I received an email from an email address claiming to be CC Moore, copied below. Note the weird formatting and spelling. Anyone else get this? Looks VERY dodgy to me and as there's nothing on their website about this, where you would expect to see it mentioned? Just thought I'd warn you guys, as this looks very dodgy.
----------------------------------------------------------------------------------------------------------------------------------------------------------
I am writing to let you know about a cyber incident tha= has recently affected CC Moore and which may have resulted in personal in=ormation you have shared with us being compromised.
This letter provid=s information about what happened, what personal information was involved,=nd contact details should you have any questions.
What h=s happened? In December, we became aware that o=r database of customers who have an online shopping account with us was co=promised by an unauthorised and unknown third party. On b=coming aware of this incident, we took immediate action to contain it and =o ensure unauthorised access to our systems was no longer available. A thorough internal investigation indicated that the incident o=curred as a result of an unknown vulnerability in our store web applicatio= which allowed the unknown third party to gain unauthorised access to our =ustomer database.
What personal information has bee= impacted? As a result of this incident, personal informatio= relating to you may have been accessed during this period. If your person=l information was accessed, there is a possibility that your personal info=mation could be used to commit identity theft or fraud. The per=onal information which may have been affected was:
• <="" li="">
• Password information: =he password used on your CC Moore online shopping account
=ote: These passwords were stored in our customer database in an encrypted =ormat.
What action have we taken? As =oon as we became aware of the incident, we took the following steps:
• We worked closely with a team of experts who have assiste= us to take the necessary steps to secure our systems and to investigate f=lly.
• We informed the Information Commissioner's Office.
• We are in the process of contacting those individual customer= who may be affected, including you.
• We invalidated every =ustomer account password such that all customers therefore had to change t=e password for their CC Moore online shopping account upon log in.
What should you do?
As a precauti=n, we recommend that you take the following steps to protect your informat=on:
o Although passwords were stored in our customer =atabase in an encrypted format, it is possible that the encryption could h=ve been compromised. You should therefore change any passwords that are th= same as that which you use for your online shopping account with CC Moore=.
o If you can't access your CC Moore account, this may be be=ause you have not used it within 2 years or live outside the UK.
If t=is is the case, we have now closed your account and removed your personal =ata from our servers. To place an order you will need to create a new acco=nt
o If you are contacted by anyone asking you for personal=nformation or passwords (such as for your bank account), we recommend tha= you take all steps to check the true identity of the organisation.
o If you receive an unsolicited email, we recommend that you do not=lick on any links without first making absolutely sure it is from a trust=orthy source.
o Always check the email address from which em=ils that you receive have been sent and the email's authenticity before re=ponding in any way.
We value the privacy of our custom=rs and we take the issue of IT security extremely seriously. We apologise =or any inconvenience or concern this incident may have caused you.
For =urther information or assistance on this matter, you can contact our data =reach support service provided by Experian by Tel; 0800 9230000 or email: =ata.support@ccmoore.com
Yours sincerely
Ian Moore=br>
Director
CC Moore & Co Ltd
----------------------------------------------------------------------------------------------------------------------------------------------------------
I am writing to let you know about a cyber incident tha= has recently affected CC Moore and which may have resulted in personal in=ormation you have shared with us being compromised.
This letter provid=s information about what happened, what personal information was involved,=nd contact details should you have any questions.
What h=s happened? In December, we became aware that o=r database of customers who have an online shopping account with us was co=promised by an unauthorised and unknown third party. On b=coming aware of this incident, we took immediate action to contain it and =o ensure unauthorised access to our systems was no longer available. A thorough internal investigation indicated that the incident o=curred as a result of an unknown vulnerability in our store web applicatio= which allowed the unknown third party to gain unauthorised access to our =ustomer database.
What personal information has bee= impacted? As a result of this incident, personal informatio= relating to you may have been accessed during this period. If your person=l information was accessed, there is a possibility that your personal info=mation could be used to commit identity theft or fraud. The per=onal information which may have been affected was:
• <="" li="">
• Password information: =he password used on your CC Moore online shopping account
=ote: These passwords were stored in our customer database in an encrypted =ormat.
What action have we taken? As =oon as we became aware of the incident, we took the following steps:
• We worked closely with a team of experts who have assiste= us to take the necessary steps to secure our systems and to investigate f=lly.
• We informed the Information Commissioner's Office.
• We are in the process of contacting those individual customer= who may be affected, including you.
• We invalidated every =ustomer account password such that all customers therefore had to change t=e password for their CC Moore online shopping account upon log in.
What should you do?
As a precauti=n, we recommend that you take the following steps to protect your informat=on:
o Although passwords were stored in our customer =atabase in an encrypted format, it is possible that the encryption could h=ve been compromised. You should therefore change any passwords that are th= same as that which you use for your online shopping account with CC Moore=.
o If you can't access your CC Moore account, this may be be=ause you have not used it within 2 years or live outside the UK.
If t=is is the case, we have now closed your account and removed your personal =ata from our servers. To place an order you will need to create a new acco=nt
o If you are contacted by anyone asking you for personal=nformation or passwords (such as for your bank account), we recommend tha= you take all steps to check the true identity of the organisation.
o If you receive an unsolicited email, we recommend that you do not=lick on any links without first making absolutely sure it is from a trust=orthy source.
o Always check the email address from which em=ils that you receive have been sent and the email's authenticity before re=ponding in any way.
We value the privacy of our custom=rs and we take the issue of IT security extremely seriously. We apologise =or any inconvenience or concern this incident may have caused you.
For =urther information or assistance on this matter, you can contact our data =reach support service provided by Experian by Tel; 0800 9230000 or email: =ata.support@ccmoore.com
Yours sincerely
Ian Moore=br>
Director
CC Moore & Co Ltd
In reply to Post #1
Not me
Not me
In reply to Post #1
Yes, I received one too, and I thought the same as you. It does look dodgy so I have ignored it.
Yes, I received one too, and I thought the same as you. It does look dodgy so I have ignored it.
In reply to Post #3
I got one too
I got one too
I received it too this morning. Checking the email address it came from it is the same email address that CC Moore uses and checking with an old email address it is identical so it is not one based in Nigeria etc and is an legitamet address.
I checked my account and I do not have one with them, probably because it has been years since I traded with them, but, they must still have my email address somewhere to have sent me this message.
I checked my account and I do not have one with them, probably because it has been years since I traded with them, but, they must still have my email address somewhere to have sent me this message.
In reply to Post #1
I've got one too, nothing on their FB page either.
Daz
I've got one too, nothing on their FB page either.
Daz
In reply to Post #6
Me too just emailed them to see if it's genuine or not
Me too just emailed them to see if it's genuine or not
In reply to Post #1
Just had a message from them on FB, it's genuine.
Daz
Just had a message from them on FB, it's genuine.
Daz
Why do you not thinks its legit? They are not asking you to do anything just informing you (as they should) of the fact your data may have been compromised. This is only for people who have registered with them to buy direct.
The only links in the email are to a legit email address. Whats the scam in that?
Many more customers buy via distributors so plastering it all over FB etc would seem a little daft when they have the contact details off all those possibly affected so just contacted them direct (which they did).
Well done for them coming clean, I suspect many others would/ have not in the past
The only links in the email are to a legit email address. Whats the scam in that?
Many more customers buy via distributors so plastering it all over FB etc would seem a little daft when they have the contact details off all those possibly affected so just contacted them direct (which they did).
Well done for them coming clean, I suspect many others would/ have not in the past
I've had one too but I've not ordered anything from them for ages
In reply to Post #9
Clearly you know very little about phishing - ANY email that has errors in it, is badly formatted or comes straight into your junk folder - you treat it with suspicion! Oh and just as there's no links, doesn't mean it's not dodgy FFS. Coming clean my bobbins - they are legally bound to come clean, you'd know that if GDPR meant anything to you. They have not put anything on their website yet. so that's poor. If anyone suffers any kind of fraudulent act as a result of this data breach, they can sue them and of course, the ICO can fine them rather a lot.
Clearly you know very little about phishing - ANY email that has errors in it, is badly formatted or comes straight into your junk folder - you treat it with suspicion! Oh and just as there's no links, doesn't mean it's not dodgy FFS. Coming clean my bobbins - they are legally bound to come clean, you'd know that if GDPR meant anything to you. They have not put anything on their website yet. so that's poor. If anyone suffers any kind of fraudulent act as a result of this data breach, they can sue them and of course, the ICO can fine them rather a lot.
I got one, just reset my password and job done
In reply to Post #12
Same as.
Same as.
In reply to Post #11
My email was perfectly formatted and had zero phishing in it! If yours came formatted like that I would suspect your email client and filter provider.
I am fully aware of GDPR and many do not come clean. They have done the correct (and legal) thing and get slatted for it
My password has been reset and the one I used on there was unique so nothing more to be done.
My email was perfectly formatted and had zero phishing in it! If yours came formatted like that I would suspect your email client and filter provider.
I am fully aware of GDPR and many do not come clean. They have done the correct (and legal) thing and get slatted for it
My password has been reset and the one I used on there was unique so nothing more to be done.
In reply to Post #14
I got one too, however it would have been nice to have been informed about 6 weeks ago.
I got one too, however it would have been nice to have been informed about 6 weeks ago.