Bulk Reef Supply Security Breach

Things like this happen. Unfortunately it's a risk we all take in the eCommerce world in which we live.

What SHOULD NOT happen is to be blindsided WAY after the fact! My situation went down in January! And NOTHING from BRS. You get in front of situations like this, own it and move on. Not communicating to the customers when this compromise was realized is not acceptable! While many of us struggled to correct this on our end, someone in some conference room made a conscious decision to sit on their hands.
 
If you read my link they're sending info out to those of us who had our info compromised. I never allow any website to store my credit info for future use and I wonder if those are the people affected.

Wait?

So you are saying that I am safe?

I have bought multiple purchases from BRS but I never saved my CC info.

I always Manually Type it in every time I order something.

So am I safe or no?
 
I had my credit card number stolen from a gas station I used to use. Stuff happens.

How can you pinpoint to what place stole the info?

Unless you only use your card at that gas station and nowhere else?

How do you know that it was the Gas Station?
 
How can you pinpoint to what place stole the info?

Unless you only use your card at that gas station and nowhere else?

How do you know that it was the Gas Station?

Because that particular card is only used at gas stations. At that time I was using the same station also. :)
 
Wait?

So you are saying that I am safe?

I have bought multiple purchases from BRS but I never saved my CC info.

I always Manually Type it in every time I order something.

So am I safe or no?

I'm not saying anything. I was asking a question. I too have bought many things from BRS in the timeframe that they had the breach and my credit card has yet to be compromised, but who knows it may yet still be used fraudulently.
 
I received a letter from BRS today outlining the incident and the steps they have taken to protect their customers. Given the level of data that was available to hackers it seems like BRS has gone above and beyond to make amends. based on how it has been handled so far I certainly would not let this unfortunate incident deter me from shopping with them in the future.

Matt
 
Finally received my letter today. Signed up fro their free credit monitoring, but I know deep in the pit of my stomach that the sky is still falling. :lol:
 
The first thing all of you who are concerned, actually everyone should do this, freeze your credit with each of the major credit companies, i.e., Experion, Transunion and Equifax. This will prevent ANYONE from opening new credit in your name. It may cost $10 per credit bureau. If you need to obtain credit, you can unfreeze for a specific creditor. I did this over a year ago. Freezing your credit is better than the fraud protection companies as they typically only let you know when something happens through the credit bureau such as a credit inquiry or new issue.

If you are concerned about anyone running up charges on the cc card you had on file with BRS, call the issuer and report it stolen.
 
I got my letter from BRS yesterday. I contacted them they said if you received a letter your info was compromised. They also said that full credit card number's were not stolen. I believe mainly names, addresses, email's and phone number's were taken. I've been getting a lot of out of state phone calls, several calls were people posing as tax expert's that claimed they did my taxes a couple of years ago (they don't realize I do my own taxes). I played along with one lady, she needed to verify my SSN. Most likely our info was sold to other scammer's, who are trying to gain more private info to further scam.
 
Got my letter today! Awesome... but I guess this is the cost of doing business on-line. All you can do is continually monitor your credit and accounts.
 
I just got a notice in mail that Bulk Reef Supply had a security breach,,this is for time period of July 30,2014 -January 21,2015..
I have already got an Early Warning from my credit card company this past Monday of fraud activity on my credit card..
I can assume this is were it is coming from ..
SO INVESTIGATE YOUR PURCHASES WITH BRS NOW.......

Thanks for your info....
 
1) They have to offer free credit monitoring because thats what the law says they have to do in cases of compromise.
2) As HKGAR said contact the credit companies and put a block on your credit, this is free for a year i believe when you can show compromise even if not free pay for it.
3) contact the credit card company fraud dept of the card you used with BRS and let them know

Watch for monetarily small "test" charges, if they succeed with those the big hits will be on the way (this isnt always the case and sometimes they just try for it all)

If the hackers are organized enough nobody can stop them. The days of hackers being pimple faced teenagers in their parent's basement are long over and this is now the domain of highly organized crime syndicates with very intelligent and educated code writers. If they are determined and skilled you will be compromised.:fun2:
LOL although even "script kiddies" get lucky now and agian
 
Last edited:
i never save my cc info and i got the letter so just throwing it out there you would have gotten the letter it said if they even got your name and address and dob so its not exclusive to those whom store there cc info...... just throwing that out there
 
I use a password app called SplashID for my iPhone. You can sync it online, but I don't use that functionality. I do sync over Wifi to my desktop PC. It's an additional charge for the wifi sync add on.

I have the password set on my iPhone, along with auto wipe after 10 failed attempts. I also have remote wipe enabled, should I ever lose my phone. The app is also password protected and according to SplashID, runs unbreakable AES and 256-bit Blowfish encryption. So you would have to guess my iPhone password within 10 attempts and then crack the 256-bit encryption to get my passwords.
 
Some small tips:

1) Change your BRS password.
2) Change your password on any site where you used that same password. If you are an average human being, you probably did that a lot of places.
3) Stop doing that. Use a password manager, and use unique passwords for every site.

I break into computer systems for a living- the difference is I only do it when hired to do so and when I get in I provide the administrators with a report on how I did it and instructions on how to fix it. (It's called "penetration testing" in the computer security industry)

If the attackers got your email address and BRS password, you can bet they will try that same email and password on other sites, since they know most people don't like to remember multiple passwords and tend to use the sames ones over and over. The old adage used to be "never write your passwords down", but I actually feel you are safer to use unique passwords everywhere you can and write them down if you need to. Just make sure you lock up or secure that piece of paper when you aren't using it.. maybe keep a backup in your safe deposit box. I think most people can relate to physically securing a piece of paper more easily than they can the electronic world.

As for BRS, while I'm sure lots of people are mad, they appear to have done the right thing here. They detected the breach, called in experts, rectified the problem, and notified their customers. Not all companies are so forthcoming, and depending on the circumstances they sometimes aren't even legally compelled to notify their customers (though I have no idea what legislature applies to BRS)

If you think this is atypical, you should probably know that penetration tests by a skilled tester are more often successful than unsuccessful when the test isn't hampered by a tiny scope ("Only this unplugged system, only during this 5 minutes of the moon cycle, and only while the tester is yodeling" etc.)
 
I received a letter from BRS today outlining the incident and the steps they have taken to protect their customers. Given the level of data that was available to hackers it seems like BRS has gone above and beyond to make amends. based on how it has been handled so far I certainly would not let this unfortunate incident deter me from shopping with them in the future.

Matt

I got the same letter with an offer for a free 1 year subscription to Expedian's ProtectMyID Alert. I didn't sign up for the Alert, as I always use PayPal on their site.. as with most others. I thought the breach was very professionally handled, and won't hesitate to shop with them in the future. Great bunch of guys up there at BRS!
 
Last edited:
Back
Top