Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Help with possible scam ?

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Security breach play.com
Reply
 
Thread Tools
Old 22-03-2011, 10:38   #1
richard1960
Guest
 
Location: Essex
Services: vm broadband tvxl TiVo, v+ sky sports and phone.
Posts: n/a
Security breach play.com

Hi just recieved an email from play.com to say their systems have been compromised and certain customers emails and names may have slipped out.

Dear Customer.

Email Security Message

We are emailing all our customers to let you know that a company that handles part of our marketing communications has had a security breach. Unfortunately this has meant that some customer names and email addresses may have been compromised.

We take privacy and security very seriously and ensure all sensitive customer data is protected. Please be assured this issue has occurred outside of Play.com and no other personal customer information has been involved.

Please be assured we have taken every step to ensure this doesn’t happen again and accept our apologies for any inconvenience this may have caused some of you.

Customer Advice

Please do be vigilant with your email and personal information when using the internet. At Play.com we will never ask you for information such as passwords, bank account details or credit card numbers. If you receive anything suspicious in your email, please do not click on any links and forward the email on to privacy@play.com for us to investigate.

Thank you for continuing to shop at Play.com and we look forward to serving you in the future.

Play.com Customer Service Team


OH dear. Just posting in case anyone has not seen this.
  Reply With Quote
Advertisement
Old 22-03-2011, 10:40   #2
BenMcr
Virgin Media Staff
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: Security breach play.com

Just as well I use a unique email address for play.com Will be able to see where any Spam emails come from
BenMcr is offline   Reply With Quote
Old 22-03-2011, 10:45   #3
Hom3r
Mum 30/09/20 Dad 08/08/24
 
Hom3r's Avatar
 
Join Date: Mar 2004
Location: Galactic Sector ZZ9 Plural Z Alpha, A secret Moonbase (shh don't tell anybody)
Age: 56
Services: 2 x TiVo 360s, SH5. Samsung Galaxy Note 10+ 5G, Ton's of Smart Home stuff, & Cuddy Toy
Posts: 17,243
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Re: Security breach play.com

Becareful this could be a scam and not from play.com

This is the header I get

Quote:
Delivered-To: my email addy
Received: by 10.43.63.84 with SMTP id xd20cs13625icb;
Mon, 21 Mar 2011 16:00:07 -0700 (PDT)
Received: by 10.151.43.15 with SMTP id v15mr4392782ybj.170.1300748407185;
Mon, 21 Mar 2011 16:00:07 -0700 (PDT)
Return-Path: <v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com>
Received: from mail1274c.newsletters.play.com (mail1274c.newsletters.play.com [74.112.64.38])
by mx.google.com with ESMTP id p5si15057377ybk.8.2011.03.21.16.00.04;
Mon, 21 Mar 2011 16:00:07 -0700 (PDT)
Received-SPF: pass (google.com: domain of v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com designates 74.112.64.38 as permitted sender) client-ip=74.112.64.38;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com designates 74.112.64.38 as permitted sender) smtp.mail=v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com
Received: by mail1274c.newsletters.play.com (PowerMTA(TM) v3.5r16) id hgvc7e0iiksj for my email addy; Mon, 21 Mar 2011 18:55:27 -0400 (envelope-from <v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com>)
Date: Mon, 21 Mar 2011 18:55:27 -0400 (EDT)
From: "Play.com" <info@play.com>
Reply-To: info@play.com
To:my email addy
Message-ID: <28465150.102901231300748127168.JavaMail.?@rbg03.pd kp1>
Subject: Important: Email Security Message
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_36685_27335354.1300748124270"
x-mid: 4793444
List-Unsubscribe: <mailto:v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com?subject=Unsubscribe>
is

Return-Path: <v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com>

a valid play.com address?
__________________
I'm a Trustee & Secretary for a local charity

