CarpForum.co.uk brand mark, a blue stylized fish with a white eye and a smooth modern look, set in the site header against a clean background CarpForum.co.uk wordmark in a bold flowing script style, reading CarpForum.co.uk, displayed in the site header
Menu
Utils
Go Premium Who's Online Members Weather Photo Gallery Articles
Account
Login Register
CC Moore - data breach (56 posts / 5,830 views)
SilureMark
Posts: 1,282
Post #1 5 Feb 2021 10:16
0
I received an email from an email address claiming to be CC Moore, copied below. Note the weird formatting and spelling. Anyone else get this? Looks VERY dodgy to me and as there's nothing on their website about this, where you would expect to see it mentioned? Just thought I'd warn you guys, as this looks very dodgy.

----------------------------------------------------------------------------------------------------------------------------------------------------------

I am writing to let you know about a cyber incident tha= has recently affected CC Moore and which may have resulted in personal in=ormation you have shared with us being compromised.
This letter provid=s information about what happened, what personal information was involved,=nd contact details should you have any questions.

What h=s happened? In December, we became aware that o=r database of customers who have an online shopping account with us was co=promised by an unauthorised and unknown third party. On b=coming aware of this incident, we took immediate action to contain it and =o ensure unauthorised access to our systems was no longer available. A thorough internal investigation indicated that the incident o=curred as a result of an unknown vulnerability in our store web applicatio= which allowed the unknown third party to gain unauthorised access to our =ustomer database.

What personal information has bee= impacted? As a result of this incident, personal informatio= relating to you may have been accessed during this period. If your person=l information was accessed, there is a possibility that your personal info=mation could be used to commit identity theft or fraud. The per=onal information which may have been affected was:


• <="" li="">
• Password information: =he password used on your CC Moore online shopping account
=ote: These passwords were stored in our customer database in an encrypted =ormat.


What action have we taken? As =oon as we became aware of the incident, we took the following steps:

• We worked closely with a team of experts who have assiste= us to take the necessary steps to secure our systems and to investigate f=lly.

• We informed the Information Commissioner's Office.
• We are in the process of contacting those individual customer= who may be affected, including you.

• We invalidated every =ustomer account password such that all customers therefore had to change t=e password for their CC Moore online shopping account upon log in.

What should you do?

As a precauti=n, we recommend that you take the following steps to protect your informat=on:


o Although passwords were stored in our customer =atabase in an encrypted format, it is possible that the encryption could h=ve been compromised. You should therefore change any passwords that are th= same as that which you use for your online shopping account with CC Moore=.

o If you can't access your CC Moore account, this may be be=ause you have not used it within 2 years or live outside the UK.
If t=is is the case, we have now closed your account and removed your personal =ata from our servers. To place an order you will need to create a new acco=nt

o If you are contacted by anyone asking you for personal=nformation or passwords (such as for your bank account), we recommend tha= you take all steps to check the true identity of the organisation.
o If you receive an unsolicited email, we recommend that you do not=lick on any links without first making absolutely sure it is from a trust=orthy source.

o Always check the email address from which em=ils that you receive have been sent and the email's authenticity before re=ponding in any way.


We value the privacy of our custom=rs and we take the issue of IT security extremely seriously. We apologise =or any inconvenience or concern this incident may have caused you.
For =urther information or assistance on this matter, you can contact our data =reach support service provided by Experian by Tel; 0800 9230000 or email: =ata.support@ccmoore.com

Yours sincerely

Ian Moore=br>
Director

CC Moore & Co Ltd
framey framey
Posts: 5,319
Post #2 5 Feb 2021 10:22
0
In reply to Post #1
Not me
JimSlimmon JimSlimmon
Posts: 311
Post #3 5 Feb 2021 11:22
0
In reply to Post #1
Yes, I received one too, and I thought the same as you. It does look dodgy so I have ignored it.
bristol bristol
Posts: 2,288
Post #4 5 Feb 2021 11:23
0
In reply to Post #3
I got one too
Zack
Posts: 3,205
Post #5 5 Feb 2021 11:25
0
I received it too this morning. Checking the email address it came from it is the same email address that CC Moore uses and checking with an old email address it is identical so it is not one based in Nigeria etc and is an legitamet address.

I checked my account and I do not have one with them, probably because it has been years since I traded with them, but, they must still have my email address somewhere to have sent me this message.
Dazjones Dazjones
Posts: 10,613
Post #6 5 Feb 2021 11:26
0
In reply to Post #1
I've got one too, nothing on their FB page either.

Daz
daytripper daytripper
Posts: 387
Post #7 5 Feb 2021 11:32
0
In reply to Post #6
Me too just emailed them to see if it's genuine or not
Dazjones Dazjones
Posts: 10,613
Post #8 5 Feb 2021 11:35
0
In reply to Post #1
Just had a message from them on FB, it's genuine.

