2012-01-18 submit to reddit

Security Breach for Zappos Customers

Over the weekend, Zappos, the online store famous for its vast array of shoes for sale, announced that personal confidential information, including such items as email addresses, partial credit card numbers and encrypted passwords to the Zappos site, of about 24 million of their customers may have been revealed after a hacking attack on a Kentucky data center server that allowed access to Zappos internal networks and data. Zappos confirmed that servers that contained full payment details and full credit card numbers were not accessed.

Zappos, based now in Henderson, Nevada and contemplating a move to Las Vegas, was founded in 1999 and soon became the largest shoe store on the Internet. Over 50,000 varieties and brands of shoes are sold on the Zappos site, from Ugg boots to Nike running shoes. Zappos specializes in supplying customers who need those hard-to-find extra-wide and extra-narrow widths and shoes in extra-large and extra-small sizes; Zappos also has a couture line of shoes for those interested in high-fashion. Since 2007, Zappos sells watches, eyewear and handbags, as well as clothing that includes brands for the big and tall and in petite or plus sizes

In November 2009, Amazon.com bought Zappos for a figure reported to be somewhere around $1.2 billion.

No details were available on the type of attack or on the identity of the perpetrators. The Zappos web site was closed to international traffic as of Monday morning, though the site was still open to US customers. All support calls for Zappos were directed to email in order to free up the phone support lines to deal with this situation and to anticipate the flood of inquiries. All employees at the Zappos headquarters, regardless of current assignment, were requested to help out in handling these inquiries.

In a precautionary move, Zappos reset all the affected passwords to the Zappos site and informed customers of the need to change their passwords; Zappos also recommended that any customers who may be using their Zappos password as a common one that they use to access other Internet sites should change the passwords at those other sites too.

All other aspects of cyber-security appear to be in place for Zappos and its customers. According to the Security web page on the Zappos site, all financial transactions are secured by the use of SSL certificates which have been provided by VeriSign. Connections are encrypted where necessary both internally and externally; the storage used for financial information is firewalled. At this time, Zappos does not require entry of the additional three-digit security code from the backside of credit cards for payment, but is considering the addition of that payment requirement.

kimberly author

Kimberly Dovander


Kimberly is the pro blogger in the WHS family. WordPress, Blogger, Tumblr... It doesn't matter - she knows them all. Send her a question, or a drop a line in the comment section below, and she'll get back to you.

Add Your Thoughts

  • 2012-02-22

    Access to Website Taken Down by US Order

    One of the fears of those who opposed the passage of the SOPA/PIPA Internet anti-piracy legislation in the US Congress last month may have come true. Many in the web hosting industry are concerned over the growi...
    us secret service
  • 2012-02-16

    Lessons Learned from Hack Attacks

    The importance of keeping customers in the loop and making them feel an integral part of a web hosting provider's business was driven home by the recent hack attack on the Cryptome.org web site. Covering whistle...
  • providers giving advise
    2012-02-15

    Web Hosting Providers Acting As Advisors

    Yahoo has recently taken a step for interaction with the customer that all web hosting providers may want to think about emulating. Last week, the beta of Yahoo Small Business premiered to the public as a resour...
  • ipv6 launch
    2012-02-09

    World IPv6 Launch Day Coming Soon

    The Internet Society recently set a date, June 6, 2012, as World IPv6 Launch Day, when it is expected that web companies and major Internet Service Providers (ISPs) will permanently enable the IPv6 protocol for ...
  • 2012-02-07

    SOPA and PIPA Lobbying Payments

    Last month, the United States Congress stopped consideration of two bills, the Stop Online Privacy Act (SOPA) in the US Senate and the Protect Intellectual Property Act (PIPA) in the US House of Representatives,...
  • 2012-01-31

    Problems for DreamHost

    Other web host providers may take a lesson from the recent set of problems that have been the experience of DreamHost, a domain name registrar and web hosting provider founded in 1996 and based in Los Angeles, C...
    dreamhost problems
  • open index
    2012-01-31

    Will New Online Protection Bill Replace SOPA and PIPA?

    With the overwhelming reaction against the Stop Online Piracy Act (SOPA) and the PROTECT IP Act (PIPA), a few members of the United States Congress have put forth an alternative bill. Oregon Democrat Senator Ron...
  • 2012-01-30

    A Closer Look at Magento

    At its simplest, Magento is a robust e-commerce solution built on a foundation of open-source technologies. The blended approach that Magento uses provides the best of both worlds for end-users. On one hand, the...
  • new gtld signing
    2012-01-24

    Smooth Start for New gTLD Program

    ICANN, the Internet Corporation for Assigned Names and Numbers, announced last week that the application system for the new gTLDs (Generic Top-Level Domains) of the Internet began on January 19th and is proceedi...
  • 2012-01-19

    SOPA Stalls, But Online Experts Advise Caution

    Amid Internet site blackouts and public outcries, the Stop Online Piracy Act (SOPA) has been placed on hold in the Senate while sponsors regroup and reconsider their position on this controversial topic. Along w...

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28

Buying Guide

Can't decide what hosting is right for you? Answer 2-5 questions and get your perfect hosting match!

To Questions

User Reviews

Make your voice heard. Review your web hosting provider - good or bad.

  •  
  •  
  •  
  •  
Everything has been very stabile and I was very impressed with all the features and extras that were included in the plan.

Bill about iPage

Read iPage Review

Ask the Editor

Editor

Ask us anything about hosting. We love to help.

David Walsh
editor in chief