I received an email from an email address claiming to be CC Moore, copied below. Note the weird formatting and spelling. Anyone else get this? Looks VERY dodgy to me and as there's nothing on their website about this, where you would expect to see it mentioned? Just thought I'd warn you guys, as this looks very dodgy.
----------------------------------------------------------------------------------------------------------------------------------------------------------
I am writing to let you know about a cyber incident tha= has recently affected CC Moore and which may have resulted in personal in=ormation you have shared with us being compromised.
This letter provid=s information about what happened, what personal information was involved,=nd contact details should you have any questions.
What h=s happened? In December, we became aware that o=r database of customers who have an online shopping account with us was co=promised by an unauthorised and unknown third party. On b=coming aware of this incident, we took immediate action to contain it and =o ensure unauthorised access to our systems was no longer available. A thorough internal investigation indicated that the incident o=curred as a result of an unknown vulnerability in our store web applicatio= which allowed the unknown third party to gain unauthorised access to our =ustomer database.
What personal information has bee= impacted? As a result of this incident, personal informatio= relating to you may have been accessed during this period. If your person=l information was accessed, there is a possibility that your personal info=mation could be used to commit identity theft or fraud. The per=onal information which may have been affected was:
• <="" li="">
• Password information: =he password used on your CC Moore online shopping account
=ote: These passwords were stored in our customer database in an encrypted =ormat.
What action have we taken? As =oon as we became aware of the incident, we took the following steps:
• We worked closely with a team of experts who have assiste= us to take the necessary steps to secure our systems and to investigate f=lly.
• We informed the Information Commissioner's Office.
• We are in the process of contacting those individual customer= who may be affected, including you.
• We invalidated every =ustomer account password such that all customers therefore had to change t=e password for their CC Moore online shopping account upon log in.
What should you do?
As a precauti=n, we recommend that you take the following steps to protect your informat=on:
o Although passwords were stored in our customer =atabase in an encrypted format, it is possible that the encryption could h=ve been compromised. You should therefore change any passwords that are th= same as that which you use for your online shopping account with CC Moore=.
o If you can't access your CC Moore account, this may be be=ause you have not used it within 2 years or live outside the UK.
If t=is is the case, we have now closed your account and removed your personal =ata from our servers. To place an order you will need to create a new acco=nt
o If you are contacted by anyone asking you for personal=nformation or passwords (such as for your bank account), we recommend tha= you take all steps to check the true identity of the organisation.
o If you receive an unsolicited email, we recommend that you do not=lick on any links without first making absolutely sure it is from a trust=orthy source.
o Always check the email address from which em=ils that you receive have been sent and the email's authenticity before re=ponding in any way.
We value the privacy of our custom=rs and we take the issue of IT security extremely seriously. We apologise =or any inconvenience or concern this incident may have caused you.
For =urther information or assistance on this matter, you can contact our data =reach support service provided by Experian by Tel; 0800 9230000 or email: =ata.support@ccmoore.com
Yours sincerely
Ian Moore=br>
Director
CC Moore & Co Ltd
----------------------------------------------------------------------------------------------------------------------------------------------------------
I am writing to let you know about a cyber incident tha= has recently affected CC Moore and which may have resulted in personal in=ormation you have shared with us being compromised.
This letter provid=s information about what happened, what personal information was involved,=nd contact details should you have any questions.
What h=s happened? In December, we became aware that o=r database of customers who have an online shopping account with us was co=promised by an unauthorised and unknown third party. On b=coming aware of this incident, we took immediate action to contain it and =o ensure unauthorised access to our systems was no longer available. A thorough internal investigation indicated that the incident o=curred as a result of an unknown vulnerability in our store web applicatio= which allowed the unknown third party to gain unauthorised access to our =ustomer database.
What personal information has bee= impacted? As a result of this incident, personal informatio= relating to you may have been accessed during this period. If your person=l information was accessed, there is a possibility that your personal info=mation could be used to commit identity theft or fraud. The per=onal information which may have been affected was:
• <="" li="">
• Password information: =he password used on your CC Moore online shopping account
=ote: These passwords were stored in our customer database in an encrypted =ormat.
