Vudu, a subscription-based digital entertainment service, says that crooks walked off with a number of items, including hard drives when they broke into their offices last month. The company says the delay in notification was due to a request form law enforcement investigating the break-in.
The company stresses that their corporate website wasn’t hacked, but that thieves broke into their offices on March 24, 2013. The next day, when the break-in was discovered, an inventory discovered a number of missing items, including hard drives containing account information.
Vudu says that the drives themselves contained names, email addresses, postal addresses, phone numbers, account activity, dates of birth and the last four digits of some credit card numbers. Complete credit card details are not maintained by the company, but they are playing it safe with regards to the other data and have reset everyone’s password.
“While the stolen hard drives included VUDU account passwords, those passwords were encrypted. We believe it would be difficult to break the password encryption, but we can’t rule out that possibility given the circumstances of this theft. Therefore, we have reset all customer passwords,” Vudu said in a statement.
“It is possible that you could get spam email, emails asking for personal information, or emails asking you to click on links to other websites. As always, you should never provide personal or account information in response to a call or email claiming to be VUDU (or anyone else) and you should avoid clicking on links in emails you were not expecting.”
In addition to the warnings, password resets, and strengthened password requirements, customers will be notified of the breach by email, and given additional instructions as to how they can enroll in a free credit monitoring service.
Not everyone qualifies for this, only those with passwords on the service will be eligible.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Critical WooCommerce Payments Vulnerability Leads to Site Takeover
- PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw
- CISA Gets Proactive With New Pre-Ransomware Alerts
- Watch on Demand: Supply Chain & Third-Party Risk Summit Sessions
- TikTok CEO Grilled by Skeptical Lawmakers on Safety, Content
- CISA, NSA Issue Guidance for IAM Administrators
- Analysis: SEC Cybersecurity Proposals and Biden’s National Cybersecurity Strategy
- Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform
