Stamp Community Family of Web Sites
Thousands of stamps, consistently graded, competitively priced and hundreds of in-depth blog posts to read








Stamp Community Forum
 
Username:
Password:
Save Password
Forgot your Password?

This page may contain links that result in small commissions to keep this free site up and running.

Welcome Guest! Registering and/or logging in will remove the anchor (bottom) ads. It's Free!

Stamp Auction Network Hacked

Previous Page
 
To participate in the forum you must log in or register.
Author Previous TopicReplies: 28 / Views: 6,680Next Topic
Page: of 2
Pillar Of The Community
United States
4123 Posts
Posted 09/28/2017   11:25 pm  Show Profile Check eyeonwall's eBay Listings Bookmark this reply Add eyeonwall to your friends list  Get a Link to this Reply

Quote:
Like you, I do not trust 'cloud' storage


Nor I.
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
978 Posts
Posted 09/29/2017   04:47 am  Show Profile Bookmark this reply Add jbcev80 to your friends list  Get a Link to this Reply
Hi

I agree with Don about security. The general public has no "clue" as to what is being said. They hear the phrase "SSL" and, having been told that it is "high security", put all sorts of personal information on the internet. Personally, I have a rule: No SSN or credit card information on-line.

As to Cloud storage. I think too much is made of it. I would rather have a DVD, or CD, with the information. That way, anything critical can be stored "off-site". What happens to ones information if the Cloud provider is compromised?

Jerry B
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
4447 Posts
Posted 09/29/2017   07:00 am  Show Profile Bookmark this reply Add angore to your friends list  Get a Link to this Reply
Everyone just needs to remember that their personal information probably has already been stolen even if you avoid online transactions because others like Equifax are following you...it just has not been reported. Some thefts are just using misused credentials -- like in the case of the NSA thefts.
Send note to Staff  Go to Top of Page
Al
Edited by angore - 09/29/2017 07:01 am
Pillar Of The Community
United States
507 Posts
Posted 09/29/2017   07:27 am  Show Profile Bookmark this reply Add dkabq8 to your friends list  Get a Link to this Reply
I trust cloud storage about as much I trust any other storage -- not completely. I make back-ups to a NAS and the cloud, and for just-can't-lose information, a DVD copy stored not at home. YMMV.
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
4447 Posts
Posted 09/29/2017   07:39 am  Show Profile Bookmark this reply Add angore to your friends list  Get a Link to this Reply
I try keep a copy of everything in the cloud..
Send note to Staff  Go to Top of Page
Al
Bedrock Of The Community
12630 Posts
Posted 09/29/2017   07:39 am  Show Profile Bookmark this reply Add rogdcam to your friends list  Get a Link to this Reply
We can all pretty much assume that our information has been compromised in some way, shape or form. The forms I submitted to the DoD for my security clearance were stolen in the OMB hack several years ago and so the government's security is far from robust. There is no "safe" place.
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
507 Posts
Posted 09/29/2017   10:11 am  Show Profile Bookmark this reply Add dkabq8 to your friends list  Get a Link to this Reply
@rogdcam

I am in the same boat as you, the ChiComs got my OMB clearance data too.
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
1179 Posts
Posted 09/29/2017   7:23 pm  Show Profile Bookmark this reply Add Hal to your friends list  Get a Link to this Reply
Interesting. They informed their Business-Users NOT their Customer-Users! Very poor practice on Tom Droge's part -- as I'm a frequent "Customer" using the portal and I never received a notification of the "hack."
Send note to Staff  Go to Top of Page
Edited by Hal - 09/29/2017 7:24 pm
Pillar Of The Community
United States
6454 Posts
Posted 09/29/2017   8:35 pm  Show Profile Check revenuecollector's eBay Listings Bookmark this reply Add revenuecollector to your friends list  Get a Link to this Reply

Quote:
Interesting. They informed their Business-Users NOT their Customer-Users! Very poor practice on Tom Droge's part -- as I'm a frequent "Customer" using the portal and I never received a notification of the "hack."


Huh?

I'm not a business user of SAN. I'm a buyer/bidder. So are others who have posted here.

Did you have a credit card on file with SAN? If not, that is possibly the reason why you weren't notified... beyond the normal junk/spam mail reasons.
Send note to Staff  Go to Top of Page
Pillar Of The Community
Canada
707 Posts
Posted 10/06/2017   5:02 pm  Show Profile Bookmark this reply Add dutchman1948 to your friends list  Get a Link to this Reply
Not sure who has heard about it and who has not but it totally P's me off. Here is what I got today as my guess is they are scared of getting sued. I have XXXX out my personal info.


October 6th, 2017
John XXXXX

Official Notice of Data Breach

Dear John XXX :

Please read this letter in its entirety. On September 28th, we notified you of this data breach. This is the formal advice as directed by our insurance company.