Daz
Smurf Smurf
Posts: 3,505
Post #9 5 Feb 2021 11:41
0
Why do you not thinks its legit? They are not asking you to do anything just informing you (as they should) of the fact your data may have been compromised. This is only for people who have registered with them to buy direct.

The only links in the email are to a legit email address. Whats the scam in that?

Many more customers buy via distributors so plastering it all over FB etc would seem a little daft when they have the contact details off all those possibly affected so just contacted them direct (which they did).

Well done for them coming clean, I suspect many others would/ have not in the past
PaulC70
Posts: 90
Post #10 5 Feb 2021 12:18
0
I've had one too but I've not ordered anything from them for ages
SilureMark
Posts: 1,282
Post #11 5 Feb 2021 14:08
0
In reply to Post #9
Clearly you know very little about phishing - ANY email that has errors in it, is badly formatted or comes straight into your junk folder - you treat it with suspicion! Oh and just as there's no links, doesn't mean it's not dodgy FFS. Coming clean my bobbins - they are legally bound to come clean, you'd know that if GDPR meant anything to you. They have not put anything on their website yet. so that's poor. If anyone suffers any kind of fraudulent act as a result of this data breach, they can sue them and of course, the ICO can fine them rather a lot.
Chuffy Chuffy
Posts: 6,794
Post #12 5 Feb 2021 14:55
0
I got one, just reset my password and job done
scar
Posts: 6,095
Post #13 5 Feb 2021 15:01
0
In reply to Post #12
Same as.
Smurf Smurf
Posts: 3,505
Post #14 5 Feb 2021 15:02
0
In reply to Post #11
My email was perfectly formatted and had zero phishing in it! If yours came formatted like that I would suspect your email client and filter provider.

I am fully aware of GDPR and many do not come clean. They have done the correct (and legal) thing and get slatted for it

My password has been reset and the one I used on there was unique so nothing more to be done.
audiguypaul audiguypaul
Posts: 1,534
Post #15 5 Feb 2021 15:29
0
In reply to Post #14
I got one too, however it would have been nice to have been informed about 6 weeks ago.
Richpp1989 Richpp1989
Posts: 2,078
Post #16 5 Feb 2021 16:36
0
I got one this morning just logged into my account through the actual cc Moore website and reset my password, no big deal
mattycarphunter mattycarphunter
Posts: 1,280
Post #17 5 Feb 2021 17:29
0
In reply to Post #16
might not seem like a big deal....BUT to have got this far clearly a lot of information has been nicked including personal contact details, addresses, passwords. It's no big deal until you are "done" and someone's nicked your identity, unravelling that can be a very horrible process.

TeeCee
Posts: 2,009
Post #18 5 Feb 2021 17:43
0
I got the email but I'm not receiving any emails with links to change my password, great!

So I wonder if they've got payment details from this scam? Might be an idea to chase them up and find out what the deal is.
SilureMark
Posts: 1,282
Post #19 5 Feb 2021 17:53
0
In reply to Post #17
My point exactly. Some people just don't take these things very seriously and they really should. I thought it very poor show for CC Moore to send out such a crap message and at the same time, fail to validate on their website. Just glad my email caught it and didn't put in my inbox. I only hope no one suffers because of the data breach.
Riggy Riggy
Posts: 2,044
Post #20 5 Feb 2021 18:28
0
I got one this morning but had to change password two weeks ago so should I have got the email two weeks ago?

Michael
scozza
Posts: 18,421
Post #21 5 Feb 2021 19:19
0
In reply to Post #19
Well said, what a crap email. I saw it and thought it was a hoax!

So it's official then
JasonM JasonM
Posts: 1,764
Post #22 5 Feb 2021 20:01
0
In reply to Post #21
Sadly data breaches happen all to often and even to the biggest and most respected organizations .

Not much more than can do than tell us whatever we think of their mail.

Happy Fridays 😄
lilharbs lilharbs
Posts: 1,630
Post #23 5 Feb 2021 20:05
0
I received the email myself today, and have just reset the password. On the home page they state that their new website is soon to go live, and could everybody please reset their password as a result.....

🤔 bit of a coincidence that, what with a data breach. At least they could have been honest, or perhaps the mistake is mine in assuming something........
Shadow Shadow
Posts: 1,006
Post #24 5 Feb 2021 20:17
0
In reply to Post #23
Strange as the email received is not even from same domain name ... @ccmoore.net when their website is ccmoore.com ?
JasonM JasonM
Posts: 1,764
Post #25 5 Feb 2021 20:35
0
In reply to Post #24
Too much deep thinking on a Friday - you lot need to get out more ahh but we can't 😃

Have a drink end of another working week - keep positive.
luckyjim luckyjim
Posts: 3,626
Post #26 5 Feb 2021 20:41
0
I haven't had one, if I had I would inform my bank asap NOT to pay CC Moore until I advise them to.
Mr-Bean-Laden Mr-Bean-Laden
Posts: 2,243
Post #27 5 Feb 2021 20:58
0
Mine was in my spam box so I just deleted it
shingoose shingoose
Posts: 38
Post #28 5 Feb 2021 22:48
0
I received the email from CCMoore today. It was pretty clearly written and appeared genuine, but you never know so I called them on their normal number to check and it IS 100% genuine.

