partsgateway.co.uk data breach

ProjectPuma

Help Support ProjectPuma:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.

evilrob

Active member
Joined
Sep 14, 2009
Messages
4,925
This lot appear to have suffered a data breach; I just received a phishing e-mail that LOOKS like an order confirmation for car parts, containing an old address and phone number of mine, sent to an e-mail address unique to my Parts Gateway account (I specifically set up a new e-mail address for anything I sign up to online so I can tell where an incoming email from a naughty third party has got my data from).

Basically it looks legit, but I imagine if you click on the links you'll either download some AIDS to your computer or they'll try to get passwords or credit card details out of you.

Not a lot anyone can do about it now, but if you receive an e-mail that looks like an order confirmation for car parts with your name, address and phone number on it, report it to your e-mail provider as spam/phishing, don't click on any of the links, and complain to Parts Gateway if you can be bothered!

Please copy/paste to other car communities you may be a part of to hopefully reduce the chances of anyone getting scammed.
 
This issue has made it into the tech press:

http://www.theregister.co.uk/2017/02/14/uk_car_parts_website_insecure_worries/
 
Just got an interesting email from PartsGateway:

Hi,

We have been made aware of a spam email being targeted to partsgateway@[mydomain].co.uk. Unfortunately we were the victims of an attack where the perpetrators were able to gain access via a V Bulletin work forum to access the user database. We must stress no financial records are stored.

We are currently going through every line of code from the last 16 years, taking various parts of the site offline and reviewing all security layers but as a small site with limited resources this will take some time. We are also due to migrate to new servers which will further bolster our defences.

In the meantime can you please delete the email account partsgateway@[mydomain].co.uk to avoid any future exposure. We have also removed all traces of your details on the server. Please accept our sincere apologies for the inconvenience this has caused.

Regards

User Support
www.partsgateway.co.uk
 

Latest posts

Back
Top