What happened? What information was involved?
We recently became aware that our StampAuctionNetwork (SAN) server was hacked on September 26, 2017. The attack did not target StampAuctionNetwork directly, we have SSL security there which protects from external attacks. The breach was made through our main offices and they were able access SAN from there. We took immediate steps to stop the access and respond to the situation. Based on our review of the systems, we have discovered that some of your personal data may have been compromised. This data includes your name and payment card information.

While we have no evidence that any of your personal information has been misused in any manner, we are taking appropriate precautionary measures to ensure your financial security and help alleviate concerns you may have.

Your VISA Credit Card Ending in XXXX with Expiration date XXXX may have been compromised. We suggest you cancel this card and request a new one, if this card is still active.

What is Droege Computing Services, Inc. doing to address this situation?
Droege Computing Services, Inc. has made immediate enhancements to our systems, security and practices. Additionally, we have engaged appropriate experts to assist us in conducting a full review of our security practices and systems to ensure that appropriate security protocols are in place going forward and we have removed all credit card information from SAN. We are committed to helping those people who may have been impacted by this unfortunate situation.

What can I do on my own to address this situation?


If you choose to place a fraud alert, you will need to contact one of the three major credit agencies directly at:

Experian (1-888-397-3742) Equifax (1-800-525-6285) TransUnion (1-800-680-7289)
P.O. Box 4500 P.O. Box 740241 P.O. Box 2000
Allen, TX 75013 Atlanta, GA 30374 Chester, PA 19016
http://experian.com www.equifax.comwww.transunion.com

Also, should you wish to obtain a credit report and monitor it on your own:

IMMEDIATELY obtain free copies of your credit report and monitor them upon receipt for any suspicious activity. You can obtain your free copies by going to the following website: http://annualcreditreport.com or by calling them toll-free at 1-877-322-8228. (Hearing impaired consumers can access their TDD service at 1-877-730-4204.
Upon receipt of your credit report, we recommend that you review it carefully for any suspicious activity.
Be sure to promptly report any suspicious activity to Droege Computing Services, Inc. and your credit card company.


In addition, we are urging all customers to notify their bank of this incident to inform them that your account may be at an increased risk for fraud and so that your bank can flag your account. We also encourage you to monitor your accounts closely for any suspicious activity and to notify your financial institution immediately if you notice any unauthorized transactions.

For More Information
You can obtain more information about identity theft and ways to protect yourself from the Federal Trade Commission (FTC). The FTC has an identity theft hotline: 877-438-4338; TTY: 1-866-653-4261. They also provide information on-line at http://ftc.gov/idtheft.

What if I want to speak with Droege Computing Services, Inc. regarding this incident?
Please call Tom Droege at 919-403-9459 from 9-5pm Eastern Standard Time, Monday through Friday.

At Droege Computing Services, Inc. we take our responsibilities to protect your personal information very seriously. We are deeply disturbed by this situation and apologize for any inconvenience.

