Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


venomio

178 posts

Master Geek
+1 received by user: 33


#289790 29-Sep-2021 13:10
Send private message

Hey all,

 

Just got this email from Aquila Technology (tech supplier based in Wellington):

 

 

We value your business and respect the privacy of your information, which is why as a precautionary measure, we are writing to let you know about a data security incident that may involve your personal information.

 

We recently became aware of a security breach to our website and have been working with a cyber security expert to determine the cause and extent. The data accessed may have included personal information such as personal or credit card information.

 

Aquila Technology values your privacy and deeply regrets that this incident has occurred. We have already taken steps to implement additional security measures designed to prevent a recurrence of such an attack, and to protect the privacy of our valued customers.

 

We are also working closely with our bank and credit card issuers and have notified the Privacy Commissioner to ensure the incident is properly addressed. If by chance your card information has been compromised by this breach, then your bank will be in touch with you directly.

 

As a precaution, we recommend resetting your Aquilatech password using the Forgot Password feature on our website. And doing the same on any other website on which you suspect that you have used the same password.

 

If you are not already in the habit of using a Password Manager you can find out about why you should be using one from this link:  Keep your data safe with a password manager

 

For further information or assistance please contact us during regular business hours or simply reply with your query, and we will respond to you asap.

 

 

Looks like they're doing what they can as soon as they can (and notifying the Privacy Commissioner) for a small two-people run team, but just an FYI to any past/current customers that may be affected.


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
Dynamic
4016 posts

Uber Geek
+1 received by user: 1853

ID Verified
Trusted
Lifetime subscriber

  #2787471 1-Oct-2021 07:56
Send private message

Their name rang only vague bells for me, and a search of my email reveals I last bought from them in 2009.  It was a battery for my Palm Treo 500.  Hopefully they have updated their web site since then and my old login details are no longer valid.

 

Aaaaaaaand a look at the web site suggests it may be the same one from 2009!  Password reset done.





“Don't believe anything you read on the net. Except this. Well, including this, I suppose.” Douglas Adams




Linux
12191 posts

Uber Geek
+1 received by user: 8480

Trusted
Lifetime subscriber

  #2787473 1-Oct-2021 08:06
Send private message

@Dynamic That is one ugly site


mentalinc
3385 posts

Uber Geek
+1 received by user: 1025

Trusted

  #2787475 1-Oct-2021 08:12
Send private message

Interesting I didn't get the email until the following day.




CPU: AMD 5900x | RAM: GSKILL Trident Z Neo RGB F4-3600C16D-32GTZNC-32-GB | MB:  Asus X570-E | GFX: EVGA FTW3 Ultra RTX 3080Ti| Monitor: LG 27GL850-B 2560x1440

 

Quic: https://account.quic.nz/refer/473833 R473833EQKIBX 




corksta
2405 posts

Uber Geek
+1 received by user: 382

Trusted
Subscriber

  #2787498 1-Oct-2021 08:40
Send private message

I got the email last night after buying two monitors from them last year. Luckily I used a randomly generated password and didn't save any credit card details; its since expired anyway.

 

The email I got was a longer version than the OP's. It says the 'additional security measures' they've taken is to 'obfuscate all credit card information and hashing all passwords'. I don't know anything about IT security, but are they not basic protocols that any decent website should have in the first place? 





2024 Mac mini M4 | 2025 iPad Air 13" M3 (Blue) | 2025 iPad Air 11" M3 (Starlight) | iPhone 15 Pro Max (Natural Titanium) | HomePod (Space Grey) | 10x HomePod mini (Space Grey, White, Yellow, Blue, Orange) | 4x Apple TV 4K | Apple Watch Ultra 2


Zeon
3926 posts

Uber Geek
+1 received by user: 759

Trusted

  #2787505 1-Oct-2021 09:13
Send private message

Reset password suggestion? Surely they are hashing before saving?

 

Goes to show never use the same password on different sites. Get a password manager people!





Speedtest 2019-10-14


sbiddle
30853 posts

Uber Geek
+1 received by user: 9996

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #2787508 1-Oct-2021 09:18
Send private message

I got the email too, having ordered something probably 10 years ago.

