• MSN
  • Hotmail
  • More
    • Autos
    • My MSN
    • Video
    • Careers & Jobs
    • Personals
    • Weather
    • Delish
    • Quotes
    • White Pages
    • Games
    • Real Estate
    • Wonderwall
    • Horoscopes
    • Shopping
    • Yellow Pages
    • Local Edition
    • Traffic
    • Feedback
    • Maps & Directions
    • Travel
    • Full MSN Index
  • Bing
  • NBCNews.com
  • TODAY
  • Nightly News
  • Rock Center
  • Meet the Press
  • Dateline
  • msnbc
  • Breaking News
  • Newsvine
  • Home
  • US
  • World
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Tech
  • Science
  • Travel
  • Local
  • Weather
Advertise | AdChoices
  • Recommended: Students can't resist distraction for two minutes ... and neither can you
  • Recommended: Surprise! Prepaid debit cards actually a good deal for consumers
  • Recommended: 'Ransomware' tricks victims into paying hefty fines
  • Recommended: Fake tweet shows country 'sensitive to any news that sounds like terrorism'

Corporate sneakiness. Government waste. Technology run amok. Outright scams. Our effort to unmask these 21st Century headaches and offer solutions that save you time and money.

  • ↓ About this blog
  • ↓ Archives
    • Icons Email E-mail updates
    • Icons Twitter Follow on Twitter
    • Icons Feed Subscribe to RSS
  • 16
    Jan
    2012
    12:29am, EST

    Zappos says hacker may have accessed info on 24 million customers

    By Bob Sullivan, Columnist, NBC News

    Online retailer Zappos.com is telling 24 million customers that their personal information has been hacked, and forcing all of them to reset their passwords.  Cyber criminals may have accessed customers' names, e-mail addresses, billing and shipping addresses, phone number, and the last four digits of consumers' credit card numbers, the firm said in an announcement that was posted on Zappos' Web site late Sunday night.  Full credit card numbers were not stolen, the firm said, because they were stored separately.

    The announcement included the text of an e-mail that Zappos customers will soon receive.

    "We were recently the victim of a cyber attack by a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky. We are cooperating with law enforcement to undergo an exhaustive investigation," says the e-mail,  which is signed by Tony Hsieh, Zappos CEO. "For your protection and to prevent unauthorized access, we have expired and reset your password so you can create a new password. Please follow the instructions below to create a new password.  We also recommend that you change your password on any other web site where you use the same or a similar password."

    While passwords that may have been stolen were cryptographically scrambled, Zappos said, it is still requiring all consumers to change their passwords. Zappos also recommends that consumers who use their Zappos password on other sites — a common, if unsafe, practice — should change those passwords, too.

    Zappos has set up a special Web page for customers to visit and change the password: http://www.zappos.com/passwordchange.

    Follow @RedTapeChron

    Anticipating a flood of customer service calls in response to the notification e-mail, Zappos is taking the unusual step of turning off its customer service telephone lines and forcing consumers with questions to send them in via e-mail.

    "Due to the volume of inquiries we are expecting, we realized that we could serve the most customers by answering their questions by email," Hsieh said in a note to employees, also posted on the firm's Web page. "We have made the hard decision to temporarily turn off our phones and direct customers to contact us by email because our phone systems simply aren't capable of handling so much volume. (If 5% of our customers call, that would be over 1 million phone calls, most of which would not even make it into our phone system in the first place.) "

    Hsieh said the firm would have "all hands on deck," to help customers with questions.

    Judged by the number of customers impacted, Zappos' data breach is among the biggest thefts of customer information ever, but still considerably smaller than last year's incident involving the Sony Play Station Network, which reportedly impacted 77 million customers.

    Hsieh struck an apologetic tone in both the e-mail to consumers and the memo to staff.

    "We've spent over 12 years building our reputation, brand, and trust with our customers. It's painful to see us take so many steps back due to a single incident," he said in the memo. "I suppose the one saving grace is that the database that stores our customers' critical credit card and other payment data was not affected or accessed."  

     Don't miss the next Red Tape:
    *Get Red Tape headlines on your Facebook Wall
    *Follow Bob on Twitter. 
    *Get an e-mail newsletter with Red Tape stories (requires Newsvine registration).

