• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Monoprice servers hacked - Check your CC statements!

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

mattspalace

I been Dolk'ed Senior
Joined
Jan 14, 2003
Location
Stuttgart, Germany
Monoprice's servers were hacked earlier this month. If you use monoprice (specifically making a purchase the first week of March) and purchased with a CC, you need to watch your statements for fraudulent charges.
Sounds like they've fixed their server issue and will be back up next week.

Thankfully, I always use Paypal with Monoprice.
 
Any articles about this?
Did they say what servers specifically were hacked?

Scary thought, don't companies like this often get security audits to make sure their systems are safe especially when dealing with customers information...

Ideally if they were smart, they don't keep CC info on their servers, but simply pass it through and if it is all SSL encrypted, no info should of been able to be grabed as even server side the cc numbers should be encrypted, at least that is how our company does things for CC transactions.
 
They have a statement on the monoprice homepage. If you did use a credit card with them you could always ask your credit card company to ship you a new card with a different number. Then you don't have to worry about someone using your card down the road.
 
Again, if you read the monoprice statements. They have NOT found any log attempts to state that it was there servers that were hacked. False information
 
Could be inside job or could be the company that MP use to process cc got hacked. Either way, if you buy from there and use cc, call and get a new card.
 
Latest update from Monoprice's website:

"3/12/2010 11:00PM PT - Our outside investigators have continued to review log files from our Internet-facing servers. They have not found evidence of any successful attempts to penetrate our computer system. Our internal IT staff found some suspicious files on one of our quarantined Web servers while they were reviewing files to build replacement servers.

We have identified the suspicious files to our outside investigators so that they can extract the files from the image of our servers that they made earlier. We asked them to let us know if the suspicious files are significant. We will post more information here about the investigation when we have it.

We are taking steps to re-launch our site early next week. We will not take credit card payments on the site initially but will take payments through PayPal Express and Google Checkout. We will let you know when the site is available. Thank you for your continued support."
 
Exactly...sounds like there was some malware but no 'guaranteed hack.' Check your statements as usual of course but no need to go overboard and cancel your card yet. I got a few things frm them in the stated time period and have seen no unauthorized activity.
 
And they just received my business yesterday. About 15 wires (coaxial and hdmi) for 50 bux.
 
I'd tried to make a purchase a couple of days ago, but my paypal payment wasn't accepted in time, so I gotta redo it. Glad they're up again though - I love me some monoprice!
 
wiki it. lot to it. kind of bull sheet if you ask me. really banks need to get there shett together. about a year and a half ago US Bank got hacked. A lot I mean A LOT of credit card numbers stolen. People called US Bank and changed the billing address on the card so when we ran the avs match (google avs code wiki) we had a good match. well we ate 1000's of dollars. The banks are setting up this PCI crap thinking it will help with fraud when it wont cause of douche bags that work at some companies and crappy banks that screw the retailer.
 
Guys, check your cards. I just found 3 fraudulent charges on the card that i used at Monoprice at the time this happened. The only other place i used it since then was thru Paypal.

Just thought i'd let you guys know to check your accounts.
 
Back