There is also a dedicated helpline number in the email which I also rang. I've changed my password. I was told they don't keep any payment details as all payments on their site are processed through PayPal or WorldPay. They were pretty helpful tbf, as indeed they should be.
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #29 5 Feb 2021 22:54
0
In reply to Post #15
What else would you expect from a bunch if farmers?

At least they have told people (in the end) which is more than another well known tackle shop did. That said based on a couple of recent cases CC M could be leaving themselves open to legal challenge having admitted they knew in December but made no-one aware.
JasonM JasonM
Posts: 1,764
Post #30 5 Feb 2021 22:56
0
In reply to Post #29
Good luck with the legal challenges.
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #31 5 Feb 2021 22:58
0
In reply to Post #30
I'm local, anything I used from them i bought from the Stalbridge warehouse.

Next?

I suggest you Google www.Badatabreach.com

The days of companies spending **** all on data security are coming to an end, expect many many cases going to court in the near future no win no fee, it is ten times bigger than PPI. Funny how people are happy to let it slide when it comes to mickey mouse fishing companies but kick off if it's a big national company, the same peronal info is being stolen whichever.
shingoose shingoose
Posts: 38
Post #32 5 Feb 2021 23:18
0
In reply to Post #31
The likelihood and chance of success of legal action depends on the nature of the data lost. The big British Airways data breach a couple of years ago included credit card details and full addresses and contact details. The CCM breach is email adresses and encrypted passwords for their website. Hardly ideal, but less serious in comparison.
Data breaches are more common than we think. Some companies don't notify people at all.
JasonM JasonM
Posts: 1,764
Post #33 5 Feb 2021 23:26
0
In reply to Post #32
Agreed I think too many folk read too much into the internet.....
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #34 5 Feb 2021 23:29
0
In reply to Post #32
Quite right but how do you know it's only passwords etc? How do you know if they have credit card details etc stored? I bet your address crops up without your input when you order.

It only takes one case to start the avalanche, your last 7 words are why it's going to be the next no win no fee claim zone.

I'm sure Ian will be along soon, just as quick as he was when his pop up's got a slagging, hang on this started in December so may be not.

SPINBOWLER SPINBOWLER
Posts: 1,418
Post #35 5 Feb 2021 23:32
0
In reply to Post #33
Too many folk dont realize the implications of having their financial info stolen in this day and age.

https://www.metacompliance.com

The above should open your eyes.

The fact they knew about this in December but only let their CUSTOMERS know now is disgusting.
shingoose shingoose
Posts: 38
Post #36 5 Feb 2021 23:39
0
In reply to Post #34
I was told when I called them what data was leaked and was categorically assured it didn't include payment details as they don't store them. I was told that this is all in the breach report to the ICO. Now, you could say I only have their word on this but they'd be pretty crazy to lie to the ICO, and why would they bother reporting it at all if they were then going to lie about the details. Not everything is a conspiracy!!

You're right about data breach claims becoming a big no win no fee business, but I suggest it'll only be for much bigger breaches than this.
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #37 5 Feb 2021 23:48
0
In reply to Post #36
Your last line is incorrect, a breach is a breach whether that be Apple Inc or CC Moore, the same info is required to make a purchase and the same info can be stolen.

Why the **** do people keep giving fishing companies a free pass, it's all the same FFS. Funny thing is the big boy's take this stuff seriously, i bet some of these mickey mouse bait and tackle companies just have an XL sitting on their main frame waiting for a Russian to sell it to the Dark Web
Smurf Smurf
Posts: 3,505
Post #38 6 Feb 2021 09:02
0
In reply to Post #37
My God you have an issue with this

Are you registered with CC Moore? If yes someone one has your email address and possibly your password, nothing else as was explained in the email in post 1. Change your password and move on, life is to short and there are more important things in this world.
Shadow Shadow
Posts: 1,006
Post #39 6 Feb 2021 09:29
0
In reply to Post #38
What people have to think about is a lot of people will have same email and password for all their other logins on other sites, may be even PayPal and online banking. This is why these people target small shops, companies as their security is likely to be poor unlike Amazon so changing your password on just the ccmore website won't help if you one of these people as the hackers will already have access to what they want not your ccmore order history.

Smurf Smurf
Posts: 3,505
Post #40 6 Feb 2021 09:47
0
In reply to Post #39
If you use the same password all the time that is not CC Moores fault!

CC Moore is a family owned and run business and they have done the correct (and legal) thing. They are not some faceless plc owned by fat shareholders that are only interested in maxim return on investment. I have dealt with Ian Moore on and off with my bait making for over 20 years and he has always been helpful and honest.

I just don't understand in this thread why everyone is jumping up and down to slag them off when I bet 90% would not say it to his face the person that did phone them up got an honest, helpful (I think) and quick answer to his questions.

I say well done CC Moore for sorting this out.
Shadow Shadow
Posts: 1,006
Post #41 6 Feb 2021 10:15
0
In reply to Post #40
Not blaming ccmore at all just explaining how this may affect some people if the use the same password combination.

They will not be the only retailer that needed to up their website security now or in the future. Customer need to do their play their part too and change their passwords regularly and have different password for each login if not you will be at risk of loosing money at some point.
TeeCee
Posts: 2,009
Post #42 6 Feb 2021 10:28
0
In reply to Post #40
I'm sure they are a decent bunch, but when you make wild claims that it's not their fault (their contractors or in-house I.T dept fault) that there was a vulnerability on *their* site, that's just bolloxs mate.

We might not be talking about the NSA or GCHQ level being haxored, even so, and the fact that we've only just been told about it when it happened late last year at around the time when there's a flood of people buying stuff from then up until the end of January....my sceptical antenni are a tingling, you know?

But hey, shills are ganna shill, amiright?
shingoose shingoose
Posts: 38
Post #43 6 Feb 2021 12:58
0
In chatting to a mate this morning he told me that a MAJOR tackle brand and another large bait brand also recently suffered breaches.

He says in both cases he was told this by employees of those companies. I'm not naming them as the info is 3rd hand but surprised we've not heard about these (unless I missed it, possible!). Shows that we don't always get told.
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #44 6 Feb 2021 13:42
0
In reply to Post #40
Not the sharpest are you mate?

"Done the correct thing" yep that's right, they told everyone weeks and weeks after it happened
Smurf Smurf
Posts: 3,505
Post #45 6 Feb 2021 15:36
0
In reply to Post #44
Yawn, I'm off.
kizzi
Posts: 2,526
Post #46 6 Feb 2021 20:07
0
Clearly CC Moore is not whiter than white here. It looks like they have had an unreasonable delay and not taking 100% accountability for the work that they outsourced

But they are a small firm and cyber security is a nightmare, even for large companies.

If they have outsourced payments to PayPal etc. so that they don't hold any credit card details then I am more sympathetic to them than people reusing usernames and passwords.
Especially as we can all store or usernames and passwords in a free password vault on our phones so we don't even have to remember them.

As for people talking about suing them. Seriously? You want to put a bait firm into financial difficulty because you can't even be bothered to maintain basic minimum security practices
Bristolsaint40 Bristolsaint40
Posts: 243
Post #47 8 Feb 2021 10:10
0
In reply to Post #37
I'm guessing you're single as you seem to have a lot of time on your hands?
TeeCee
Posts: 2,009
Post #48 8 Feb 2021 11:32
0
In reply to Post #47
Most blokes if they're not doormats end up single, all alone, living on a campsite/ boat/ tiny flat after they've been rinsed by a parasite, with only a dog for company...good times.

Could well be you in the near future 👌
braders1978 braders1978
Posts: 18,195
Post #49 8 Feb 2021 11:36
0
In reply to Post #48
Sounds like a very sad life indeed
Bristolsaint40 Bristolsaint40
Posts: 243
Post #50 8 Feb 2021 11:50
0
In reply to Post #48
Been there done that and got the tshirt, at the ripe old age of 42 living back with my parents, not going to be lonely with 4 kids a dog and a new partner lol
TeeCee
Posts: 2,009
Post #51 8 Feb 2021 17:35
0
In reply to Post #50
Hope it all works out 👍
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #52 8 Feb 2021 18:08
0
In reply to Post #47
No mate, have a stunning wife, two stunning kid's and a grandson.

Bristolsaint40 Bristolsaint40
Posts: 243
Post #53 9 Feb 2021 00:14
0
In reply to Post #52


I was only mucking about glad you're happy
Chuffy Chuffy
Posts: 6,794
Post #54 9 Feb 2021 10:04
0
In reply to Post #53
He didn't say he was happy
SPINBOWLER SPINBOWLER
Posts: 1,418
Post #55 9 Feb 2021 15:24
0
In reply to Post #54
Her cooking could be a bit better.
Chuffy Chuffy
Posts: 6,794
Post #56 9 Feb 2021 16:17
0
In reply to Post #55
Reading ALL pages
Are you sure?

This action cannot be undone.

Yes, continue

Loading…