Jump to content
abwsco

Warning from Lush

Recommended Posts

I've posted this on my FB and my Guiding Forum earlier on....I've phoned my bank and had a good chat to someone called Omar in New Delhi. He said not to worry...they'll put a stop to any dodgy payments and ring me...He hadn't heard of Lush:) Keep an eye out for small multiple payments, like O2 or Tesco Mobile...if they go through they make massive withdrawals later on...

Link to comment
Share on other sites

I spotted that too, they are very apologetic on their website.

 

OUR WEBSITE HAS BEEN THE VICTIM OF HACKERS.

 

24 hour security monitoring has shown us that we are still being targeted and there are continuing attempts to re-enter.

 

We refuse to put our customers at risk of another entry - so have decided to completely retire this version of our website.

 

For complete ease of mind, we would like all customers that placed ONLINE orders with us between 4th Oct 2010 and today, 20th Jan 2011, to contact their banks for advice as their card details may have been compromised.

 

We Believe hacking is a serious crime which steals large amounts of money and disrupts the lives of cardholders.

 

We Believe that hacking erodes the trust between businesses and their customers and creates a climate of fear around online ordering.

 

We Believe in working with police and banks to do all we can to bring this branch of organised crime to justice.

Link to comment
Share on other sites

TO THE HACKER

If you are reading this, our web team would like to say that your talents are formidable. We would like to offer you a job - were it not for the fact that your morals are clearly not compatible with ours or our customers'.

 

Love that.

Link to comment
Share on other sites

:wall::wall::wall: I had to repeat what had happened three times to the chap at Santander before he cottoned on to the fact I needed to cancel my card and how flaming annoying it was that since they 'enhanced' the security on their website I cannot log in to check my account. Goodness knows what's been going in and out of it and I'll only find out in 7-10 days when my new log in details arrive. There isn't a branch for miles around so I'll just have to wait and see :roll:

 

I really really hate Santander with a passion. Phoning them is never easy. All I ever want to do is speak to a human being who knows what they're doing and it's such a rigmarole. They first give four options, none of which apply to me, so they repeat them again and I carry on ignoring them. Then I'm asked to key in my card number, simples. Until it then wants my telephone banking number. I don't have one. It asks me three times. I ignore it three times. Then I finally get put in a queue to speak to a person. I really look forward to a repeat of this fun and games should someone have actually used my card details fraudulently :wall:

Link to comment
Share on other sites

:wall::wall::wall: I had to repeat what had happened three times to the chap at Santander before he cottoned on to the fact I needed to cancel my card and how flaming annoying it was that since they 'enhanced' the security on their website I cannot log in to check my account. Goodness knows what's been going in and out of it and I'll only find out in 7-10 days when my new log in details arrive. There isn't a branch for miles around so I'll just have to wait and see :roll:

 

I really really hate Santander with a passion. Phoning them is never easy. All I ever want to do is speak to a human being who knows what they're doing and it's such a rigmarole. They first give four options, none of which apply to me, so they repeat them again and I carry on ignoring them. Then I'm asked to key in my card number, simples. Until it then wants my telephone banking number. I don't have one. It asks me three times. I ignore it three times. Then I finally get put in a queue to speak to a person. I really look forward to a repeat of this fun and games should someone have actually used my card details fraudulently :wall:

 

Oh tell me about it. We had a load of money taken from our business account a year or so ago, and the hours and hours and faf my hubby went through! Cancelling cards so we had no access! It was finally sorted out, but it makes you think twice about phoning them.

 

I am so glad that I didn't buy anything from them this year, as I was going to get the kids a bath bomb each *phew* Hope you all manage to get your fraudulent activities sorted swiftly and easily.

Link to comment
Share on other sites

It isn't where my fraud originated as I haven't shopped online with Lush, only in the store. Mine was sorted straight away by Barclays but with no explanation - oddly, the only online payment I'd made at the time wasn't strictly 'online'....I'd gone to pay my subscription for Home Farmer and noticed that their payment page wasn't secure - no https and no padlock - so I phoned and mentioned it and gave my details over the phone :?

 

Nice to see Lush taking a positive stance over this.

Link to comment
Share on other sites

I'm a bit angry that it was first hacked on 26/27th December, and they are only telling us now.....not good customer service!

 

Yes, but you don't know when the company discovered this had happened. The start date will be when they managed to track back the problem to when it first occured I suspect.

Link to comment
Share on other sites

I'm a bit angry that it was first hacked on 26/27th December, and they are only telling us now.....not good customer service!

 

Yes, but you don't know when the company discovered this had happened. The start date will be when they managed to track back the problem to when it first occured I suspect.

 

Well, I assume ( I know. :oops: ..) that the fact that the site was shut for several days after Christmas due to "website tech issues" was when they first discovered it, and were trying to fix it. Perhaps I'm wrong, but it seems like too much of a coincidence to me. Don't mistake my criticism, I'm a huge fan on Lush....but it seems like they dropped the ball on this one. Despite their Faire Trade, Animal Friendly etc....status, they are a multinational company, and can't be let off he hook by posting a video of lemmings. Would everyone be so understanding if it was Boots or Topshop?? I'm not being argumentative..but reading some of the "fluffy bunny" comments of the Lush FB page has made me really cross :wink:

Link to comment
Share on other sites

I had to have a card cancelled because of this too so not happy.

 

It's surely the first rule of ecommerce that you either don't store card details on your website or else store them in an encrypted manner. To store them unencrypted is reckless and dangerous. FYIW I'm a big fan of how Lush (a local company for me) do things usually...

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.




×
×
  • Create New...