What action have we taken? As =oon as we became aware of the incident, we took the following steps:
• We worked closely with a team of experts who have assiste= us to take the necessary steps to secure our systems and to investigate f=lly.
• We informed the Information Commissioner's Office.
• We are in the process of contacting those individual customer= who may be affected, including you.
• We invalidated every =ustomer account password such that all customers therefore had to change t=e password for their CC Moore online shopping account upon log in.
What should you do?
As a precauti=n, we recommend that you take the following steps to protect your informat=on:
o Although passwords were stored in our customer =atabase in an encrypted format, it is possible that the encryption could h=ve been compromised. You should therefore change any passwords that are th= same as that which you use for your online shopping account with CC Moore=.
o If you can't access your CC Moore account, this may be be=ause you have not used it within 2 years or live outside the UK.
If t=is is the case, we have now closed your account and removed your personal =ata from our servers. To place an order you will need to create a new acco=nt
o If you are contacted by anyone asking you for personal=nformation or passwords (such as for your bank account), we recommend tha= you take all steps to check the true identity of the organisation.
o If you receive an unsolicited email, we recommend that you do not=lick on any links without first making absolutely sure it is from a trust=orthy source.
o Always check the email address from which em=ils that you receive have been sent and the email's authenticity before re=ponding in any way.
We value the privacy of our custom=rs and we take the issue of IT security extremely seriously. We apologise =or any inconvenience or concern this incident may have caused you.
For =urther information or assistance on this matter, you can contact our data =reach support service provided by Experian by Tel; 0800 9230000 or email: =ata.support@ccmoore.com
Yours sincerely
Ian Moore=br>
Director
CC Moore & Co Ltd
In reply to Post #1
Not me
Not me
In reply to Post #1
Yes, I received one too, and I thought the same as you. It does look dodgy so I have ignored it.
Yes, I received one too, and I thought the same as you. It does look dodgy so I have ignored it.
In reply to Post #3
I got one too
I got one too
I received it too this morning. Checking the email address it came from it is the same email address that CC Moore uses and checking with an old email address it is identical so it is not one based in Nigeria etc and is an legitamet address.
I checked my account and I do not have one with them, probably because it has been years since I traded with them, but, they must still have my email address somewhere to have sent me this message.
I checked my account and I do not have one with them, probably because it has been years since I traded with them, but, they must still have my email address somewhere to have sent me this message.
In reply to Post #1
I've got one too, nothing on their FB page either.
Daz
I've got one too, nothing on their FB page either.
Daz
In reply to Post #6
Me too just emailed them to see if it's genuine or not
Me too just emailed them to see if it's genuine or not
In reply to Post #1
Just had a message from them on FB, it's genuine.
Daz
Just had a message from them on FB, it's genuine.
Daz
Why do you not thinks its legit? They are not asking you to do anything just informing you (as they should) of the fact your data may have been compromised. This is only for people who have registered with them to buy direct.
The only links in the email are to a legit email address. Whats the scam in that?
Many more customers buy via distributors so plastering it all over FB etc would seem a little daft when they have the contact details off all those possibly affected so just contacted them direct (which they did).
Well done for them coming clean, I suspect many others would/ have not in the past
The only links in the email are to a legit email address. Whats the scam in that?
Many more customers buy via distributors so plastering it all over FB etc would seem a little daft when they have the contact details off all those possibly affected so just contacted them direct (which they did).
Well done for them coming clean, I suspect many others would/ have not in the past
I've had one too but I've not ordered anything from them for ages
In reply to Post #9
Clearly you know very little about phishing - ANY email that has errors in it, is badly formatted or comes straight into your junk folder - you treat it with suspicion! Oh and just as there's no links, doesn't mean it's not dodgy FFS. Coming clean my bobbins - they are legally bound to come clean, you'd know that if GDPR meant anything to you. They have not put anything on their website yet. so that's poor. If anyone suffers any kind of fraudulent act as a result of this data breach, they can sue them and of course, the ICO can fine them rather a lot.
