Monoprice security breach?

Once Bit Your Sister
Donator
Puce Moose's picture
Location: Waiting for you in heaven... with a gun.

I was planning to order an HDMI cable today and I noticed this on monoprice:

http://www.monoprice.com/home/view_notice.asp

It looks like the site was down for a few days, and they're still not accepting credit card payments. It looks like you can use Google checkout/PayPal.

they charge per letter
pol's picture
Location: Charlottesville, VA

I may be going to hell in a bucket, but at least I'm enjoyin' the ride

King of Ping
Donator V7.0
Lester_King's picture
Location: Souf Cakilac

I bought a mount and a few cables from them right before this happened. Like, 3 days before.

I haven't had any fraudulent charges or any strange activity. I think it's just a scare that Monoprice is handling very appropriately.

Off With My Head!
Donator V5.0
LiquidMantis's picture
Location: Rocky Mtn. Foothills

It was back in December, but I had to close my old debit card because I had a $1.10 iTunes feeler charge (I don't even use iTunes). Turned out that was a common test charge to see if a card was valid before going nuts. Luckily I caught it while it still showed up as pending. I've got no basis for blaming Monoprice given the amount of online purchasing I do, but I did make a Monoprice order in December too. That's a while back though. Regardless I won't hesitate to use Monoprice in the future.

Xbox | PSN: LiquidmantisGWJ
Web
--
Fond memories of a flexible Grandma ensue. - m0nk3yboy

Claw Shrimp
Donator V6.0
LobsterMobster's picture
Location: On a picnic, going "La la la!"

I bought a new bare hard drive that didn't come with a SATA cable so I ordered one through Monoprice this morning using PayPal. Charge still hasn't gone through. I guess they're being very busy or very cautious.

NOTE: Not a doodle bug.

Steam-XBox-PSN: Lobstermancer

Junior Executive
Donator V2.0
DF7's picture
Location: Boulder

PayPal should keep you safe from what I understand: PayPal never gives the card info to the vendor, you just authorize a one time payment to the vendor, which is routed through PayPal. At least that is what I think happens, can anyone confirm this?

Cabbot Patch Kid
Donator V4.0
Thin_J's picture
Location: Riding my invisible bike.

LiquidMantis wrote:
Regardless I won't hesitate to use Monoprice in the future.

If anything their handling of this has only made me like them more.

XBLive: Thin J | PSN: Thin_J | Battle.net: ThinJ.284
You know stuff. - MannishBoy

Pimpin' Ain't Eezy
Donator V8.0
Eezy_Bordone's picture
Location: Western Washington

If it's any consolation, my PP payments never go through on the same day.

Do you ever walk alone like a drifter in the dark?
---------------------------------------------------------------
Steam: Bordone

Discretion is not the better part of
Donator V7.0
Malor's picture
Location: Perpetually suspended

Thin_J wrote:
LiquidMantis wrote:
Regardless I won't hesitate to use Monoprice in the future.

If anything their handling of this has only made me like them more.

Yeah, exactly, they're obviously a class outfit.

They really shouldn't have stored CC info locally; that was a bad move on their part. It sounds like, from the lengthy downtime, that they're re-engineering their solution to work properly.

Elewis17 wrote:

I endorse any suggestion by Malor to put computer components in kitchen appliances.

Executive
Donator V2.0
misterglass's picture
Location: Los Angeles

Good for them! Even the one time I had a question, the person that answered it was very nice and very competent. I'm glad that seems to apply to the whole company.

When my son was born and I saw his beautiful face, I was so happy that it wasn't made with Bioware's character creator.

Executive
Donator V5.0
KillTrash's picture
Location: Miami, FL

This is weird, but I purchased from Monoprice last month and today I noticed I had a charge for $775 on my CC, for a 42" Panasonic plasma on a website called justbuyelectronics.com. The TV was to be delivered in Louisiana and I live in FL!

I suspect that this person got my CC number and billing address info from this Monoprice security breach? I don't know, because I only use this card to pay for my utilities and just this once I used it to buy a set of cables and speaker stands at Monoprice, since I just moved in to this apartment last month and apparently, the person that bought that TV under my name had my current billing address.

What a headache! Spent the whole morning calling the bank, that website, canceling my CC, working on a dispute. Sigh...

XBL/PSN/Steam Gamertag: KillTrash
BF3 Soldier: KillTrsh

Consultant
datawang's picture
Location: Setting booby traps.

I'm afraid I might be in the same boat. I bought a cable 3 weeks or so ago. Last night my card was frozen due to suscpicious activity. The store was ACCCA for $314.42. I have no idea what that is - ACCCA stands for various organizations on Google.

Had to cancel the card, in the process of notifying everyone today.

PSN: datawang | Steam: datawang | SWTOR: Waldron
"We know who Troy is. He's that cheap guy."

Throat Specialist
Donator
Dr.Ghastly's picture

Ouch, that sucks guys.

Unfortunately, if I slash my wrist with my lightsaber it cauterizes instantly. - PurEvil on emo Star Wars plots.
I don't always run Windows, but when I do, I use MSE. (Stay uninfected, my friends) - *Legion*, TMILUITW

Off With My Head!
Donator V5.0
LiquidMantis's picture
Location: Rocky Mtn. Foothills

It's awesome that HDMI cables grow on plants.

Xbox | PSN: LiquidmantisGWJ
Web
--
Fond memories of a flexible Grandma ensue. - m0nk3yboy

Calmer Than You Are
Jeff-66's picture
Location: Daytona, FL

As for me & monoprice, I think I got lucky. I usually used paypal in the past, but twice in November I used a debit card (why Jeff? why?!). Where I got lucky is that my bank changed ownership and in December the debit card I used at Monoprice was replaced by a new card, killing off the old one.