STAY AT HOME: I found out that mum will never walk again as the coronavirus attacked her nervous system. She died on September 30th.
Hom3r is offline   Reply With Quote
Old 22-03-2011, 10:46   #4
BenMcr
Virgin Media Staff
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: Security breach play.com

Not sure how it's a scam. There is nothing in it asking for information, and the only e-mail address in it is a valid play.com one

It has also gone to the correct email address I used for play.com as well
BenMcr is offline   Reply With Quote
Old 22-03-2011, 10:51   #5
Hom3r
Mum 30/09/20 Dad 08/08/24
 
Hom3r's Avatar
 
Join Date: Mar 2004
Location: Galactic Sector ZZ9 Plural Z Alpha, A secret Moonbase (shh don't tell anybody)
Age: 56
Services: 2 x TiVo 360s, SH5. Samsung Galaxy Note 10+ 5G, Ton's of Smart Home stuff, & Cuddy Toy
Posts: 17,243
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Re: Security breach play.com

Quote:
Originally Posted by BenMcr View Post
Not sure how it's a scam. There is nothing in it asking for information, and the only e-mail address in it is a valid play.com one

It has also gone to the correct email address I used for play.com as well
True but if you get any emails from "play.com" asking you to click on a link, DON'T. Goto the play.com site via you own explorer.
__________________
I'm a Trustee & Secretary for a local charity

STAY AT HOME: I found out that mum will never walk again as the coronavirus attacked her nervous system. She died on September 30th.
Hom3r is offline   Reply With Quote
Old 22-03-2011, 10:52   #6
Graham M
-
 
Graham M's Avatar
 
Join Date: Jul 2003
Location: Poole, Dorset
Age: 40
Services: FreeSat+ Tivo V-Box VM 60MBit
Posts: 13,365
Graham M has a pair of shiny starsGraham M has a pair of shiny stars
Graham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny stars
Send a message via MSN to Graham M Send a message via Yahoo to Graham M
Re: Security breach play.com

Quote:
Originally Posted by Hom3r View Post
Becareful this could be a scam and not from play.com

This is the header I get



is

Return-Path: <v-ejcege_fiodecco_kghklao_kghklao_a@bounce.newslette rs.play.com>

a valid play.com address?

Looks like it, it goes to an account on the play.com domain
Graham M is offline   Reply With Quote
Old 22-03-2011, 10:53   #7
BenMcr
Virgin Media Staff
 
Join Date: Nov 2006
Location: Manchester
Services: 360 x2, Maxit TV, Sky Sports and Sky Cinema. Gig1
Posts: 17,929
BenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
BenMcr has a pair of shiny starsBenMcr has a pair of shiny stars
Re: Security breach play.com

Quote:
Originally Posted by Hom3r View Post
True but if you get any emails from "play.com" asking you to click on a link, DON'T. Goto the play.com site via you own explorer.
Had no plans to lol
BenMcr is offline   Reply With Quote
Old 22-03-2011, 11:10   #8
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Security breach play.com

It's a genuine email..

Moved to the Security forum
Kymmy is offline   Reply With Quote
Old 22-03-2011, 12:35   #9
dilli-theclaw
R.I.P.
 
dilli-theclaw's Avatar
 
Join Date: Jun 2003
Location: Near Sandy Heath transmitter
Services: BT
Posts: 19,325
dilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden aura
dilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden auradilli-theclaw has a golden aura
Re: Security breach play.com

More info

http://www.theinquirer.net/inquirer/...ecurity-breach
dilli-theclaw is offline   Reply With Quote
Old 22-03-2011, 13:19   #10
Zing
Guest
 
Posts: n/a
Re: Security breach play.com

this information is often leaked/sold by data collecting companies. Most of us in one way or another are on such a list somewhere. This info can net those selling it quite a bit of money.