 

Storing credit card numbers unsecured is a huge no no, and they may face some serious repercussions from their bank over this for their lack of compliance with merchant rules. Now saying they'll take credit numbers over the phone as a temporary measure is IMHO not much better. I won't give my card number to anybody over the phone.

 

 

 

 

 

 


 
 
 

Shop on-line at New World now for your groceries (affiliate link).
dolsen
1483 posts

Uber Geek
+1 received by user: 319

Trusted
Lifetime subscriber

  #2787540 1-Oct-2021 11:03
Send private message

I brought something from them in April and received this email yesterday. Interestingly, I have just had to replace my credit card due to authorizations that were not valid (JCPENNY.COM PLANTO US on the 20/9 for $0). 

 

The only new place I have used my card was at jlcpcb, however, it looks like it could have been this instead.

 

 

 

 


Benjip
978 posts

Ultimate Geek
+1 received by user: 524

ID Verified

  #2787542 1-Oct-2021 11:04
Send private message

I too received the email – a quick search of my inbox shows I ordered a case for an iPod mini in 2005!

 

What a hoot.


littlehead
222 posts

Master Geek
+1 received by user: 102


  #2787568 1-Oct-2021 11:54
Send private message

Received this email also. This was more interesting to me as I bought a monitor from them in June last year and then two weeks later the credit card I used with them was used for fraudulent Play Store transactions and had to be cancelled/replaced. There wasn't any other non-regular places I had bought from recently. Bank couldn't say for sure where they had got the card details from, they could of been compromised for a while and waited until then, but I always thought it a bit suspicious with the timing.

 

The credit card form on their website was not a regular payment gateway. I would guess that it either emailed them the details or stored manually in some other method and they processed it manually.

 

 

 

 


dfnt
1553 posts

Uber Geek
+1 received by user: 1036

Trusted
Lifetime subscriber

  #2787569 1-Oct-2021 11:57
Send private message

Linux:

 

@Dynamic That is one ugly site

 

 

Agreed, that's why I never purchased anything from them as it's horrible


SirHumphreyAppleby
2943 posts

Uber Geek
+1 received by user: 1863


  #2787640 1-Oct-2021 12:55
Send private message

dfnt:

 

Linux:

 

@Dynamic That is one ugly site

 

 

Agreed, that's why I never purchased anything from them as it's horrible

 

 

I like their Website. Easy to use, basic layout, with all the info I need.

 

I've purchased from them in the past and Mike is really helpful.


 
 
 

Want to support Geekzone and browse the site without the ads? Subscribe to Geekzone now (monthly, annual and lifetime options).
boosacnoodle
1287 posts

Uber Geek
+1 received by user: 867


  #2787653 1-Oct-2021 13:36
Send private message

littlehead:

 

The credit card form on their website was not a regular payment gateway. I would guess that it either emailed them the details or stored manually in some other method and they processed it manually.

 

 

Yikes! That is concerning and lines up with the suggestions earlier in the thread that they are processing cards over the phone.


richms
29107 posts

Uber Geek
+1 received by user: 10223

Trusted
Lifetime subscriber

  #2787656 1-Oct-2021 13:54
Send private message

Phone processing is ok if theyre entering it straight into the gateway or doing it on the terminal but sooooo many places write it down including the 3 digit number.





Richard rich.ms

Handle9
11927 posts

Uber Geek
+1 received by user: 9683

Trusted
Lifetime subscriber

  #2787727 1-Oct-2021 15:43
Send private message

Benjip:

I too received the email – a quick search of my inbox shows I ordered a case for an iPod mini in 2005!


What a hoot.



Seems a little unlikely. iPad mini was released in 2012.

mattwnz
20520 posts

Uber Geek
+1 received by user: 4798


  #2787729 1-Oct-2021 15:44
Send private message

Handle9:
Benjip:

 

I too received the email – a quick search of my inbox shows I ordered a case for an iPod mini in 2005!

 

 

 

What a hoot.

 



Seems a little unlikely. iPad mini was released in 2012.

 

 

 

iPod mini


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.