I placed an order with Midwest back in June, and had unauthorized charges to my credit card. I have not received any communication from Midwest as stated. Anyone else had this happen?Recently we learned that despite our best efforts the security of our website was breached by an outside party. For certain types of transactions, this breach may have resulted in the outside party being able to capture and use customer credit card information entered at the time of the transaction. When we identified the breach, we immediately secured our servers, hired a technical team to investigate and help resolve the situation, notified the credit card companies and law enforcement, and obtained legal counsel specializing in computer hacking to help us navigate the very specific legal notification requirements for all 50 states. At this time, all of the notifications have been made, and letters have been sent to all customers that may have been impacted. We regret not providing an update sooner, but we did not want to comment publicly until our investigation was complete and we were able to identify and notify those potentially affected.
Our investigation has now been completed and we are satisfied that the situation has been resolved and that all affected customers have been identified. We have also implemented extensive steps to prevent this kind of incident from happening again. In addition, we sent a letter to each customer who may have been impacted, notifying them of the incident and providing our sincere apology and a credit for $25 worth of homebrewing or winemaking supplies. If you have any questions or concerns please contact our customer service department by phone at 888-449-2739. Rest assured that if you were not contacted you were not among the customers impacted.
We have spent many years working to earn your trust and loyalty. And we recognize an attack like this can undermine that trust. As one brewer to another, you can rest assured that we won’t rest until you’ve brewed your best.
David Kidd
President
__________________
Beer and Wine Making Supplies since 1995
http://www.midwestsupplies.com
Midwest Supplies Security Breach
Moderators: BlackDuck, Beer-lord, LouieMacGoo, philm00x, gwcr
Midwest Supplies Security Breach
This was posted on HBT over the weekend by Midwest Supplies:
In Soviet Russia, beer brews you!
My brews
- RickBeer
- Brew Guru
- Posts: 3099
- Joined: Thu Aug 08, 2013 1:21 pm
- Location: Ann Arbor, Michigan (Go Blue!)
Re: Midwest Supplies Security Breach
That's a major cluster*&^@. PCI requirements are that the credit card numbers be encoded and NOT stored, so they were violating that. The number gets stored at the credit card processor, NOT at the merchant.
Lawsuits coming. Hope the new owners are ready for them.
Lawsuits coming. Hope the new owners are ready for them.
I have over 9,000 posts on "another forum", which means absolutely nothing. Mr. Beer January 2014 Brewer of the Month with all the pomp and circumstance that comes with it...
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
My Beer - click to reveal
Re: Midwest Supplies Security Breach
They were not stored; according to some other documents posted on HBT, their server was injected with malware that forwarded CC#'s (and other personal info) as they were entered during an order placement to an unknown third party.RickBeer wrote:That's a major cluster*&^@. PCI requirements are that the credit card numbers be encoded and NOT stored, so they were violating that. The number gets stored at the credit card processor, NOT at the merchant.
Lawsuits coming. Hope the new owners are ready for them.
In Soviet Russia, beer brews you!
My brews
- RickBeer
- Brew Guru
- Posts: 3099
- Joined: Thu Aug 08, 2013 1:21 pm
- Location: Ann Arbor, Michigan (Go Blue!)
Re: Midwest Supplies Security Breach
Wow. Not good at all.
I have over 9,000 posts on "another forum", which means absolutely nothing. Mr. Beer January 2014 Brewer of the Month with all the pomp and circumstance that comes with it...
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
My Beer - click to reveal
Re: Midwest Supplies Security Breach
Not good to hear that. Thanks for bringing it to our attention!
Fermenting: Bucket 1 - Fresh Squeezed IPA; Bucket 2 - Empty
Kegged: Keg 1 - Irish Red; Keg 2 - Cream Ale; Keg 3 - Amber Ale; Keg 4 - APA; Keg 5 - Empty; Keg 6 - Empty; Keg 7 - Empty
The reason why the above list is so small Home Theater Build
Kegged: Keg 1 - Irish Red; Keg 2 - Cream Ale; Keg 3 - Amber Ale; Keg 4 - APA; Keg 5 - Empty; Keg 6 - Empty; Keg 7 - Empty
The reason why the above list is so small Home Theater Build
Re: Midwest Supplies Security Breach
Damn...
I hope you get some communication at the least, and a bigger gift card than $25 which won't buy much from a homebrew store.
I hope you get some communication at the least, and a bigger gift card than $25 which won't buy much from a homebrew store.
"The trouble with quotes on the internet is you can never be sure if they are true." - Walt Whitman
- RickBeer
- Brew Guru
- Posts: 3099
- Joined: Thu Aug 08, 2013 1:21 pm
- Location: Ann Arbor, Michigan (Go Blue!)
