're all paying for this through fees and charges.
 
Yep my second go round too

Yep my second go round too

Just found a cloud backup service company charge on my card-3 days after using my card at BRS. Had it hacked in January, after shopping there also. Don't blame them but not giving them my card again.
 
Just had it happen to me. Of course, there's no way of (me) knowing whether it came from BRS or not - last time I shopped there was a few months ago, but it seems odd they can't seem to get it fixed.
 
Credit card companies and businesses are simply not sufficiently motivated yet to verify that online or in-person transactions are from the legitimate card holder, and there's not sufficient technology yet to help them.

That portion is not true at all when it comes to the banks issuing the cards since they eat the fraud typically. The amount of money the card companies eat yearly in fraud is astounding. Sure they can write some of it off as business loses but that writeoff does not cover the actual costs that they eat both in staff to watch for fraud, customer service, mailings, new cards, and so on.

There has been no liability for the business typically and as such the banks have pushed for legislation to be closer to the standards in the rest of the world. Retail has pushed back resulting in a very slow adoption of new protections you will see coming online this year and stretching into the years to come.

IE as of the end of 2015 brick and mortar retailers will be held liable for their fraud if they do not have the systems in place for chip based cards. This will stretch into other retail environments in the coming years as well giving them a push to actually check the card and id as well as a every so slightly more secure card.

The next step in the US to catch up to the international market is the chip and pin cards. They would require a pin like a debit card to work and that could be easily changed online by the card member.

The final step is variable token security which is coming online now but will result in more retailer changes to adopt. Though by that point we might be all using the digital wallets more which offer more security when set up correctly.

no matter what with all the databases out there you are at risk everytime you swipe a card at a store be it a brick and mortar or online. Even the banks get hacked at times so nothing is secure unless you wish to pay cash only but good luck with that everywhere.
 
I just got hit with a charge from a cloud base site also. Is or has anyone signup with the protectmycard site that was on the mailing? or would just getting a new card take care of it.
 
Possible New or Continued BRS Breach

Possible New or Continued BRS Breach

I just joined this forum to update this thread. Yesterday, I purchased an RO system from BRS, and within less than 24 hours, my credit card company notified me of a fraudulent charge, and subsequently locked my account.

This was my first time purchasing anything from Bulk Reef Supply, and I felt a little nervous using their site, since their software auto-filled my address as I started typing it, despite the fact that I have never bought from them before. I did a quick search using the words, "bulk reef supply fraud," and my search engine suggested, "bulk reef supply fraud alert," which I then searched, and this thread came up.

I thought it would be worth letting you all know that I contacted BRS just this morning to inform them that I'd had this happen within 24 hours of purchasing from them, and that there could be a new (or continued) breach. Jason was very polite and professional on the phone, and he said they would let me know what they find.
 
This is a shame. Have no fear BRS is a top notch company and will do everything they can to fix the issue if it indeed is from them. I have been dealing with them for years. When this happened a few years ago they sent out personal letters informing customers about the breach. Most companies wouldn't care enough to do that.


Sent from my iPhone using Tapatalk
 
I just joined this forum to update this thread. Yesterday, I purchased an RO system from BRS, and within less than 24 hours, my credit card company notified me of a fraudulent charge, and subsequently locked my account.

This was my first time purchasing anything from Bulk Reef Supply, and I felt a little nervous using their site, since their software auto-filled my address as I started typing it, despite the fact that I have never bought from them before. I did a quick search using the words, "bulk reef supply fraud," and my search engine suggested, "bulk reef supply fraud alert," which I then searched, and this thread came up.

I thought it would be worth letting you all know that I contacted BRS just this morning to inform them that I'd had this happen within 24 hours of purchasing from them, and that there could be a new (or continued) breach. Jason was very polite and professional on the phone, and he said they would let me know what they find.


My computer auto-fills (with permission) even if I have never been to a site. It doesn't necessarily wait for the site's assistance. With BRS, all fields are already filled when I order. However, they take PayPal and that's what I use.
 
Back
Top