Acer settles online breach probe for $115k: Difference between revisions
Bythmusters (talk | contribs) m added cargo |
m Add missing archival URLs |
||
| Line 21: | Line 21: | ||
===Acer's response=== | ===Acer's response=== | ||
According to the customer notice letter submitted to the California Attorney General’s office:<ref>Acer's Notice of Breach to Customers | According to the customer notice letter submitted to the California Attorney General’s office:<ref>{{Cite web |author=Mark Groveunder |date= |title=Acer's Notice of Breach to Customers |url=https://oag.ca.gov/system/files/Customer%20Notice%20Letter%20-%20California_0.pdf |url-status=live |archive-url=https://web.archive.org/web/20161016121726/https://oag.ca.gov/system/files/Customer%20Notice%20Letter%20-%20California_0.pdf |archive-date=2016-10-16 |access-date=2026-02-06}}</ref> | ||
*Notification: Acer sent a formal ''Notice of Data Breach'' to impacted customers, informing them that if they shopped on the Acer e-commerce site between May 12, 2015 and April 28, 2016, their personal and payment information may have been exposed, including name, address, credit card number (with the last digits specified), expiration date, and CVV security code. Acer clarified the hackers did not collect Social Security numbers, and they had no evidence that passwords or login credentials were compromised California DOJ Attorney General. It should be noted that in the settlement with the New York State Attorney General, Acer admitted username and passwords were part of the breach.<ref name=":0" /> | *Notification: Acer sent a formal ''Notice of Data Breach'' to impacted customers, informing them that if they shopped on the Acer e-commerce site between May 12, 2015 and April 28, 2016, their personal and payment information may have been exposed, including name, address, credit card number (with the last digits specified), expiration date, and CVV security code. Acer clarified the hackers did not collect Social Security numbers, and they had no evidence that passwords or login credentials were compromised California DOJ Attorney General. It should be noted that in the settlement with the New York State Attorney General, Acer admitted username and passwords were part of the breach.<ref name=":0" /> | ||
| Line 37: | Line 37: | ||
==Consumer response== | ==Consumer response== | ||
Consumers expressed frustration, distrust, and tangible harm following Acer’s data breach. On HardForum, several posters reported that they never received a notification from Acer despite being affected, and some discovered fraudulent charges on their credit cards after purchasing through Acer’s online store.<ref>{{Cite web |author=HardOCP News |date=2016-06-20 |title=Acer Admits Hackers Stole Up To 34,000 Customer Credit Cards |url=https://hardforum.com/threads/acer-admits-hackers-stole-up-to-34-000-customer-credit-cards.1902876/ |url-status=live |archive-url= |archive-date= |access-date= | Consumers expressed frustration, distrust, and tangible harm following Acer’s data breach. On HardForum, several posters reported that they never received a notification from Acer despite being affected, and some discovered fraudulent charges on their credit cards after purchasing through Acer’s online store.<ref>{{Cite web |author=HardOCP News |date=2016-06-20 |title=Acer Admits Hackers Stole Up To 34,000 Customer Credit Cards |url=https://hardforum.com/threads/acer-admits-hackers-stole-up-to-34-000-customer-credit-cards.1902876/ |url-status=live |archive-url=https://web.archive.org/web/20260202121316/https://hardforum.com/threads/acer-admits-hackers-stole-up-to-34-000-customer-credit-cards.1902876/ |archive-date=2026-02-02 |access-date=2026-02-06 |website=[H]ardForum}}</ref> Others criticized Acer for mishandling sensitive payment data, particularly for storing CVV codes, which violates standard payment card security rules. The overall tone was one of anger at both the breach and Acer’s poor communication. | ||
On The Register’s forum, reactions were similarly skeptical and critical.<ref>{{Cite web |last=Nichols |first=Shaun |date=2016-06-17 |title=You Acer holes! PC maker leaks payment cards in e-store hack |url=https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |archive-url=https://web.archive.org/web/20260104042936/https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |archive-date=2026-01-04 |access-date=2025-08-18 |website=The Register}}</ref> Commenters condemned Acer for failing to follow PCI DSS compliance standards and for allowing card verification codes to be compromised.<ref>{{Cite web |last=Pasher |first=Justin |date=2016-06-17 |title=Re: Storing CC security verification codes |url=https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |archive-url=https://web.archive.org/web/20260104043419/https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |archive-date=2026-01-04 |access-date=2025-08-18 |website=Forum on 'The Register'}}</ref> Some users confirmed they did receive breach notification letters, though experiences varied widely. Many expressed concern that Acer’s negligence would push costs and risks onto consumers through fraudulent charges and credit monitoring needs. | On The Register’s forum, reactions were similarly skeptical and critical.<ref>{{Cite web |last=Nichols |first=Shaun |date=2016-06-17 |title=You Acer holes! PC maker leaks payment cards in e-store hack |url=https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |archive-url=https://web.archive.org/web/20260104042936/https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |archive-date=2026-01-04 |access-date=2025-08-18 |website=The Register}}</ref> Commenters condemned Acer for failing to follow PCI DSS compliance standards and for allowing card verification codes to be compromised.<ref>{{Cite web |last=Pasher |first=Justin |date=2016-06-17 |title=Re: Storing CC security verification codes |url=https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |archive-url=https://web.archive.org/web/20260104043419/https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |archive-date=2026-01-04 |access-date=2025-08-18 |website=Forum on 'The Register'}}</ref> Some users confirmed they did receive breach notification letters, though experiences varied widely. Many expressed concern that Acer’s negligence would push costs and risks onto consumers through fraudulent charges and credit monitoring needs. | ||