    Comment

    Show more
    Explore related topics: featured, hacks, data-breach, zappos

Browse

  • featured,
  • credit,
  • privacy,
  • bob-sullivan,
  • red-tape,
  • consumer,
  • security,
  • fees,
  • lending,
  • computer,
  • facebook,
  • rights,
  • cards,
  • and,
  • hackers,
  • redtaperoadtrip2011,
  • sneaky,
  • internet,
  • identity-theft,
  • how,
  • to,
  • online,
  • save,
  • on,
  • money,
  • twitter,
  • ftc,
  • banks,
  • identity,
  • ads,
  • redtaperoadtrip2010,
  • scams,
  • technology,
  • social-media,
  • google,
  • cell-phones,
  • theft,
  • in,
  • truth,
  • consumers,
  • virus,
  • hack,
  • cramming,
  • government,
  • airlines,
  • web,
  • police,
  • id-theft,
  • bank
Also
Advertise | AdChoices

Bob Sullivan, Columnist, NBC News

I'm a reporter for msnbc.com and I try to write stories that make the world a little bit more fair. My blog, The Red Tape Chronicles, is among the most popular consumer affairs columns on the Web. My recent book, Gotcha Capitalism, was a New York Times best seller. Since 1995, I've written about the troubles created for consumers by both technology, covering topics like privacy, identity theft, computer viruses and hackers.

Bob Sullivan, Columnist, NBC News Blogroll

  • Consumerist
  • Life Inc - The economy and you

Archives

  • 2013
    • May (4)
    • April (7)
    • March (9)
    • February (8)
    • January (11)
  • 2012
    • December (7)
    • November (6)
    • October (7)
    • September (7)
    • August (8)
    • July (6)
    • June (12)
    • May (10)
    • April (7)
    • March (10)
    • February (13)
    • January (14)
  • 2011
    • December (4)
    • November (12)
    • October (12)
    • September (9)
    • August (8)
    • July (6)
    • June (18)
    • May (10)
    • April (20)
    • March (14)
    • February (7)
    • January (8)
  • 2010
    • December (6)
    • November (9)
    • October (4)
    • September (7)
    • August (7)
    • July (6)
    • June (9)
    • May (8)
    • April (9)
    • March (8)
    • February (9)
    • January (9)
  • 2009
    • December (10)
    • November (5)
    • October (8)
    • September (7)
    • August (5)
    • July (8)
    • June (7)
    • May (8)
    • April (7)
    • March (7)
    • February (8)
    • January (6)
  • 2008
    • December (4)
    • November (3)
    • October (8)
    • September (5)
    • August (8)
    • July (9)
    • June (3)
    • May (6)
    • April (9)
    • March (8)
    • February (7)
    • January (8)
  • 2007
    • December (7)
    • November (10)
    • October (8)
    • September (7)
    • August (6)
    • July (8)
    • June (12)
    • May (7)
    • April (2)
    • March (8)
    • February (6)
    • January (7)
  • 2006
    • December (6)
    • November (9)
    • October (2)
    • September (5)
    • August (11)
    • July (7)
    • June (10)
    • May (5)
    • April (7)
    • March (8)
    • February (8)
    • January (8)
  • 2005
    • December (10)
    • November (8)
    • October (6)

Recent Posts

  • How the smartphone killed the three-day weekend
  • Storm after the storm: Consumers warned about fake Oklahoma charities (17)
  • Students can't resist distraction for two minutes ... and neither can you
  • Surprise! Prepaid debit cards actually a good deal for consumers
  • LivingSocial database hacked; 50 million customers impacted
  • 'Ransomware' tricks victims into paying hefty fines
  • Fake tweet shows country 'sensitive to any news that sounds like terrorism'
  • Use your personal smartphone for work email? Your company might take it

Other blogs

  • The Body Odd
  • Cosmic Log
  • PhotoBlog
  • US News
  • Open Channel

NBCNews.com top stories

3147,10
© 2013 NBCNews.com
  • Security on NBCNews.com
  • About us
  • Contact
  • Help
  • Site map
  • Careers
  • Closed captioning
  • Terms & Conditions
  • Privacy policy
  • Advertise