Sincerely,

Thomas Droege
President and CEO
Additional Important Information
For residents of Hawaii, Michigan, Missouri, Virginia, Vermont, and North Carolina:
It is recommended by state law that you remain vigilant for incidents of fraud and identity theft by reviewing credit card account statements and monitoring your credit report for unauthorized activity. For residents of Illinois, Iowa, Maryland, Missouri, North Carolina, Oregon, and West Virginia:
It is required by state laws to inform you that you may obtain a copy of your credit report, free of charge, whether or not you suspect any unauthorized activity on your account. You may obtain a free copy of your credit report by contacting any one or more of the following national consumer reporting agencies:
Equifax Experian TransUnion
P.O. Box 740241 P.O. Box 22104 P.O. Box 2000
Atlanta, GA 30374 Allen, TX 75013 Chester, PA 19022
1-800-685-1111 1-888-397-3742 1-800-888-4213
www.equifax.com www.experian.com www.transunion.com
You may also obtain a free copy of your credit report online at http://annualcreditreport.com, by calling toll-free 1-877-322-8228, or by mailing an Annual Credit Report Request Form (available at http://annualcreditreport.com) to: Annual Credit Report Request Service, P.O. Box 105281, Atlanta, GA, 30348-5281. For residents of Iowa:
State law advises you to report any suspected identity theft to law enforcement or to the Attorney General. For residents of Oregon:
State laws advise you to report any suspected identity theft to law enforcement, as well as the Federal Trade Commission. For residents of Maryland, North Carolina, and Illinois:
You can obtain information from the Maryland and North Carolina Offices of the Attorneys General and the Federal Trade Commission about fraud alerts, security freezes, and steps you can take toward preventing identity theft.
Maryland Office of the North Carolina Office of the Federal Trade Commission
Attorney General Attorney General Consumer Response Center
Consumer Protection Division Consumer Protection Division 600 Pennsylvania Avenue, NW
200 St. Paul Place 9001 Mail Service Center Washington, DC 20580
Baltimore, MD 21202 Raleigh, NC 27699-9001 1-877-IDTHEFT (438-4338)
1-888-743-0023 1-877-566-7226 www.ftc.gov/bcp/edu/microsites/idtheft
www.oag.state.md.us www.ncdoj.com
For residents of Massachusetts:
State law requires you be informed of your right to obtain a police report if you are a victim of identity theft. For residents of all states:
Fraud Alerts: You can place fraud alerts with the three credit bureaus at one of the three major credit bureaus by phone and also via Experian#146;s or Equifax#146;s website. A fraud alert tells creditors to follow certain procedures, including contacting you, before they open any new accounts or change your existing accounts. For that reason, placing a fraud alert can protect you, but also may delay you when you seek to obtain credit. The contact information for all three credit bureaus is below:
Monitoring: You should always remain vigilant and monitor your accounts for suspicious or unusual activity.
Security Freeze: You also have the right to place a security freeze on your credit report. A security freeze is intended to prevent credit, loans and services from being approved in your name without your consent. To place a security freeze on your credit report, you need to make a request to each consumer reporting agency. You may make that request by certified mail, overnight mail, or regular stamped mail, or by following the instructions found at the websites listed below. The following information must be included when requesting a security freeze (note that if you are requesting a credit report for your spouse, this information must be provided for him/her as well): (1) full name, with middle initial and any suffixes; (2) Social Security number; (3) date of birth; (4) current address and any previous addresses for the past five years; and (5) any applicable incident report or complaint with a law enforcement agency or the Registry of Motor Vehicles. The request must also include a copy of a government-issued identification card and a copy of a recent utility bill or bank or insurance statement. It is essential that each copy be legible, display your name and current mailing address, and the date of issue. The consumer reporting agency may charge a small fee to place, life, or remove a freeze, but is free if you are a victim of identity theft or the spouse of a victim of identity theft, and you have submitted a valid police report relating to the identity theft incident to the consumer reporting agency. You may obtain a security freeze by contacting any one or more of the following national consumer reporting agencies:
Equifax Security Freeze Experian Security Freeze TransUnion (FVAD)
P.O. Box 105788 P.O. Box 9554 P.O. Box 2000
Atlanta, GA 30348 Allen, TX 75013 Chester, PA 19016
https://www.freeze.equifax.com/Free...alIDInfo.jsp https://www.experian.com/freeze/center.html https://freeze.transunion.com

More information can also be obtained by contacting the Federal Trade Commission listed above.

Send note to Staff  Go to Top of Page
Bedrock Of The Community
12630 Posts
Posted 10/06/2017   5:23 pm  Show Profile Bookmark this reply Add rogdcam to your friends list  Get a Link to this Reply
Just received my notice today that my info was stolen. Not sure why it took 10 days to let me know.
Send note to Staff  Go to Top of Page
Pillar Of The Community
United States
6454 Posts
Posted 10/06/2017   5:42 pm  Show Profile Check revenuecollector's eBay Listings Bookmark this reply Add revenuecollector to your friends list  Get a Link to this Reply

Quote:
Just received my notice today that my info was stolen. Not sure why it took 10 days to let me know.


I would check spam/junk filters and if you cannot find it then call Tom and ask why. I was notified literally within 2 days of the hack and I am very small potatoes as a SAN bidder.
Send note to Staff  Go to Top of Page
Bedrock Of The Community
12630 Posts
Posted 10/06/2017   5:51 pm  Show Profile Bookmark this reply Add rogdcam to your friends list  Get a Link to this Reply
I really do not blame SAN. My information has been stolen multiple times now in different hacks including my clearance paperwork for the DoD which was stolen in the OMB hack. It is pretty much a given nowadays that your information will be compromised at some point. What makes me uncomfortable is not knowing when damage may be done by the bad guys. Tomorrow? Next year? Five years from now? Not a good situation.
Send note to Staff  Go to Top of Page
Page: of 2 Previous TopicReplies: 28 / Views: 6,680Next Topic  
Previous Page
 
To participate in the forum you must log in or register.

Go to Top of Page

Disclaimer: While a tremendous amount of effort goes into ensuring the accuracy of the information contained in this site, Stamp Community assumes no liability for errors. Copyright 2005 - 2026 Stamp Community Family - All rights reserved worldwide. Use of any images or content on this website without prior written permission of Stamp Community or the original lender is strictly prohibited.
Privacy Policy / Terms of Use    Advertise Here
Stamp Community Forum © 2007 - 2026 Stamp Community Forums
It took 0.23 seconds to lick this stamp. Powered By: Snitz Forums 2000 Version 3.4.05