At first, Monoprice seemed to suggest that nothing much happened.

monoprice.com wrote:
To date, the investigators have found no evidence that card information has been stolen from Monoprice’s computer network. As a precaution to ensure that our customers’ information is not at risk, we have taken our website offline temporarily while we and our investigators complete the audit of our computer network.

We want to ensure that there is no security vulnerability in any part of our computer network system.

I guess that's not true. Seems a LOT of people are being hit with this.

Anyway, it looks like they are back up and running and "now accepting CC payments". Not sure I'd trust them with that at this point, in fact, I'm going to be a lot more careful how & where I use my card online.

the pot and the kettle
Donator V3.0
boogle's picture
Location: Norman, OK

Meh, I ordered something yesterday with my CC.

pretend boogle wrote:

tweed jacket + pedestrian = Parisian dandy

Discretion is not the better part of
Donator V7.0
Malor's picture
Location: Perpetually suspended

God, boogle, they take Paypal. Why on earth deliberately tempt fate?

Elewis17 wrote:

I endorse any suggestion by Malor to put computer components in kitchen appliances.

Off With My Head!
Donator V5.0
LiquidMantis's picture
Location: Rocky Mtn. Foothills

Haven't you heard the news? Boogle's trying to get screwed.

Xbox | PSN: LiquidmantisGWJ
Web
--
Fond memories of a flexible Grandma ensue. - m0nk3yboy

the pot and the kettle
Donator V3.0
boogle's picture
Location: Norman, OK

Malor wrote:
God, boogle, they take Paypal. Why on earth deliberately tempt fate?
Its from my weekly account that I only transfer in funds for my week. So maximum (excluding travel) means they could steal 100 dollars?

pretend boogle wrote:

tweed jacket + pedestrian = Parisian dandy

Calmer Than You Are
Jeff-66's picture
Location: Daytona, FL

Jeff-66 wrote:

As for me & monoprice, I think I got lucky. I usually used paypal in the past, but twice in November I used a debit card (why Jeff? why?!). Where I got lucky is that my bank changed ownership and in December the debit card I used at Monoprice was replaced by a new card, killing off the old one.

I just researched it, and I was wrong. I did use my current debit card on the monoprice purchase in November. So mine was in their system I guess. no bogus charges yet, but I'm taking no chances. I called my bank and killed that card, and ordered a new one.

Can be exchanged for goods or maulings
Donator V3.0
Tigerbill's picture
Location: Prowlin' the Wasteland

LiquidMantis wrote:
Haven't you heard the news? Boogle's trying to get screwed.

Bazinga!

Muddying the Waters
Donator V2.0
MannishBoy's picture
Location: Nashville

boogle wrote:
Malor wrote:
God, boogle, they take Paypal. Why on earth deliberately tempt fate?
Its from my weekly account that I only transfer in funds for my week. So maximum (excluding travel) means they could steal 100 dollars?

Credit card or check card?

It is possible to overdraw a checking account on a check card up until some new laws go into place next month where you have to opt in to allow it to happen. Just like they'll pay checks into NSF with the right account history.

But if you take a hit and notify your bank in a timely manner, Reg E generally will get your money back to you. You'll have a lot of time and hassle, but in the end, you're reimbursed by the bank in most cases (by law).

Also, credit cards actually have more protection than debit/check cards do.

/banker who used to manage an ATM network for a state

Andy aka:

Xbox: TheMannishBoy PSN: Skinchanger Steam: MannishBoy

the pot and the kettle
Donator V3.0
boogle's picture
Location: Norman, OK

Credit.

pretend boogle wrote:

tweed jacket + pedestrian = Parisian dandy

Executive
Donator V5.0
KillTrash's picture
Location: Miami, FL

So I got a letter from Monoprice yesterday, stating that my personal information could have been stolen, since I made my purchase from them exactly at the time frame they suspected the breach occurred. They are offering a free 12 month service for ID protection, consultation and some other benefits with some company that provides online security services. I can't remember the name of the company now, I don't have that letter with me.

My bank took care of all the charges I had on my card, canceled it and put my account on high alert for any "strange activities". I will also be monitoring my credit reports for a while just in case something weird shows up as well. What a hassle, but it's good to see that Monoprice is taking this issue seriously. Too bad my first purchase from them end up being such a mess!

XBL/PSN/Steam Gamertag: KillTrash
BF3 Soldier: KillTrsh

MMMMAGGOTS!
Donator V4.0
NSMike's picture
Location: Akron, Ohio

I would like to add that, if you don't like PayPal, Monoprice also deals with Google Checkout. It's actually my preferred method.

TempestBlayze wrote:

Mike, you're like Francis in L4D. You hate everything.

XBox Live
Steam

Off With My Head!
Donator V5.0
LiquidMantis's picture
Location: Rocky Mtn. Foothills

Got my Monoprice letter today. Guess that means it probably was the cause of my stuff back in December.

Xbox | PSN: LiquidmantisGWJ
Web
--
Fond memories of a flexible Grandma ensue. - m0nk3yboy

Calmer Than You Are
Jeff-66's picture
Location: Daytona, FL

KillTrash wrote:
So I got a letter from Monoprice yesterday, stating that my personal information could have been stolen, since I made my purchase from them exactly at the time frame they suspected the breach occurred.

What was the date range they believe the breach occurred in?

Off With My Head!
Donator V5.0
LiquidMantis's picture
Location: Rocky Mtn. Foothills

Ah, just reread the actual letter, Feb. 23 through Mar. 5. So I guess my card was compromised some other way since my thing happened back in December.

Xbox | PSN: LiquidmantisGWJ
Web
--
Fond memories of a flexible Grandma ensue. - m0nk3yboy