Re: Midwest Supplies Security Breach
Most companies that have this happen offer their customers a credit monitoring service for a period, usually a year. Midwest is only offering the future discount.
I have over 9,000 posts on "another forum", which means absolutely nothing. Mr. Beer January 2014 Brewer of the Month with all the pomp and circumstance that comes with it...
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
My Beer - click to reveal
Re: Midwest Supplies Security Breach
I have always used my paypal account with them. It has a lot to do with why I shop there.
- RickBeer
- Brew Guru
- Posts: 3099
- Joined: Thu Aug 08, 2013 1:21 pm
- Location: Ann Arbor, Michigan (Go Blue!)
Re: Midwest Supplies Security Breach
For those that aren't aware, SOME credit cards allow you to create a safe number to use for a purchase or purchase(s). One brand is called ShopSafe, which is used by Bank of America. It's free to card holders, you log on the site, tell them you want to make a virtual number, and after verifying your identify it makes a number. You pick a credit limit and an expiration date, and you're all set. You can change the limit in the future also.
It's great for sites that need a credit number (i.e. Google Play Store) but you don't ever want to buy - set a $1 limit.
It would help in this case, they'd have your name, address and a virtual credit card number with a set limit that you could go in and nuke right now. Then they'd just know who you are.
Of course are credit card providers cover our losses, but you have to go through the trouble of getting a new number and then changing all your automatic payments. With a virtual number like one from ShopSafe, you wouldn't have to do that.
It's great for sites that need a credit number (i.e. Google Play Store) but you don't ever want to buy - set a $1 limit.
It would help in this case, they'd have your name, address and a virtual credit card number with a set limit that you could go in and nuke right now. Then they'd just know who you are.
Of course are credit card providers cover our losses, but you have to go through the trouble of getting a new number and then changing all your automatic payments. With a virtual number like one from ShopSafe, you wouldn't have to do that.
I have over 9,000 posts on "another forum", which means absolutely nothing. Mr. Beer January 2014 Brewer of the Month with all the pomp and circumstance that comes with it...
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
My Beer - click to reveal
- LouieMacGoo
- Site Admin
- Posts: 1846
- Joined: Fri Jul 05, 2013 12:09 pm
- Location: S.E. Michigan
- Contact:
Re: Midwest Supplies Security Breach
Im going to make this a global sticky for the next week. I think this important information for people to see in case they are affected!
Worrying can spoil the taste of beer more then anything else! ~ Charles Papazian
Find out more about Yeast, Hops, Grains and Cleaning & Sanitizing
Find out more about Yeast, Hops, Grains and Cleaning & Sanitizing
Whats Brewing
Re: Midwest Supplies Security Breach
Crap! I just bought two corny's a week ago!
Re: Midwest Supplies Security Breach
I think they have fixed the problem by then. Most people affected seemed to have placed orders in June.Tabasco wrote:Crap! I just bought two corny's a week ago!
In Soviet Russia, beer brews you!
My brews
- RickBeer
- Brew Guru
- Posts: 3099
- Joined: Thu Aug 08, 2013 1:21 pm
- Location: Ann Arbor, Michigan (Go Blue!)
Re: Midwest Supplies Security Breach
Seems like they had to get their legal ducks in a row before they went public with it.
I have over 9,000 posts on "another forum", which means absolutely nothing. Mr. Beer January 2014 Brewer of the Month with all the pomp and circumstance that comes with it...
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
Certificate in Brewing and Distillation Technology
Sites to find beer making supplies: Adventures in Homebrewing - Mr. Beer - MoreBeer
My Beer - click to reveal
- jimjohson
- Brewer of the Month
- Posts: 2603
- Joined: Tue Jul 09, 2013 9:14 pm
- Location: Cusseta Ga
- Contact:
Re: Midwest Supplies Security Breach
that's good know information RickBeer. thanks
"Filled with mingled cream and amber
I will drain that glass again.
Such hilarious visions clamber
Through the chambers of my brain
-- Quaintest thoughts -- Queerest fancies
Come to life and fade away;
Who cares how time advances?
I am drinking ale today."
Edgar Allan Poe
I will drain that glass again.
Such hilarious visions clamber
Through the chambers of my brain
-- Quaintest thoughts -- Queerest fancies
Come to life and fade away;
Who cares how time advances?
I am drinking ale today."
Edgar Allan Poe
Re: Midwest Supplies Security Breach
Just got my $25 gift card and cant complain. For a credit card you simply need to dispute and if its a problem they will handle it. Cant complain as they didn't have to do that and a show of good faith. If you can hack into NASA, etc, who is to blame a small company. Kudos to them with handling this.
Silverleaf Vineyard & Winery / Old Mission Hops Exchange / Porchside Vineyard / The North York Brewing Company