Clearly you know very little about phishing - ANY email that has errors in it, is badly formatted or comes straight into your junk folder - you treat it with suspicion! Oh and just as there's no links, doesn't mean it's not dodgy FFS. Coming clean my bobbins - they are legally bound to come clean, you'd know that if GDPR meant anything to you. They have not put anything on their website yet. so that's poor. If anyone suffers any kind of fraudulent act as a result of this data breach, they can sue them and of course, the ICO can fine them rather a lot.
I got one, just reset my password and job done
In reply to Post #12
Same as.
Same as.
In reply to Post #11
My email was perfectly formatted and had zero phishing in it! If yours came formatted like that I would suspect your email client and filter provider.
I am fully aware of GDPR and many do not come clean. They have done the correct (and legal) thing and get slatted for it
My password has been reset and the one I used on there was unique so nothing more to be done.
My email was perfectly formatted and had zero phishing in it! If yours came formatted like that I would suspect your email client and filter provider.
I am fully aware of GDPR and many do not come clean. They have done the correct (and legal) thing and get slatted for it
My password has been reset and the one I used on there was unique so nothing more to be done.
In reply to Post #14
I got one too, however it would have been nice to have been informed about 6 weeks ago.
I got one too, however it would have been nice to have been informed about 6 weeks ago.
I got one this morning just logged into my account through the actual cc Moore website and reset my password, no big deal
In reply to Post #16
might not seem like a big deal....BUT to have got this far clearly a lot of information has been nicked including personal contact details, addresses, passwords. It's no big deal until you are "done" and someone's nicked your identity, unravelling that can be a very horrible process.
might not seem like a big deal....BUT to have got this far clearly a lot of information has been nicked including personal contact details, addresses, passwords. It's no big deal until you are "done" and someone's nicked your identity, unravelling that can be a very horrible process.
I got the email but I'm not receiving any emails with links to change my password, great!
So I wonder if they've got payment details from this scam? Might be an idea to chase them up and find out what the deal is.
So I wonder if they've got payment details from this scam? Might be an idea to chase them up and find out what the deal is.
In reply to Post #17
My point exactly. Some people just don't take these things very seriously and they really should. I thought it very poor show for CC Moore to send out such a crap message and at the same time, fail to validate on their website. Just glad my email caught it and didn't put in my inbox. I only hope no one suffers because of the data breach.
My point exactly. Some people just don't take these things very seriously and they really should. I thought it very poor show for CC Moore to send out such a crap message and at the same time, fail to validate on their website. Just glad my email caught it and didn't put in my inbox. I only hope no one suffers because of the data breach.
I got one this morning but had to change password two weeks ago so should I have got the email two weeks ago?
Michael
Michael
In reply to Post #19
Well said, what a crap email. I saw it and thought it was a hoax!
So it's official then
Well said, what a crap email. I saw it and thought it was a hoax!
So it's official then
In reply to Post #21
Sadly data breaches happen all to often and even to the biggest and most respected organizations .
Not much more than can do than tell us whatever we think of their mail.
Happy Fridays 😄
Sadly data breaches happen all to often and even to the biggest and most respected organizations .
Not much more than can do than tell us whatever we think of their mail.
Happy Fridays 😄
I received the email myself today, and have just reset the password. On the home page they state that their new website is soon to go live, and could everybody please reset their password as a result.....
🤔 bit of a coincidence that, what with a data breach. At least they could have been honest, or perhaps the mistake is mine in assuming something........
🤔 bit of a coincidence that, what with a data breach. At least they could have been honest, or perhaps the mistake is mine in assuming something........
In reply to Post #23
Strange as the email received is not even from same domain name ... @ccmoore.net when their website is ccmoore.com ?
Strange as the email received is not even from same domain name ... @ccmoore.net when their website is ccmoore.com ?
In reply to Post #24
Too much deep thinking on a Friday - you lot need to get out more ahh but we can't 😃
Have a drink end of another working week - keep positive.
Too much deep thinking on a Friday - you lot need to get out more ahh but we can't 😃
Have a drink end of another working week - keep positive.
I haven't had one, if I had I would inform my bank asap NOT to pay CC Moore until I advise them to.
