ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Lush Cosmetics Data Breach

By | January 21, 2011, 2:42am PST

Lush Cosmetics, a handmade cosmetics company headquartered in Poole, Dorset in the United Kingdom with some 600 locations around the world, has ostensibly been the “victim of hackers” according to a post on their UK version web site http://www.lush.co.uk/ yesterday. Details are in somewhat short supply, but according to the notice posted, there was a successful initial intrusion and repeated subsequent attempts at re-entry.

A number of consumers of Lush products are reporting on the Lush Facebook page seeing similar fraudulent transactions (similar dollar amounts) in their bank accounts for items like prepaid phones, hotel bookings, and Xbox Live charges. With a handful of users reporting problems going back a couple of weeks, an important question emerges that is not yet answered: when did Lush first become aware of this problem?

Lush has indicated that only the UK version of their web site is affected and has advised any person that placed an online order between October 4th of last year and yesterday to contact their banks, indicating that credit card details have been compromised. Finally, in an unusual twist, they have elected to completely shutter the web site, opting to set up a temporary online shop that accepts PayPal payments. The front page of the site includes notes to both customers, and the hacker.

E-mail to Customers From Lush

We would like to draw your attention to the statement below, as we believe you placed an order with us during the affected period. We are keen for customers not to have their credit cards used fraudulently, so urge you to contact your bank.

Our website has been the victim of hackers. 24 hour security monitoring has shown us that we are still being targeted and there are continuing attempts to re-enter. We refuse to put our customers at risk of another entry – so have decided to completely retire this version of our website.

For complete ease of mind, we would like all customers that placed ONLINE orders with us between 4th Oct 2010 and today, 20th Jan 2011, to contact their banks for advice as their card details may have been compromised.

Customer Notice
The notice to customers posted on the Lush web site reads as follows:

Our website has been the victim of hackers.

24 hour security monitoring has shown us that we are still being targeted and there are continuing attempts to re-enter.

We refuse to put our customers at risk of another entry - so have decided to completely retire this version of our website.

For complete ease of mind, we would like all customers that placed ONLINE orders with us between 4th Oct 2010 and today, 20th Jan 2011, to contact their banks for advice as their card details may have been compromised.

We Believe hacking is a serious crime which steals large amounts of money and disrupts the lives of cardholders.

We Believe that hacking erodes the trust between businesses and their customers and creates a climate of fear around online ordering.

We Believe in working with police and banks to do all we can to bring this branch of organised crime to justice.

A completely separate, temporary website will be launched in a few days - initially taking PayPal payments only.

Meanwhile we would be delighted to serve you in our shops or take your order at our Mail Order Phone Room. Both of which have not been affected by this crisis since their credit card terminals are directly linked to the banks only and are not internet based.

We would like to thank all our customers for standing shoulder to shoulder with us whilst we have shared being victims of this crime.

Dear Hacker…
To the hacker they wrote the following:

TO THE HACKER
If you are reading this, our web team would like to say that your talents are formidable. We would like to offer you a job - were it not for the fact that your morals are clearly not compatible with ours or our customers’.

Forensic Response
An initial concern is that while Lush has taken time out to write a mission statement on data theft and chastise the “hacker”, really a cracker, they mention nowhere that they have hired a reputable computer forensics company to come in and assess the damage. They provide little actual detail of what actually happened, and beyond shuttering the web site communicate no plan to customers that demonstrates new controls being implemented to prevent or limit problems like this in the future.

PCI
Perhaps also troubling is that credit card details are being reported as compromised with a company that is clearly affected by PCI DSS compliance, for whatever PCI is worth, who had previously implemented a point-to-point encryption solution for their card readers at retail locations in the UK. While this certainly does not directly affect the storage of credit card numbers by their web application, it demonstrates both an understanding of what is required to be PCI complaint, and an awareness of encryption solutions for protecting sensitive data.

Searching for additional discussion of security controls turns up little, unfortunately the “site security” section within their privacy policy for the U.S. version web site appears dated, discussing only the use of SSL in web transactions, and no indication of further protections beyond using a “secure server”:

We use appropriate security safeguards to protect your personal information against loss, theft, and unauthorized access. Any personal information you provide to LUSH is exchanged on a secure server. We use an advanced security system, the Secure Sockets Layer (SSL) protocol, to encrypt, or encode, information you send to us in the order process. The encryption process protects information, such as your credit card number, and billing and shipping information by scrambling it before it is sent from your computer. Only once we receive your information is it decoded, and we make all reasonable efforts to ensure its security on our own systems. - Lush Privacy Policy

Finally…Muppets
The final thing they did, which I’ve never quite seen before, is they linked to a video of a singing Muppet lemming “turning frowns upside down” to share a smile and cheer themselves up. Customer reaction appears mixed, with some customers indicating problems while others seem to support the company’s handling of the data breach. But this breach does look like it will have an impact to the cosmetic company’s bottom line, in the words of one angry consumer on Facebook: “What a nightmare and I am very very annoyed at this and will no longer be shopping with lush ever again as we entrusted our details and they were not kept secure.”

The Lush UK web site as it appeared yesterday.

The Lush UK web site as it appeared yesterday.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Daniel Kennedy leads initiatives in policy and operational security management, directs strategy on risk assessment and certification, and is head of business continuity planning and disaster recovery at Praetorian Security Group, LLC.

Disclosure

Daniel Kennedy

Daniel Kennedy is a part owner of the information security consulting firm Praetorian Security Group, LLC. He has some stock in Bank of New York, and a standard 401k invested in various mutual funds.

Biography

Daniel Kennedy

Daniel Kennedy leads initiatives in policy and operational security management, directs strategy on risk assessment and certification, and is head of business continuity planning and disaster recovery at Praetorian Security Group, LLC.

Prior to Praetorian Security Group, Daniel was the Global Head of Information Security at D.B. Zwirn & Co. where he managed the firm's information security program. He was specifically responsible for the development, implementation, and maintenance of the firm's information security policies. He also managed security metrics reporting, the security awareness and education program, security incident response, security audit, and developing the firm's security technology strategy. In this role he worked closely with the firm's CIO, COO, head of compliance, head of legal, head of infrastructure, head of client services, and overseas IT managers.

Prior to D.B. Zwirn, Daniel was Vice President and Program Manager for the application security program at Pershing LLC, a division of the Bank of New York. Daniel's responsibilities included management of the firm's application security program, coordination of application vulnerability assessments and penetration testing, application security training, documentation of secure coding guidelines, and development of the firm's application security SDLC. He was the primary liaison for application security concerns between application development and teams such as the Information Security Office, Internal Audit, Information Risk Management (IRM), and the business teams. He served on several firm committees including the Infrastructure Security Workgroup, Security Architecture, and chartered and chaired the firm's Application Security Council, an interdisciplinary group consisting of application developers and information security subject matter experts.

His previous positions at Pershing included development management and systems' engineering positions building the firm's web applications for facilitating online brokerage. He has also been employed at Donaldson, Lufkin, & Jenrette Inc. in a technology analyst role for the Treasury area.

Daniel holds a Masters of Science degree in Information Systems from Stevens Institute of Technology, a Masters of Science in Information Assurance from Norwich University, and a Bachelors of Science in Information Management and Technology from Syracuse University. He is certified as a CEH (Certified Ethical Hacker) from the EC-Council, a CISSP, and has a NASD Series 7 license.

You can also follow him on Twitter as well as the blog Praetorian Prefect.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
21
Comments

Join the conversation!

Just In

RE: Lush Cosmetics Data Breach
Metin2 17th Mar
You get past the Lush Cosmetics
http://m2oyna.com http://pvp-serverlar.in
0 Votes
+ -
They addressed the Hacker?
SonofaSailor 21st Jan 2011
kind of odd...yeah, I can see how they could hope that statement would lure someone into coming forward about the attack...but, does that statement also establish a desire to prosecute (or lack thereof)?

I can't see that happening on this side of the pond or else some lawyer would take that and run with it:

"Your Honor, my client can not be prosecuted ...the defendant announced publicly that it was all but ready to offer my client a job."
0 Votes
+ -
RE: Lush Cosmetics Data Breach
lovedong 13th Sep
Good luck to you! replica watches
0 Votes
+ -
@lovedong
I feel sorry for both of them. For the hacked its pretty obvious why but for the hackers with their talents they could do so much more



Double glazing prices
0 Votes
+ -
How will this affect my credit rating?
sidic Updated - 24th Jan 2011
Lush is trying to shift the responsibility to the customer. In the past, I have reported to my bank that my credit card might be compromised. But, that is because of my mistake using similar password on many sites. So, I am prepared to take credit rating hit by reporting this.
However, if it is the e-commerce website lapses on security, I believe they should report this incident to VISA/Mastercard that will eventually contact the banks.
0 Votes
+ -
RE: Lush Cosmetics Data Breach
aep528 21st Jan 2011
@sidic

Huh? Why would your credit rating be affected?
0 Votes
+ -
RE: Lush Cosmetics Data Breach
sidic 24th Jan 2011
@aep528
I am not trying to spread FUD. I hope, "reporting potential fraud over my credit card to my back as precaution" will not affect my credit rating. I hope that is true, because it is fault of the website and the cracker. It is not my fault.
0 Votes
+ -
Lush Uk Fault
Pierrafeu 21st Jan 2011
It's Lush UK Fault they had not update their software of ecommerce Virtuemart see an article with my help http://bit.ly/fUzJSU
Make your own opinion...
0 Votes
+ -
RE: Lush Cosmetics Data Breach
sidic 24th Jan 2011
@Pierrafeu
I hate SQL injection.
0 Votes
+ -
YAWN
james347 22nd Jan 2011
Not concerned.
0 Votes
+ -
RE: Lush Cosmetics Data Breach
Prefect23 23rd Jan 2011
@james347 Assuming you don't wear makeup then.
0 Votes
+ -
Mt2 turk MMO PvP game download online game servers
metin2 - metin2 indir - metin2 hile - metin2 gm komutlari - metin2 at gorevleri
MMO online games, game related content turk mt2 pvp servers
metin 2 - pvp - server - knight
Mt2 turk MMO PvP game servers online
metin2 pvp sererler - serverlar - pvp serverler - metin2 pvp sererlar - pvp kenti

download http://www.metin2oyunu.org game servers online http://www.metin2pvpserver.net turk mt2 pvp servers http://www.metin2pvpserverlar.com
mt2
metin2 turk
mt2 turk
metin2 tr
Metin 2
alemt2 indir
alemt2 kaydol
alemt2
fancymt2 kaydol
fancy mt2
mt2 pvp
metin2 pvp
metin2 pvp serverler
pvp
metin2
serverler
serverler

metin2pvpserver
metin2 pvp server
metin2 pvpserver
metin2pvp server
metin2pvp
metin2 server


metin2pvpserverlar
metin2 pvp serverlar
metin2pvp serverlar
metin2 serverlar

face
facebook
0 Votes
+ -
You get past the Lush Cosmetics
http://m2oyna.com http://pvp-serverlar.in
0 Votes
+ -
RE: Lush Cosmetics Data Breach
MACKENZI 10th Sep
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
0 Votes
+ -
RE: Lush Cosmetics Data Breach
MARAGARET 11th Sep
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
0 Votes
+ -
RE: Lush Cosmetics Data Breach
RHIANNONA 13th Sep
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
0 Votes
+ -
RE: Lush Cosmetics Data Breach
SATURNINA 13th Sep
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
0 Votes
+ -
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
0 Votes
+ -
This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
0 Votes
+ -
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
0 Votes
+ -
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix