_GOTOBOTTOM
Modeling in General
General discussions about modeling topics.
HANNANTS CC DATA BASE STOLEN
spoons
Visit this Community
England - East Anglia, United Kingdom
Member Since: January 09, 2008
entire network: 527 Posts
KitMaker Network: 19 Posts
Posted: Tuesday, October 26, 2010 - 07:49 AM UTC
I wanted to make users of Armorama aware that I've just received an email from Hannants stating that credit/debit card details entered onto their website have been stolen!
2 days earlyer my bank rang me to let me know some one had tried unsuccessfully to charge £370 to my card.
Hannants are investigating but don't know what the problem is!

Bigskip
Visit this Community
England - South East, United Kingdom
Member Since: June 27, 2006
entire network: 2,487 Posts
KitMaker Network: 464 Posts
Posted: Tuesday, October 26, 2010 - 08:05 AM UTC
My bank also called me yesterday with a strange transaction on my credit card, fortunatley only for 72 pence and all sorted, However i for one think Hannants have done the right thing in coming forward and letting people know. I think you will find that it is a third party that has been hacked, rather than Hannants themsleves, However i for one have no problems with using them or their website, it would have been very easy to say nothing, so max kudos to Hannants for coming forward.

Andy
staff_Jim
Staff MemberPublisher
KITMAKER NETWORK
Visit this Community
New Hampshire, United States
Member Since: December 15, 2001
entire network: 12,571 Posts
KitMaker Network: 4,397 Posts
Posted: Tuesday, October 26, 2010 - 08:56 AM UTC
I got this email as well (even though I am just signed up on their mailing list and have never purchased from them).


Quoted Text

Dear Customer

We are very sorry to have to tell you that a number of customers who have used our website have had their card details stolen and used by criminals.

ALL CUSTOMERS THAT HAVE ENTERED CARD NUMBERS ON OUR NEW WEBSITE PLEASE CHECK YOUR ACCOUNTS FOR SUSPICIOUS CHARGES OR ATTEMPTED CHARGES.
If you see any please contact your company that issued your card.

At the moment no one is sure how this has happened. There are several internet security firms investigating everything and we will keep you all updated as soon as we can.

There is no sign of any intrusion into the server where the card number and expiry date information that we keep is encrypted*. The CVV number is not stored.

After looking at the information we have received we think this mainly affects some customers who have sent us an order in the last 2 weeks though there are 3 from September.

We have been contacted by about 40 customers so far but are not sure how many others have had their cards compromised but have not told us yet. If you know your card has been compromised PLEASE tell us. Please send us as much information as you can as soon as you can. We need as much information as soon as possible.

Please look out for small 'insignificant' test charges of under $5.00 followed by larger charges of varying amounts. Charges have originated from different countries and in different currencies.

Until we have found out what has caused this problem and it has been fixed we have closed the website. None of the experts can find any problems with it but until the problem is resolved we prefer not to take any risks.

We have deleted ALL card numbers from the website database. We are aware that a few of you wanted access so you could delete your details but we have done this for everyone.

Paypal. We have been asked why we do not accept it. There are 2 reasons. Firstly when we started work on the new website 4 (four) years ago we could not get it to work with the fully stock controlled warehouse that we wanted to run. We did some trials but it took too long for payments arrive in our bank account which would seriously have delayed the despatch of orders. Things have now improved. Secondly it was too expensive. 3 times the cost of handling Visa and Mastercard. All our payments are now handled by Sage pay, a large British firm. Recently they have started working with Paypal and our website designers had been doing some work to incorporate it into the website. We are going to speed up the work on this and try to get it incorporated quicker.

We will re-open the website as soon as we can but will not be rushing into it.

Thank you for your help and understanding.

ALL CUSTOMERS THAT HAVE ENTERED CARD NUMBERS ON OUR NEW WEBSITE PLEASE CHECK YOUR ACCOUNTS FOR SUSPICIOUS CHARGES OR ATTEMPTED CHARGES.
If you see any please contact your company that issued your card.

* This data is stored so that customers do not have to enter it each time they order and so that we can run a back order service.




The end bit seems to indicate that it may well be possible that their system was the culprit. As a professional Web developer I have advised my clients and employers on numerous occasions NOT to store credit card information. Hannants says it was 'encrypted' but obviously it was able to be decrypted at some point to auto-populate payment screens, etc. This is fine for companies like eBay, Amazon, and GoDaddy to do with limited risk. But I somehow doubt that Hannants has the same level of network and data security as those types of companies.

Message to Hannants: Don't attempt to store CC info in future or at minimum give users the ability to opt out of that feature.

Jim

OEFFAG_153
Visit this Community
Västra Götaland, Sweden
Member Since: February 19, 2010
entire network: 1,473 Posts
KitMaker Network: 3 Posts
Posted: Wednesday, October 27, 2010 - 02:43 AM UTC
Intersesting

– This explains why my bank contacted me yesterday about suspicious activity... The card is now canceled, and a new one will be issued – no harm done to me, but really annoying none the less...

BTW I use a separate account and card for my internet buys, so even if I get scammed the damage will not be severe, this might be worth considering if you don't already do it this way.

Mikael
ludwig113
Visit this Community
England - South East, United Kingdom
Member Since: February 05, 2008
entire network: 1,381 Posts
KitMaker Network: 176 Posts
Posted: Wednesday, October 27, 2010 - 03:25 AM UTC
i used them on sunday but so far........i seem to be ok,think i'll check my account everyday though.
ludwig113
Visit this Community
England - South East, United Kingdom
Member Since: February 05, 2008
entire network: 1,381 Posts
KitMaker Network: 176 Posts
Posted: Wednesday, October 27, 2010 - 04:23 AM UTC
to be on the safe side i've just cancelled that card.

paul
Red4
Visit this Community
California, United States
Member Since: April 01, 2002
entire network: 4,287 Posts
KitMaker Network: 824 Posts
Posted: Wednesday, October 27, 2010 - 10:40 AM UTC
A couple buddies here in the states got hit for minimum amounts as suggested in Jim's message. Their banks declined the charges and canceled their accounts. At least it seems the banks are on top of things. I have a separate account for all my model related stuff and check it frequently, and I have other security measures in place. Hope they figure out what happened, and then catch the folks responsible for it....then provide them with matching bracelets. "Q"
padawan_82
Visit this Community
United Kingdom
Member Since: December 10, 2008
entire network: 817 Posts
KitMaker Network: 122 Posts
Posted: Wednesday, October 27, 2010 - 10:07 PM UTC
the same thing happened to me on monday my bank texted me saying i'd tried purchasing £250.00 worth of stuff online at O2.co.uk is this correct? i said no! i'm on T-mobile, have been for the past 10 years! immediately checked my e mail and saw the message from Hannants... now i gotta wait for a new bank card.... my confidence in hannants and their security protocols has severely been shaken... i'm strongly debating weather to reregister once i've got my new card.... i agree with Q once they catch the culprit they should give em matching bracelets, after all those they tried to rip off have kicked the crap out of them that is
Red4
Visit this Community
California, United States
Member Since: April 01, 2002
entire network: 4,287 Posts
KitMaker Network: 824 Posts
Posted: Thursday, October 28, 2010 - 01:34 AM UTC
Another one of my friends let me know last night they got him for quite a lot. The bank stopped paying the charges after use #3. All of them were to dating/escort services. Luckily his bank is waiving the amounts. My friend said they must have had a hell of a good time and he couldn't perform that well in his younger days.. I really hope Hannants gets this straightened out as I like shopping with them. "Q"
james84
Visit this Community
Roma, Italy
Member Since: January 28, 2006
entire network: 1,368 Posts
KitMaker Network: 36 Posts
Posted: Thursday, October 28, 2010 - 01:53 AM UTC
I haven't been shopping from them for a while, but my CC data were in their DB too.
Luckily I have a prepaid card issued by the Italian post system, so I just went to the ATM at a post office nearby as soon as I got the e-mail (yesterday evening) and picked up the money.
I admire Hannants for their reliability, trasparency and customer service, but I think they should implement a different system which doesn't require you to save the CC data on the website, especially if they are linked to a bank account.
Tomcat31
#042
Visit this Community
England - North East, United Kingdom
Member Since: November 18, 2006
entire network: 2,828 Posts
KitMaker Network: 212 Posts
Posted: Thursday, October 28, 2010 - 03:46 AM UTC
Although I registered on the new site I think only ever ordered for collection at a show so hopefully I'll be OK for the moment. I normally only ever use the site to check for parts then I ring the order through as I've always found the delivery to be quicker. I'll just keep an eye on my bank just in case.