Mine was in my spam box so I just deleted it
I received the email from CCMoore today. It was pretty clearly written and appeared genuine, but you never know so I called them on their normal number to check and it IS 100% genuine.
There is also a dedicated helpline number in the email which I also rang. I've changed my password. I was told they don't keep any payment details as all payments on their site are processed through PayPal or WorldPay. They were pretty helpful tbf, as indeed they should be.
There is also a dedicated helpline number in the email which I also rang. I've changed my password. I was told they don't keep any payment details as all payments on their site are processed through PayPal or WorldPay. They were pretty helpful tbf, as indeed they should be.
In reply to Post #15
What else would you expect from a bunch if farmers?
At least they have told people (in the end) which is more than another well known tackle shop did. That said based on a couple of recent cases CC M could be leaving themselves open to legal challenge having admitted they knew in December but made no-one aware.
What else would you expect from a bunch if farmers?
At least they have told people (in the end) which is more than another well known tackle shop did. That said based on a couple of recent cases CC M could be leaving themselves open to legal challenge having admitted they knew in December but made no-one aware.
In reply to Post #29
Good luck with the legal challenges.
Good luck with the legal challenges.
In reply to Post #30
I'm local, anything I used from them i bought from the Stalbridge warehouse.
Next?
I suggest you Google www.Badatabreach.com
The days of companies spending **** all on data security are coming to an end, expect many many cases going to court in the near future no win no fee, it is ten times bigger than PPI. Funny how people are happy to let it slide when it comes to mickey mouse fishing companies but kick off if it's a big national company, the same peronal info is being stolen whichever.
I'm local, anything I used from them i bought from the Stalbridge warehouse.
Next?
I suggest you Google www.Badatabreach.com
The days of companies spending **** all on data security are coming to an end, expect many many cases going to court in the near future no win no fee, it is ten times bigger than PPI. Funny how people are happy to let it slide when it comes to mickey mouse fishing companies but kick off if it's a big national company, the same peronal info is being stolen whichever.
In reply to Post #31
The likelihood and chance of success of legal action depends on the nature of the data lost. The big British Airways data breach a couple of years ago included credit card details and full addresses and contact details. The CCM breach is email adresses and encrypted passwords for their website. Hardly ideal, but less serious in comparison.
Data breaches are more common than we think. Some companies don't notify people at all.
The likelihood and chance of success of legal action depends on the nature of the data lost. The big British Airways data breach a couple of years ago included credit card details and full addresses and contact details. The CCM breach is email adresses and encrypted passwords for their website. Hardly ideal, but less serious in comparison.
Data breaches are more common than we think. Some companies don't notify people at all.
In reply to Post #32
Agreed I think too many folk read too much into the internet.....
Agreed I think too many folk read too much into the internet.....
In reply to Post #32
Quite right but how do you know it's only passwords etc? How do you know if they have credit card details etc stored? I bet your address crops up without your input when you order.
It only takes one case to start the avalanche, your last 7 words are why it's going to be the next no win no fee claim zone.
I'm sure Ian will be along soon, just as quick as he was when his pop up's got a slagging, hang on this started in December so may be not.
Quite right but how do you know it's only passwords etc? How do you know if they have credit card details etc stored? I bet your address crops up without your input when you order.
It only takes one case to start the avalanche, your last 7 words are why it's going to be the next no win no fee claim zone.
I'm sure Ian will be along soon, just as quick as he was when his pop up's got a slagging, hang on this started in December so may be not.
In reply to Post #33
Too many folk dont realize the implications of having their financial info stolen in this day and age.
https://www.metacompliance.com
The above should open your eyes.
The fact they knew about this in December but only let their CUSTOMERS know now is disgusting.
Too many folk dont realize the implications of having their financial info stolen in this day and age.
https://www.metacompliance.com
The above should open your eyes.
The fact they knew about this in December but only let their CUSTOMERS know now is disgusting.
In reply to Post #34
I was told when I called them what data was leaked and was categorically assured it didn't include payment details as they don't store them. I was told that this is all in the breach report to the ICO. Now, you could say I only have their word on this but they'd be pretty crazy to lie to the ICO, and why would they bother reporting it at all if they were then going to lie about the details. Not everything is a conspiracy!!
You're right about data breach claims becoming a big no win no fee business, but I suggest it'll only be for much bigger breaches than this.
I was told when I called them what data was leaked and was categorically assured it didn't include payment details as they don't store them. I was told that this is all in the breach report to the ICO. Now, you could say I only have their word on this but they'd be pretty crazy to lie to the ICO, and why would they bother reporting it at all if they were then going to lie about the details. Not everything is a conspiracy!!
You're right about data breach claims becoming a big no win no fee business, but I suggest it'll only be for much bigger breaches than this.
In reply to Post #36
Your last line is incorrect, a breach is a breach whether that be Apple Inc or CC Moore, the same info is required to make a purchase and the same info can be stolen.
Why the **** do people keep giving fishing companies a free pass, it's all the same FFS. Funny thing is the big boy's take this stuff seriously, i bet some of these mickey mouse bait and tackle companies just have an XL sitting on their main frame waiting for a Russian to sell it to the Dark Web
Your last line is incorrect, a breach is a breach whether that be Apple Inc or CC Moore, the same info is required to make a purchase and the same info can be stolen.
Why the **** do people keep giving fishing companies a free pass, it's all the same FFS. Funny thing is the big boy's take this stuff seriously, i bet some of these mickey mouse bait and tackle companies just have an XL sitting on their main frame waiting for a Russian to sell it to the Dark Web
In reply to Post #37
My God you have an issue with this
Are you registered with CC Moore? If yes someone one has your email address and possibly your password, nothing else as was explained in the email in post 1. Change your password and move on, life is to short and there are more important things in this world.
My God you have an issue with this
Are you registered with CC Moore? If yes someone one has your email address and possibly your password, nothing else as was explained in the email in post 1. Change your password and move on, life is to short and there are more important things in this world.
In reply to Post #38
What people have to think about is a lot of people will have same email and password for all their other logins on other sites, may be even PayPal and online banking. This is why these people target small shops, companies as their security is likely to be poor unlike Amazon so changing your password on just the ccmore website won't help if you one of these people as the hackers will already have access to what they want not your ccmore order history.
What people have to think about is a lot of people will have same email and password for all their other logins on other sites, may be even PayPal and online banking. This is why these people target small shops, companies as their security is likely to be poor unlike Amazon so changing your password on just the ccmore website won't help if you one of these people as the hackers will already have access to what they want not your ccmore order history.
In reply to Post #39
If you use the same password all the time that is not CC Moores fault!
CC Moore is a family owned and run business and they have done the correct (and legal) thing. They are not some faceless plc owned by fat shareholders that are only interested in maxim return on investment. I have dealt with Ian Moore on and off with my bait making for over 20 years and he has always been helpful and honest.
I just don't understand in this thread why everyone is jumping up and down to slag them off when I bet 90% would not say it to his face
the person that did phone them up got an honest, helpful (I think) and quick answer to his questions.
I say well done CC Moore for sorting this out.
If you use the same password all the time that is not CC Moores fault!
CC Moore is a family owned and run business and they have done the correct (and legal) thing. They are not some faceless plc owned by fat shareholders that are only interested in maxim return on investment. I have dealt with Ian Moore on and off with my bait making for over 20 years and he has always been helpful and honest.
I just don't understand in this thread why everyone is jumping up and down to slag them off when I bet 90% would not say it to his face
I say well done CC Moore for sorting this out.
In reply to Post #40
Not blaming ccmore at all just explaining how this may affect some people if the use the same password combination.
They will not be the only retailer that needed to up their website security now or in the future. Customer need to do their play their part too and change their passwords regularly and have different password for each login if not you will be at risk of loosing money at some point.
Not blaming ccmore at all just explaining how this may affect some people if the use the same password combination.
They will not be the only retailer that needed to up their website security now or in the future. Customer need to do their play their part too and change their passwords regularly and have different password for each login if not you will be at risk of loosing money at some point.
In reply to Post #40
I'm sure they are a decent bunch, but when you make wild claims that it's not their fault (their contractors or in-house I.T dept fault) that there was a vulnerability on *their* site, that's just bolloxs mate.
We might not be talking about the NSA or GCHQ level being haxored, even so, and the fact that we've only just been told about it when it happened late last year at around the time when there's a flood of people buying stuff from then up until the end of January....my sceptical antenni are a tingling, you know?
But hey, shills are ganna shill, amiright?
I'm sure they are a decent bunch, but when you make wild claims that it's not their fault (their contractors or in-house I.T dept fault) that there was a vulnerability on *their* site, that's just bolloxs mate.
We might not be talking about the NSA or GCHQ level being haxored, even so, and the fact that we've only just been told about it when it happened late last year at around the time when there's a flood of people buying stuff from then up until the end of January....my sceptical antenni are a tingling, you know?
But hey, shills are ganna shill, amiright?
In chatting to a mate this morning he told me that a MAJOR tackle brand and another large bait brand also recently suffered breaches.
He says in both cases he was told this by employees of those companies. I'm not naming them as the info is 3rd hand but surprised we've not heard about these (unless I missed it, possible!). Shows that we don't always get told.
He says in both cases he was told this by employees of those companies. I'm not naming them as the info is 3rd hand but surprised we've not heard about these (unless I missed it, possible!). Shows that we don't always get told.
In reply to Post #40
Not the sharpest are you mate?
"Done the correct thing" yep that's right, they told everyone weeks and weeks after it happened
Not the sharpest are you mate?
"Done the correct thing" yep that's right, they told everyone weeks and weeks after it happened
In reply to Post #44
Yawn, I'm off.
Yawn, I'm off.
Clearly CC Moore is not whiter than white here. It looks like they have had an unreasonable delay and not taking 100% accountability for the work that they outsourced
But they are a small firm and cyber security is a nightmare, even for large companies.
If they have outsourced payments to PayPal etc. so that they don't hold any credit card details then I am more sympathetic to them than people reusing usernames and passwords.
Especially as we can all store or usernames and passwords in a free password vault on our phones so we don't even have to remember them.
As for people talking about suing them. Seriously? You want to put a bait firm into financial difficulty because you can't even be bothered to maintain basic minimum security practices
But they are a small firm and cyber security is a nightmare, even for large companies.
If they have outsourced payments to PayPal etc. so that they don't hold any credit card details then I am more sympathetic to them than people reusing usernames and passwords.
Especially as we can all store or usernames and passwords in a free password vault on our phones so we don't even have to remember them.
As for people talking about suing them. Seriously? You want to put a bait firm into financial difficulty because you can't even be bothered to maintain basic minimum security practices
In reply to Post #37
I'm guessing you're single as you seem to have a lot of time on your hands?
I'm guessing you're single as you seem to have a lot of time on your hands?
In reply to Post #47
Most blokes if they're not doormats end up single, all alone, living on a campsite/ boat/ tiny flat after they've been rinsed by a parasite, with only a dog for company...good times.
Could well be you in the near future 👌
Most blokes if they're not doormats end up single, all alone, living on a campsite/ boat/ tiny flat after they've been rinsed by a parasite, with only a dog for company...good times.
Could well be you in the near future 👌
In reply to Post #48
Sounds like a very sad life indeed
Sounds like a very sad life indeed
In reply to Post #48
Been there done that and got the tshirt, at the ripe old age of 42 living back with my parents, not going to be lonely with 4 kids a dog and a new partner lol
Been there done that and got the tshirt, at the ripe old age of 42 living back with my parents, not going to be lonely with 4 kids a dog and a new partner lol
In reply to Post #50
Hope it all works out 👍
Hope it all works out 👍
In reply to Post #47
No mate, have a stunning wife, two stunning kid's and a grandson.
No mate, have a stunning wife, two stunning kid's and a grandson.
In reply to Post #52
I was only mucking about glad you're happy
I was only mucking about glad you're happy
In reply to Post #53
He didn't say he was happy
He didn't say he was happy
In reply to Post #54
Her cooking could be a bit better.
Her cooking could be a bit better.
In reply to Post #55
Reading ALL pages