tdiparts got hacked?

Status
Not open for further replies.

edstreet

Member
Joined
Apr 4, 2007
Location
Columbus, GA
TDI
2004
Anyone else get one of these or know whats going on here??
I just received this email from tdiparts:

Dear Ed

TDIParts experienced a breach to its data files on March 16, 2009. As a result, credit card numbers were copied from our site. Although we've found out how the cards were stolen and fixed the problem, you're receiving this email because we've identified you as a customer who has used a credit card number to purchase from us, and we show that credit card as still valid (not expired). If you've purchased via PayPal, already canceled your card, or if your card has expired then please disregard this message.

If you do have a valid credit card that you used to purchase with us, please contact your card provider immediately. Tell them there's a fraud risk with the card and ask them to replace it. This will protect you from any future risk as a result of this incident. The card number you used for the purchase ended in these four numbers: XXXX.

We've taken a number of steps to prevent this from happening in the future. As of March 26 we only store the last four digits of credit card numbers on our site. And we've added new software to monitor our site both for vulnerabilities and hacking. As a result, we believe the site is safe, and you should be able to make purchases with confidence that your data will not be compromised.

I apologize for any inconvenience this has caused. If you believe you've experienced fraud as a result of purchasing from us, please report it to me at peter@tdiparts.com. We've reported this incident to the FBI and local authorities and want to provide them with a list of affected individuals. Most credit card companies provide protection that relieves you from any obligation to pay fraudulent charges. But if you've experienced any financial loss as a result of this event please contact me.

Thank you for your business.

Peter Noble
Principal, TDIParts
peter@tdiparts.com
Before anyone mentions it yes the headers and mail server logs does check out ok on this, it's not a spoof. Yes I do own the mail server and have full access to the email logs as well.
 

Ookpic

Veteran Member
Joined
Jun 20, 2008
Location
London, ON - Port Huron, MI
TDI
2002 Golf 2Dr 5spd
It is in fact a legit email. There was a problem with TDIParts website. It has been fixed.

Peter addressed this in the Vender Accountability Thread post #9.

There was another thread that was started by a member previous to TDI Parts being aware of the attack which I can't locate. Doesn't really matter as your question is answered.
 

pruzink

Veteran Member
Joined
Sep 25, 2004
Location
Granbury, Texas
TDI
GLS, 2004, silver
Unfortunately, these types of things happen a lot more often than we know. I give TDI parts credit for at least sending out an email to notify people about the potential problem. About a year ago, I happened to read an article in the paper about that happening to TJ Max (my wife likes to shop there). Not too long after that we got a call from our credit card company that someone had gone on a shopping spree with our card (I live in CT., the card was used in CA). Its just a PITA having to change around accounts that you use the card for auto bill pays; you won't be held liable for the charges if someone does use it. Its a good idea to have a 2nd CC in case this happens because they will halt all use once suspicious activity is flagged.
 

n1das

TDIClub Enthusiast, Veteran Member
Joined
Jun 11, 2002
Location
Nashua, NH, USA
TDI
2014 BMW 535xd ///M-Sport, 2012 BMW X5 Xdrive35d, former 3x TDI owner
Ookpic said:
It is in fact a legit email. There was a problem with TDIParts website. It has been fixed.

Peter addressed this in the Vender Accountability Thread post #9.

There was another thread that was started by a member previous to TDI Parts being aware of the attack which I can't locate. Doesn't really matter as your question is answered.
I received the same email this evening and immediately called up my CC issuer and shut down the CC and a replacement CC is on the way. I have not experienced any fraud activity from what I can tell.

Many thanks and Kudos to Peter for his very rapid response! :cool:
 

Sip'n Diesel

Veteran Newbie
Joined
Apr 13, 2008
Location
San Joaquin Valley, I have VCDS (KII-USB)
TDI
2003 ALH: 254,000 miles
Ookpic said:
There was another thread that was started by a member previous to TDI Parts being aware of the attack which I can't locate.
that's the one I was looking for. went through all my posts back to 3/15 and didn't see it. it was likely deleted after someone suggested it was a good candidate for the Vendor Accountability Thread
 

ocelot

Veteran Member
Joined
Oct 9, 2005
Location
Fairfax, VA
TDI
'96 Passat TDi
I was affected as well, and there was fraud on my card. It's been closed, but I still have to deal with the CC company to dispute the charges.
 

Nocky

Veteran Member
Joined
Sep 6, 2006
Location
Iowa
TDI
2003 Jetta wagon
My card company sent some new cards the other day. This was before I got the email:confused:
 
Status
Not open for further replies.
Top