Live data from Hacker News

Credit cards used on cvsphoto.com may have been compromised

cvsphoto.com

1–10 of 61 posts

Re: Credit cards used on cvsphoto.com may have been compromised

#2
For those not looking to click through to the site:

====

We have been made aware that customer credit card information collected by the independent vendor who manages and hosts CVSPhoto.com may have been compromised. As a precaution, as our investigation is underway, we are temporarily shutting down access to online and related mobile photo services. We apologize for the inconvenience and are working diligently to resume service as soon as possible. Your images are saved and you will have access to them once service to CVSPhoto.com is restored. Our in-store photo centers are not affected and remain in service. Film and disposable camera orders are being processed and your CVS/pharmacy will contact you when they are received.

Customers who provided credit card information for transactions on CVSPhoto.com are advised to check their credit card statements for any fraudulent or suspicious activity and to call their bank or financial institution to report anything of concern.

Customer registrations related to online photo processing and CVSPhoto.com are completely separate from CVS.com, optical.cvs.com, cvs.com/MinuteClinic on line bill pay and our pharmacies. Financial transactions on CVS.com, optical.cvs.com, cvs.com/MinuteClinic and in-store are not affected.

Nothing is more central to us than protecting the privacy and security of our customer information, including financial information. We are working closely with the vendor and our financial partners and will share updates as we know more.

For more information, call 1-800-SHOP-CVS.

====

Re: Credit cards used on cvsphoto.com may have been compromised

#5
Same thing happened to Costco a few weeks ago. Maybe the same company behind both. From http://www.costcophotocenter.com/

===

As a result of recent reports suggesting that there may have been a security compromise of the third party vendor that hosts Costcophotocenter.com, we are temporarily suspending access to the site. We take the security of our members’ data seriously, which is why we are taking this precautionary step. This decision does not affect any other Costco website or our in-store operations, including in-store photo centers.

This situation is affecting multiple online photo sites. We are diligently working to determine when we can re-enable the site, but in all likelihood that will not occur until the middle of August. We will update this statement when we have more information.

Re: Credit cards used on cvsphoto.com may have been compromised

#6
post #2

For those not looking to click through to the site: ==== We have been made aware that customer credit card information collected by the independent vendor who manages and hosts CVSPhoto.com may have been compromised. As a precaution, as our investigation is underway, we are temporarily shutting down access to online and related mobile photo services. We apologize for the inconvenience and are working diligently to re…

Thank you, this is a very valuable and useful comment.

Re: Credit cards used on cvsphoto.com may have been compromised

#8
Like others have said about this happening to Costco too, this is all because CVS, Costco, Sam’s Club, Walmart Canada, and Rite Aid use PNI Media as a backend for their photo services and PNI seems to have been hacked:

http://krebsonsecurity.com/2015/07/cvs-probes-card-breach-at...

Post reply on HN