CC WARNING!!! TheNerds.net HACKED

JPSJPS

Senior member
Apr 17, 2001
216
0
0
I just got an E-mail containing my L/P & credit card # from a hacker that had hacked TheNerds credit card database.
I called TheNerds and they confirmed that had happened!
Time to go to the bank and change numbers.
John

EDIT: 05/29/2002 at 11:51 AM - Watch out. TheNerds is not admittting that their customer information was actually hacked and that the hacker has the full information. Yet, I had earlier informed them that the hacker's mail to me included my *FULL* credit card #, expiration date, Email addr, home addr, & home phone #.
I have posted their Email to me in a later post below. This is because, in spite of their mail, we customers are still in trouble and need to cancel these cards!
Is this the kind of company that you want to do business with?


EDIT#2: 05/29/2002 at 4:13 PM - TheNerds finally sent another Email admitting that some CC#s were compromised and told us to contact our credit card company. That is what I think they should have said originally, but better late than never.

---

This needs a sticky for awhile.

Mod
 

Emulex

Diamond Member
Jan 28, 2001
9,759
1
71
those shops get 0wned all the time. You should still use the one-time CC # feature!!! whenever possible.
 

OrlandoTiger

Golden Member
Jul 16, 2001
1,427
0
0
AHHH... I ordered from these guys last year,they were a good store... now im wondering if they kept my card info on file... Has anyone else confirmed this report?If this is the case,what a pain...
thanks for the heads up JPSJPS
 

JPSJPS

Senior member
Apr 17, 2001
216
0
0
Originally posted by: OrlandoTiger
AHHH... I ordered from these guys last year,they were a good store... now im wondering if they kept my card info on file... Has anyone else confirmed this report?If this is the case,what a pain...
thanks for the heads up JPSJPS

The following is a copy of the Email I got from TheNerds:

Note the use of the words "potentially", "no indication that any customer information has been compromised", "threat", "may", "claims to present "evidence"", "Remember how easy it is, online, for people to forge evidence and make it appear to be legitimate", etc.
These are nothing but LIES! I had earlier contacted TheNerds and informed them that the hacker *EXACTLY* stated my *FULL* credit card #, expiration date, Email addr, home addr, & home phone # in his Email to me.
Is this the kind of company that you want to do business with?


Dear Customer,

TheNerds.net has discovered that a hacker has accessed our computer systems, potentially
including our customer databases. While there is no indication that any customer
information has been compromised, as a precautionary measure, we have taken immediate steps to
protect you by contacting the U.S Secret Service and the FBI.

Since speaking with law enforcement we have discovered who the hackers are and their
motives. Just recently another internet company was a victim of "Zilterio". Lead by a man
who calls himself "Mr. Zilterio," they wanted $50,000 transferred to a bank account that
was traced through Russia to Yemen.

The threat? Zilterio claimed that they had, or might be able to access confidential
customer information, to include credit card numbers.

Here are some of the details that we have learned.

¤ We quickly learned, from talking to law enforcement authorities
and other victims, that the same criminal and his associates
had extorted as much as $4 billion from other companies using
similar tactics.

¤ We found that they may, in fact, have exploited an obscure and
previously unknown hole in a common commercial software program
we use, one that's supposed to be very secure.


¤ This "Mr. Zilterio" may, if he follows a pattern he's established
when attacking other organizations, send you email which claims to
present "evidence" that he has access to confidential information,
and/or that he was actually trying to "help" TheNerds.Net with its
security. Remember how easy it is, online, for people to forge
evidence and make it appear to be legitimate. All you have to do is
conduct a little online research of your own about Zilterio to find proof
that he is nothing more than a extortionist, a criminal, a cyber-terrorist.


In order to combat Zilterio and any future hackers, we have retained the world's leading
computer security experts to conduct a thorough investigation of our security procedures
and an analysis of this breach.

¤ We quickly plugged that hole and have now taken extraordinary
additional steps to put customer data where it cannot be accessed
except locally by authorized staff.

¤ We notified the major credit card companies of the threat and
they have placed a special watch on your credit card numbers --
this will NOT affect your ability to use the card, but some of
you may get occasional calls from your credit card issuer just
to make sure that certain charges were, in fact, made by you.