There is always a option to tick when you register anywhere 3rd party blar blar some is a tick to opt in and other ( the crafty ones) are tick to opt out which means if you aint read it properly and assume its a tick giving permission your data is on a list

Sky for example is an opt out company you actually have to deny permission or by default your info is shared
  Reply With Quote
Old 22-03-2011, 20:22   #11
LSainsbury
Guest
 
Location: Near Hungerford, West Berkshire
Services: TV: Sky HD, Landline: BT, Mobile: Orange, Internet: Quite Slow!
Posts: n/a
Re: Security breach play.com

More info here at BBC News
  Reply With Quote
Old 22-03-2011, 20:40   #12
deadite66
cf.geek
 
deadite66's Avatar
 
Join Date: Jun 2003
Location: great yarmouth
Services: Zen Fibre, Asus RT-AC68U
Posts: 900
deadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these partsdeadite66 is just so famous around these parts
Re: Security breach play.com

Interestingly gmail let this through without flagging as spam.
related to the play email leaks?

[img]Download Failed (1)[/img]
deadite66 is offline   Reply With Quote
Old 22-03-2011, 21:07   #13
Toto
Inactive
 
Join Date: Dec 2004
Posts: 3,403
Toto has a bronzed appealToto has a bronzed appeal
Toto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appeal
Re: Security breach play.com

Quote:
Originally Posted by deadite66 View Post
Interestingly gmail let this through without flagging as spam.
related to the play email leaks?

Probably because the spam email was sent over a compromised network that has a valid SPF record. Google will give a lot of positive weight to a spam or phishing email if it has SPF:PASS in the header.
Toto is offline   Reply With Quote
Old 22-03-2011, 22:09   #14
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Security breach play.com

Another email from PLAY.COM

Quote:
Dear Customer,

As a follow up to the email we sent you last night, I would like to give you some further details. On Sunday the 20th of March some customers reported receiving a spam email to email addresses they only use for Play.com. We reacted immediately by informing all our customers of this potential security breach in order for them to take the necessary precautionary steps.

We believe this issue may be related to some irregular activity that was identified in December 2010 at our email service provider, Silverpop. Investigations at the time showed no evidence that any of our customer email addresses had been downloaded. We would like to assure all our customers that the only information communicated to our email service provider was email addresses. Play.com have taken all the necessary steps with Silverpop to ensure a security breach of this nature does not happen again.

We would also like to reassure our customers that all other personal information (i.e. credit cards, addresses, passwords, etc.) are kept in the very secure Play.com environment. Play.com has one of the most stringent internal standards of e-commerce security in the industry. This is audited and tested several times a year by leading internet security companies to ensure this high level of security is maintained. On behalf of Play.com, I would like to once again apologise to our customers for any inconvenience due to a potential increase in spam that may be caused by this issue .

Best regards,

John

John Perkins
CEO
Play.com
Kymmy is offline   Reply With Quote
Old 22-03-2011, 22:31   #15
Hom3r
Mum 30/09/20 Dad 08/08/24
 
Hom3r's Avatar
 
Join Date: Mar 2004
Location: Galactic Sector ZZ9 Plural Z Alpha, A secret Moonbase (shh don't tell anybody)
Age: 56
Services: 2 x TiVo 360s, SH5. Samsung Galaxy Note 10+ 5G, Ton's of Smart Home stuff, & Cuddy Toy
Posts: 17,243
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Hom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny starsHom3r has a pair of shiny stars
Re: Security breach play.com

I got the second email, and OK I was wrong, but better safe than sorry.

---------- Post added at 22:31 ---------- Previous post was at 22:16 ----------

If you get any suspicious emails that appear to come from Play.com

Quote:
It has also requested that any suspicious messages be forwarded to privacy@play.com.
I tend to only get 3 emails from them IIRC

1. General promo's
2. Order placed/received
3. Order dispatched.

And I spend a LOT of cash there, and will continue to do so.
__________________
I'm a Trustee & Secretary for a local charity

STAY AT HOME: I found out that mum will never walk again as the coronavirus attacked her nervous system. She died on September 30th.
Hom3r is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 10:18.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum