Was "Home Shopping Network" hacked?

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
Cass Broadview
Posts: 292
Joined: 27 Oct 2007 11:34 am
State/Province: -
Country: United States

Was "Home Shopping Network" hacked?

Post by Cass Broadview »

Was the "Home Shopping Network" hacked, and information about me given out? Is this legit? I do have a HSN credit card. I'm concerned because it starts out "Dear HSN Customer,".
Important Customer Service Notification

Sunday, April 3, 2011 3:02 AM
From: This sender is DomainKeys verified"HSN Customer Service" <CommunityNews>
Add sender to Contacts


April 2, 2011

Dear HSN Customer,

HSN values your trust and wants to make you aware of a recent incident. We learned from our email provider, Epsilon, that limited information about you was accessed by an unauthorized individual or individuals. This information included your name and email address and did not include any financial or other sensitive information. We felt it was important to notify you of this incident as soon as possible. We apologize for any inconvenience and have outlined below a number of email safeguards to help ensure your privacy online.

Email scams, spam, and other attacks on email systems are on the rise, but, by taking certain precautions when receiving emails, you can continue to safely use email for your business and personal needs:

•Don't open links or attachments from people you don't know and trust.
•Don't provide personal, financial, or other sensitive information when asked to do so by email. Most reputable companies do not ask for such information by email, and, rest assured, we will not do so.
•If you receive an email appearing to come from us that does ask you for sensitive information, do not respond, click on any links, or download any attachments. Instead, please inform us immediately at the toll-free number or email address provided below.

We take your privacy very seriously and work diligently to protect your information, whether held by us or by our service providers. HSN's internal databases, which store all customer-provided data, were in no way compromised. Our email provider has taken significant steps to further protect the limited customer information held in its databases. If you have any questions or concerns regarding this incident, please contact us toll free at 1-800-933-2887 or email us at customerservice@hsn.com.

Sincerely,
Gregg Stallwood
Senior Vice President, Customer Care – HSN

Please do not reply to this email. If you would like to contact us, please call us toll free at 1-800-933-2887 or email us at customerservice@hsn.com.
HSN Interactive LLC | Attn: Customer Service | 1 HSN Drive | St. Petersburg, FL 33729‪
User avatar
Jack Stoner
Posts: 22147
Joined: 3 Dec 1999 1:01 am
Location: Kansas City, MO
State/Province: Kansas
Country: United States

Post by Jack Stoner »

It appears to be legitimate. Several major clients that also use Epsilon also have the same issue. It looks like name and e-mail is apparently the only thing potentially hacked into.

Here is more info from Computerworld:

CLICK ME
User avatar
Wiz Feinberg
Posts: 6117
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

You can include Kroger customers in the group of stolen email addresses and names of the people holding the accounts. This is rapidly becoming a monster hacking incident. Somebody at Epsilon was tricked into opening a Trojan Horse in an attachment. It was a Spear Phishing attack, targeting one specific individual and it worked.

Anyway, those affected can login to their accounts and change the passwords.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Jim Smith
Posts: 7949
Joined: 4 Aug 1998 11:00 pm
Location: Midlothian, TX, USA
State/Province: -
Country: United States

Post by Jim Smith »

Just heard on the news that you can add Walgreens to the hacked list. I think Epsilon has some 'splainin' to do! :x
User avatar
Chris Dorch
Posts: 490
Joined: 15 Feb 2010 3:55 pm
Location: Wisconsin, USA
State/Province: Wisconsin
Country: United States

Post by Chris Dorch »

Add Best Buy...
User avatar
Wiz Feinberg
Posts: 6117
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

You can now add J.P. Morgan Chase Bank. However, the notice they sent says that it was mostly their own internal company email accounts and user names that were harvested. We shall see...
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Cass Broadview
Posts: 292
Joined: 27 Oct 2007 11:34 am
State/Province: -
Country: United States

Post by Cass Broadview »

Yikes! thanks guys. I have a habit a leaving credit card info on my user accounts for easy paying. Is that a wise thing to do? I have accounts at JC Penney, Sears, HSN, QVC etc, and of course on file with my paypal account. :?:
User avatar
Jack Stoner
Posts: 22147
Joined: 3 Dec 1999 1:01 am
Location: Kansas City, MO
State/Province: Kansas
Country: United States

Post by Jack Stoner »

According to what has been posted, this is a company that sends out advertising for client companies. They could have your name and e-mail address but nothing else. Your personal info, including credit card, is only on the actual client's site (e.g. HSN site).