The LHS who has a traders account with them on the other hand got stung big style. I told the manager last night about the email and they got a call this morning asking about a £3000 purchase fortunately it was declined
staff_Jim
Staff MemberPublisher
KITMAKER NETWORK
Visit this Community
New Hampshire, United States
Member Since: December 15, 2001
entire network: 12,571 Posts
KitMaker Network: 4,397 Posts
Posted: Thursday, October 28, 2010 - 05:06 AM UTC
Hannants has sent out another update.


Quoted Text

Dear Customer,

Investigations are still on-going but so far no problem area or trace of illegal entry can be found anywhere. How the card numbers were taken is still a mystery. Two firms are still looking at everything and we hope to have their reports in soon. For now we are still not prepared to fully re-open the website.

We have PARTIALLY re-opened the website. We have done this so you can check that we are telling the truth that the card details have been removed and so that you can use all the other parts of the site. We suggest that while you are logged in you also check any items that are on back order and/or in your cart and adjust as required.

Currently you cannot enter new card details at this time or send orders to us but most other facilities are still operating as usual.

We have temporarily stopped sending out back orders just in case sending the data that goes with ordering is where the problem is. We have been told that it is encrypted everywhere and is not a problem area so now we do not think it is but we need to be certain.

TELFORD SHOW ORDERS. To send us an order for collection at the show please add a Collect from show address with your name on as usual, add what you want to buy to your cart as before BUT then email us to say it is there in your cart. We will then download it and have it ready for collection and payment at the show. You do not pay until you collect so we do not need any payment now.

MAILORDERS. WE CAN NOW ACCEPT ORDERS THIS WAY... Please put your order in the cart as normal then TELEPHONE or FAX us with your card details. We will then download your order and attach the card details to the order. We will then be able to process your order. Our email is not secure so we cannot recommend you send your card details that way.

Please be aware that the cart only 'remembers' items if they are actually saved in the cart. Items in the Quick Order only do not get saved.

We will email more information as soon as we can. Quite a few customers have told us that they are on the emailing (Hot News) list but have not received an email from us. We think this is because they are being stopped as spam. Mostly the customers are with Hotmail, Yahoo, AOL and of course BT. If you can pass our emails to any of your modelling friends please do.

Everyone at Hannants would like to say a massive 'thank you' for the emails, and phone calls of support, help and encouragement you have sent us. With the exception of about 8 people your support has been fantastic.

Congratulations should also go to the worlds banking system who seem to have spotted and stopped the majority of the charges before they got to the customer.

Best regards

Hannants

staff_Jim
Staff MemberPublisher
KITMAKER NETWORK
Visit this Community
New Hampshire, United States
Member Since: December 15, 2001
entire network: 12,571 Posts
KitMaker Network: 4,397 Posts
Posted: Thursday, October 28, 2010 - 01:10 PM UTC
And another update. This one clearly stating that if you entered your card info in the new website (on or after March 23, 2010) they recommend cancelling that card.


Quoted Text

Dear Customer,

Two of the investigations into our problem and have come back but failed to find anything significant.

We have analysed a lot (but not all yet) of the information our customers have sent us. We can confidently say that no information was captured as orders were transmitted. This means that we should be able to re-open the website quite quickly.

However it does mean that we still do not know how the data was accessed and so have to recommend that anyone who registered their card details on the NEW website CANCEL the card with their bank. We realise this is annoying, irritating, time consuming and inconvenient but we think it is the safest thing to do under these circumstances.