We wish to underscore that we have taken these steps as precautions. We have no
information at this time to suggest that any credit card information has been or will be used in
any fraudulent manner. We feel that this was vandalism against TheNerds.net rather than
our customers. We are investigating this possibility, and we are doing everything we can to
proactively protect you. If you would like further information, you may wish to contact
the issuer of your credit card to determine what steps you should take. We regret any
inconvenience this may cause you.

If you have additional questions, please call our customer service team at 1-888-566-NERD
(566-6373).

Respectfully,

TheNerds.net



 

slycat

Diamond Member
Jul 18, 2001
5,656
0
0
they sux...yes 1-time use card # are a necessity these days.
...i use my Citibank card "Virtual numbers"...it takes a bit longer but its worth it.
 

shurato

Platinum Member
Sep 24, 2000
2,398
0
76
Their website is not showing up....damn, i bought a printer from them and I think I remember them requiring you to put a credit card on file with them and not having the option to just input it each time you order. IF that is truely the case, they are morons...I need to find out what credit card I have with them on file.
 

JPSJPS

Senior member
Apr 17, 2001
216
0
0
Originally posted by: shurato---I need to find out what credit card I have with them on file.
You need get in touch with the hacker "Mr Ziltero" who earlier sent this mail to me ;-)
(NOTE: I replaced the private stuff with XXXXs but they were all correct.
I guess the Wed May 02 Date comes from his computer)
----------------------------------------------------------------------------------------------------------------------------------
Subject: Your account has been hacked

From: "Mr. Zilterio" <zilterio@yahoo.com> | Block Address | Add to Address Book

To: XXXXXXXX@yahoo.com

Date: Wed May 02 Russian Daylight Time

Dear, John XXXXXX

I hate to inform you that your account
has been hacked on THENERDS.NET. This site has
a very weak security protection system and
the database with credit cards and other
personal information is not protected at all.
Your personal details:

name: John XXXXXXX (id: XXXX )
email: XXXXXXXX@yahoo.com , password: XXXXXX
address: XXXX West XXX Ave Placentia
CA 92870 US
phone: XXX-XXX-XXXX ,

Your credit card (account) information:

card number: XXXXXXXXXXXXXXXX
expiration time: XXXXXX

We offered them our help many times. But top
management of THENERDS.NET doesn't care about
their customers - you. They care only about
their money.

zilterio


 

OrlandoTiger

Golden Member
Jul 16, 2001
1,427
0
0
Hmmm,hadnt thought about writing the hacker to see if he'll be generous and tell me which card of mine he has the info on!Its a funny world we live in isnt it?How about,dear Mr Hacker Sir,please dont use my card until I find out which one it is you now own...
No word from the hacker in email yet,but I did get this from the Nerds...
Dear Customer,

Thank you for your patience and understanding with regards to the hacking of the
customer databases at TheNerds.net. Please know the email you received earlier
today describing the situation was sent as soon as we became aware our data was
compromised. Unfortunately, due to the number of messages sent, you might have
experienced a delay in receiving this e-mail. As we described in that message,
there was no indication at that time that any customer information had been
compromised.

After conferring with the FBI, Secret Service and several valued customers, it
has become clear that your personal and credit card information might have been
compromised. In fact, some customers even received their credit card numbers
from this self-confessed cyber-terrorist over a non-secure internet connection.
Because of this most unfortunate development, we highly recommend that all
previous customers contact their credit card company, inform them that your card
might be compromised and seek their recommendation for a course of action.

In addition, we are pleased to report we have discovered and repaired the hole
which this criminal used to violate each of us. Unfortunately, Microsoft made
the public aware of the hole just last week. In addition to repairing the hole,
we are now changing the way our customer information is stored. Customer data
will no longer be accessible by anyone, even our internal staff, over any type
of Internet connection.

We sincerely invite your feedback and are happy to answer any questions, however
note this is a no-reply email address. Becuase we are using a newsletter
managment system to send this to you, messages sent as a reply to this e-mail
might not be read by our staff. Should you wish to contact us via e-mail, please
write to info@thenerds.net. In addition, should you wish to call us, you may do
so at 888-566-NERD from 8:30 - 6:00 EST. Thank you for the many emails we
received from you today. We will surely answer each email, however as you can
imagine, we are currently focusing on fixing the immediate problem at hand.

Again, thank you for your patience and understanding. We hope to service your
computer needs in the near future.

