Amazon subsidiary admits security breach

By
07 March 2001 08:44 AM
Tags: security, amazon, hack, customer records, breach, site, compromise, server
Online book searching service Bibliofind shuts down its servers amid fears that up to 100,000 customer records may have been compromised

Amazon.com-owned book service Bibliofind.com restarted its Web site yesterday in the wake of a hacker attack that compromised some 98,000 customer records and forced the company offline.

Bibliofind, which links buyers and sellers of hard-to-find and out-of-print books, discovered last week that a hacker had broken into its Web servers sometime in October and had continued to access the company's site since then, Bibliofind spokesman Jim Courtovich said. The hacker downloaded customer records from the site, including customers' names, addresses and credit card numbers, Courtovich said.

In response to the discovery, Bibliofind, a wholly owned subsidiary of Amazon, shut down its Web site on Friday and removed customers' credit card information and addresses from its servers, he said. Courtovich declined to say whether Bibliofind had identified a suspect in the attack, saying only that the company notified the Federal Bureau of Investigation, which is looking into the matter.

"Bibliofind has just learned of a security violation on its site that compromised the security of credit card information used on Bibliofind's servers," the company said in an e-mail message to customers. "We are working to bring the Bibliofind service back into operation shortly. We apologize for any inconvenience this may cause you."

Although Bibliofind has notified credit card companies of the attack, the company does not have any indication that the numbers have been used, Courtovich said.

The fact that a hacker had access to Bibliofind's records for four months without Bibliofind discovering the breach is simply a case of the company not keeping a good eye on its site, said Richard Power, editorial director of the Computer Security Institute. With that much time and access to Bibliofind's systems, the hacker could possibly have found much more than customer records; he might have been able to find a backdoor into Amazon.com, Power said.

"It's going to take awhile for them to figure out how much damage was really done and who else may have been compromised by being connected by their sites," Power said.

Amazon spokeswoman Patty Smith said the Seattle-based e-tailer's servers were not affected by the attack on Bibliofind. Amazon does not share customer information with Bibliofind and no Amazon customer information was compromised by the breach, she said.

"They operate on different platform than what our server is running on," Smith said. "The integrity of Amazon's systems was never in question."

The Bibliofind breach is only the latest in a string of security breaches at leading e-commerce sites. A breach at Columbia House's Web site left open some 3,700 customer records last month. And in January, a security hole at Travelocity.com exposed the personal information of up to 51,000 customers.

Meanwhile, a breach at Egghead.com in December potentially exposed all of its 3.7 million customer database.

By shutting down its Web servers, Bibliofind also closed down access to Musicfile.com, which shares the same server as Bibliofind. Musicfile's customer records were not affected by the breach, Courtovich said. Bibliofind went back online Monday afternoon.

Amazon acquired both companies when it bought Exchange.com in April 1999.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured