https://krebsonsecurity.com/2021/10/zales-com-leaked-customer-data-just-like-sister-firms-jared-kay-jewelers-did-in-2018/ Advertisement [142] Advertisement [19] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking Zales.com Leaked Customer Data, Just Like Sister Firms Jared, Kay Jewelers Did in 2018 October 28, 2021 2 Comments In December 2018, bling vendor Signet Jewelers fixed a weakness in their Kay Jewelers and Jared websites that exposed the order information for all of their online customers. This week, Signet subsidiary Zales.com updated its website to remediate a nearly identical customer data exposure. [signet] Last week, KrebsOnSecurity heard from a reader who was browsing Zales.com and suddenly found they were looking at someone else's order information on the website, including their name, billing address, shipping address, phone number, email address, items and total amount purchased, delivery date, tracking link, and the last four digits of the customer's credit card number. The reader noticed that the link for the order information she'd stumbled on included a lengthy numeric combination that -- when altered -- would produce yet another customer's order information. When the reader failed to get an immediate response from Signet, KrebsOnSecurity contacted the company. In a written response, Signet said, "A concern was brought to our attention by an IT professional. We addressed it swiftly, and upon review we found no misuse or negative impact to any systems or customer data." Their statement continues: "As a business principle we make consumer information protection the highest priority, and proactively initiate independent and industry-leading security testing. As a result, we exceed industry benchmarks on data protection maturity. We always appreciate it when consumers reach out to us with feedback, and have committed to further our efforts on data protection maturity." When Signet fixed similar weaknesses with its Jared and Kay websites back in 2018, the reader who found and reported that data exposure said his mind quickly turned to the various ways crooks might exploit access to customer order information. "My first thought was they could track a package of jewelry to someone's door and swipe it off their doorstep," said Brandon Sheehy, a Dallas-based Web developer. "My second thought was that someone could call Jared's customers and pretend to be Jared, reading the last four digits of the customer's card and saying there'd been a problem with the order, and if they could get a different card for the customer they could run it right away and get the order out quickly. That would be a pretty convincing scam. Or just targeted phishing attacks." In the grand scheme of many other, far more horrible things going on in information security right now, this Zales customer data exposure is small potatoes. And this type of data exposure is unbelievably common today: KrebsOnSecurity could probably run one story each day for several months just based on examples I've seen at dozens of other places online. But I do think one key reason we continue to see companies make these easily avoidable mistakes with their customer data is that there are hardly ever any real consequences for organizations that fail to take more care. Meanwhile, their customers' data is free to be hoovered up by anyone or anything that cares to look for it. "Being a Web developer, the only thing I can chalk this up to is complete incompetence, and being very lazy and indifferent to your customers' data," Sheehy said. "This isn't novel stuff, it's basic Web site security." This entry was posted on Thursday 28th of October 2021 02:54 PM A Little Sunshine Data Breaches Brandon Sheehy Jared Kay Jeweler Signet Jewelers Zales.com [147] Post navigation - FBI Raids Chinese Point-of-Sale Giant PAX Technology 2 thoughts on "Zales.com Leaked Customer Data, Just Like Sister Firms Jared, Kay Jewelers Did in 2018" 1. Pedro October 28, 2021 I'm struggling to reconcile "As a business principle we make consumer information protection the highest priority, and proactively initiate independent and industry-leading security testing" with using Insecure Direct Object References, which has been one of the OWASP Top 10 issues for most (if not all) of the time OWASP has existed. Perhaps they should ask whoever provides the "industry-leading security testing" to explain how they missed that little detail? Brian, many thanks for your hard work and excellent reporting, you are performing a service that benefits every honest internet user, and we all owe you for it. Reply - 2. ReadandShare October 28, 2021 Seems to me our laws are always playing 'catch up'. For years now, companies don't need to do much more than publish inane statements like "we take the safety and privacy of our customer data seriously" - and they get away with impunity when their systems get hacked - oftentimes from sheer sloppy security practices! When will our laws catch up to finally make companies pay? Four thousand years ago... when city-living was still a new thing... the Code of Hammurabi (Babylon) read thus: "If a builder builds a house for a man and does not make its construction firm, and the house which he has built collapses and causes the death of the owner of the house, that builder shall be put to death." Harsh... but makes me wonder if that law was also the result of years and years of pent-up anger? Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] Advertisement [16] Advertisement [146] Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * Zales.com Leaked Customer Data, Just Like Sister Firms Jared, Kay Jewelers Did in 2018 * FBI Raids Chinese Point-of-Sale Giant PAX Technology * Conti Ransom Gang Starts Selling Access to Victims * Missouri Governor Vows to Prosecute St. Louis Post-Dispatch for Reporting Security Vulnerability * How Coinbase Phishers Steal One-Time Passwords Spam Nation Spam Nation A New York Times Bestseller! Thinking of a Cybersecurity Career? Thinking of a Cybersecurity Career? Read this. All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * Employment Fraud * How to Break Into Security * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) * Who Hacked Ashley Madison? (361) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security