PLEASE CANCEL ANY CREDIT OR DEBIT CARD THAT WAS REGISTERED ON OUR NEW WEBSITE. (registered on or after March 23rd 2010)


We will re-open as soon as possible with a new system that does not remember the card details. This will be annoying for our customers who order regularly and will not want to enter their card details each time but we think it is the best way to go at the moment.

This will mean that we will not be able to automatically send any back orders. We will NOT be cancelling any back orders and will send you all revised Back Order details as soon as we have decided on the best way to handle them. For the moment you can add any available items to your cart and then phone or fax your card details through. Then we can download the order from your cart and attach the card details. We will charge and despatch as soon as we can.


TELFORD SHOW ORDERS. To send us an order for collection at the show please add a Collect from show address with your name on as usual. Add what you want to buy to your cart as before BUT then email us to say it is there in your cart. We will then download it and have it ready for collection and payment at the show. You do not pay until you collect so we do not need any payment now. The country in the delivery address should be Collect from show NOT United Kingdom or any other country.

MAILORDERS. WE CAN NOW ACCEPT ORDERS THIS WAY. BUT ONLY THIS WAY PLEASE. Please put your order in the cart as normal then TELEPHONE or FAX us with your card details. We will then download your order and attach the card details to the order. We will then be able to process your order. Our email is not secure so we cannot recommend you send your card details that way though we know a lot of you will.

PLEASE DO NOT PHONE OR FAX OR POST YOUR ORDERS TO US AT THE MOMENT. WE ARE GRATEFUL FOR FOR YOUR ORDERS BUT CANNOT LOAD THEM TO THE WEBSITE AS QUICKLY AS YOU CAN.

We are sending this email via 2 methods so as to try and get it delivered. We apologise if you receive it twice.

We are still receiving immense amounts of support and help and we thank you all for it.

Best regards

Hannants.

Eloranta
Visit this Community
Hame, Finland
Member Since: November 30, 2008
entire network: 286 Posts
KitMaker Network: 12 Posts
Posted: Thursday, October 28, 2010 - 02:35 PM UTC
"We will re-open as soon as possible with a new system that does not remember the card details. This will be annoying for our customers who order regularly and will not want to enter their card details each time but we think it is the best way to go at the moment."

Ok, hands up who's annoyed everytime they have to enter card details every time they order something? You sir should stop building models immediately, they contain also annoying repetative tasks.
wizard179
Visit this Community
New South Wales, Australia
Member Since: January 27, 2006
entire network: 251 Posts
KitMaker Network: 46 Posts
Posted: Thursday, October 28, 2010 - 04:30 PM UTC
the compromise might be worse than they think.

Ironically, about 30mins after reading this thread I recieved a call from CC provider querying transactions, which unfortunately are fraudulent.

I haven't bought anything from Hannants for months and by that I mean 6-12 months so either it's a coincidence, a common processing house or hannants's compromise is worse than they think. I will send them a mail to let them know as well.

Wiz
35th-scale
Visit this Community
Kildare, Ireland
Member Since: November 21, 2007
entire network: 3,212 Posts
KitMaker Network: 250 Posts
Posted: Sunday, October 31, 2010 - 08:01 PM UTC

Quoted Text



Congratulations should also go to the worlds banking system who seem to have spotted and stopped the majority of the charges before they got to the customer.

Best regards

Hannants



Agreed. Banks over here have had a lot of bad press lately, and rightly so, but in this instance they spotted the suspicious transactions on my account and suspended it. Once contact was made with me and the transactions were verified as fraudulent they have now cancelled the account and I'm awaiting a new card: but I didn't get stung. For that I'm grateful.
james84
Visit this Community
Roma, Italy
Member Since: January 28, 2006
entire network: 1,368 Posts
KitMaker Network: 36 Posts
Posted: Saturday, November 06, 2010 - 03:10 AM UTC
Have you experienced some small transactions on your cards?
AlanL
Visit this Community
England - East Anglia, United Kingdom
Member Since: August 12, 2005
entire network: 14,499 Posts
KitMaker Network: 411 Posts
Posted: Saturday, November 06, 2010 - 03:20 AM UTC
Hi Guys,

They (who ever they are) must be working their way diown the list. My card got hit yesterday at some point, several small transactions, but I had already asked the bank to keep an eye on it so they didn't get much.

Ended up cancelling the card.

Al
Jasonbee71
#009
Visit this Community
England - South East, United Kingdom
Member Since: March 03, 2003
entire network: 686 Posts
KitMaker Network: 74 Posts
Posted: Saturday, November 06, 2010 - 03:42 AM UTC


I had my debit and credit card hit, but luckily I managed to call my bank about the pending transaction on my debit card and had it cancelled in time so I didn't lose anything., and my credit card company noticed suspicious behaviour on my credit card and cancelled it, no real damage done personally, I may just decide to make purchases at shows and not use the internet, may make me spend a lot less and help keep the stash a respectable size......

Jason
Silantra
Visit this Community
Putrajaya, Malaysia
Member Since: March 04, 2004
entire network: 2,511 Posts
KitMaker Network: 1,296 Posts
Posted: Tuesday, November 09, 2010 - 12:00 PM UTC
Yesterday my cc company call me to verify a few transaction that i didnt do... i was so surprise but off course i denied those transactions and asked them to investigate. Few hours later the bank security department called me. They said, i was charged twice on Nov 5 for GBP 1.0 and then on Nov 8 for approx USD600 for a purchase from apple.com. They managed to track the transaction was done from a proxy server in China... luckily for me the SOB failed the security check.
Now my cc is being cancelled and waiting for a new one.

So far i only shop once at hannants and that was 2-3 years ago... and i never received their email as what Staff Jim and others got. I only learn this on the internet.
Some local modeller that has been shop in hannants also involved in this incident.

Bigskip
Visit this Community
England - South East, United Kingdom
Member Since: June 27, 2006
entire network: 2,487 Posts
KitMaker Network: 464 Posts
Posted: Tuesday, November 09, 2010 - 08:52 PM UTC
Just for the conspiracy theorists out there, my boss, who thinks i'm a **** (insert your own expletive here) for spending money on bits of plastic has been hit too, he has never used Hannants, methinks there is a bigger problem going on with a clearing company, rather than hannants!!

I will state again that i am very impressed with Hannants reaction to this and they must be given due credit for their openness and honesty.

I was never much of a fan of theirs, delivery times being suspect etc, but now they have improved that, are coming into the 21st century and will be getting my support, and i feel we should all support them. Many companies would not have been so honest, and really if they hadn't come forward would we all know about it??

Just my £0.02

Andy
Torchy
#047
Visit this Community
England - East Anglia, United Kingdom
Member Since: September 13, 2005
entire network: 2,016 Posts
KitMaker Network: 237 Posts
Posted: Friday, November 12, 2010 - 12:32 AM UTC
My bank called,several transactionsto a total of just under £900 were tried and rejected
Andy
docdios
#036
Visit this Community
England - West Midlands, United Kingdom
Member Since: December 01, 2001
entire network: 1,998 Posts
KitMaker Network: 257 Posts
Posted: Friday, November 12, 2010 - 02:25 AM UTC
yep I had mine done last night, luckily the bank put a stop to it just several small transactions to Vodafone, it look like they are slowly working down a list as my last dealing with Hannants was back in june.

will take a few days to be my money back but it was only around £60, luckily for me that account never has a lot in it any way

cheers

Keith
ianclasper
Visit this Community
Washington, United States
Member Since: September 02, 2009
entire network: 227 Posts
KitMaker Network: 9 Posts
Posted: Friday, March 25, 2011 - 07:23 AM UTC
Looks like this specter is still at large.

My Bank of America Credit Card has just been canceled after several strange charges were attempted from the UK. Someone tried to buy airline tickets (Easyjet) with the card as well as some other transactions which BofA considered to be out of the ordinary.

I hardly use this card and Hannants was one of the few places that I had used the card online just prior to their incident , thus I suspect that the card details that were harvested have been sat upon til now.

Ian
 _GOTOTOP