Regards,

Jeremy Schneiderman and David Kriegstein
Principals
Computer Nerds International, Inc.

thanks again for the heads up on this JPSJPS
 

olds

Elite Member
Mar 3, 2000
50,071
744
126
This is great. First my employeer gets hacked and they get our names, addresses, SSAN, etc. Now My CC # gets stolen at the nerds.net. What next? ATTBI going to start charging me more because I own my own modem? Sheessh! Oh, wait.......
 

CasioTech

Diamond Member
Oct 1, 2000
7,145
9
0
haha I used to work there, here in miami, I did some web work for them, and networking, a++. Haven't spoke with the owners for about 1 yr now.
 

huesmann

Diamond Member
Dec 7, 1999
8,618
0
76
I hope they track down this guy in some Muslim country where they follow sharia and chop his hands off. :|
 

olds

Elite Member
Mar 3, 2000
50,071
744
126
Originally posted by: CasioTech
haha I used to work there, here in miami, I did some web work for them, and networking, a++. Haven't spoke with the owners for about 1 yr now.
thenerds.net? I had a good customer service experience with them. Not much of that in this day and age.

 

CasioTech

Diamond Member
Oct 1, 2000
7,145
9
0
yup if anyone is familiar w/ the area they are here off biscayne blvd, next to the post office. About two years ago, they sucked, and had high prices, b/c they couldn't sell their stuff quickly enough and didn't want to lower prices, they had about 500 kds lcd''s there they couldn't get rid of, but I told jeremy to lower the price and he wouldn't. I guess now, they are cheaper and better.
 

olds

Elite Member
Mar 3, 2000
50,071
744
126
Does jeremy's last name start with an "S". I got an email form a "jeremys", I assumed it was a flunky.
 

GetReal

Golden Member
Mar 30, 2001
1,747
0
0
Originally posted by: CasioTech
haha I used to work there, here in miami, I did some web work for them, and networking, a++. Haven't spoke with the owners for about 1 yr now.

Hah I would not have disclosed that!. TheNerds.Net is (was) one of the worst e-commerce web sites in existence. They constantly have (had) multiple pricing errors on their site are too stupid to know how to correct them. I can?t count the number of times that we have received free merchandise from them after disputing with our CC company after TheNerds.Net shipped the incorrect or wrong quantity of a item we ordered. I just successfully completed a dispute with them over 10 OEM 20 pack of Sound Blaster Audigy MP3s that we ordered from them that they had priced at $69.00 for the 20 pk on their web site.
 

GetReal

Golden Member
Mar 30, 2001
1,747
0
0
Originally posted by: CasioTech
I doubt you ripped them off $699.99.

We did not "rip them off" of anything. They advertised, quoted in an email order confirmation, and shipped us the 10 OEM 20pk SB audigys @ $69.00ea per 20pk. The order total with S&H was $768.00. A week later they attemped to charge an additional $11,257.20 to our CC which we disputed and won without contest. We have done this at least a dozen times over the past couple of years for items that they "priced" on their website. It looks like they would learn after the first couple of times, but as long as they are advertising and shipping "their price" items why not order? Even today, they still have 20-50 items mispriced in most of the pricing search engines. Just search for 20pk or 30pk and 9 times out of 10, they will be at the top the list with a price 1/20th or 1/30th of the others in the list. If they are not capable of correctly pricing their procuts and don't like the free enterprise system in the US then tell them to go back to Cuba and conduct their business where prices are controlled.

Here is one to get you started, I was able to find 14 more within five minutes...

20-PK 3.5IN 1.44MB IBM FLOPPY DRIVE BLACK BEZEL Our price: $27.31

PACKAGE CONTENTS
- 20 MPF920-1/121 BLACK BEZEL FLOPPY DRIVES IN OEM 20-PACK PACKAGING



As I said before, theTheNerds.Net is one of the worst (or best for us at least) E-Commerce sites.
 

johto

Senior member
Apr 20, 2001
642
0
0
um... so the guy exploited a bug posted last WEEK by Microsoft?! wtf? I patch my systems the DAY the bulletins come in... granted i'm not running an ecommerce site, but it should be done that NIGHT if not the next weekend. Jesus.
 

chrisjor

Golden Member
Dec 4, 2001
1,736
0
0
there is another thread about this in OT. This one is bigger, check this link and read my posting as how unprofessional they really are here.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |