Simple clear advice in plain English

Lush website open to hackers for four months

Cosmetics retailer narrowly misses huge fine from ICO

lipstick-jpg
Details of customers of online cosmetic retailer available to hackers for four months


Cosmetics retailer Lush has narrowly escaped a hefty fine from the Information Commissioner after its website was hacked and customer account and credit card details stolen

The breach of the Data Protection Act and Lush's failure to process card details in accordance with the Payment Card Industry Data Security Standard mean 95 customers became victims of card fraud.

However in order to issue a fine the Information Commissioner's Office (ICO) must be satisfied that certain principles have been breached. Although an extremely serious case, Lush managed to evade a fine because it had taken some action

"A monetary penalty was not issued to Lush because we could not show that they ‘failed to take reasonable steps to prevent the contravention," the ICO told us.

The cosmetic company's website was compromised for four months between October 2010 and January 2011. Hackers were able to access the payment details of 5,000 customers who had previously shopped on the company's website. The company only discovered the breach after customers complained that their credit card details had been used fraudulently.

The ICO's investigation found that, although the company had measures in place to keep customers' payment details secure, they were not sufficient to prevent a determined attack on their website.

It said that Lush's methods of recording suspicious activity on their website were also insufficient, which delayed the time it took them to identify the security breach.

ICO Acting Head of Enforcement Sally Anne Poole said:

"Lush took some steps to protect their customers' data but failed to do regular security checks and did not fully meet industry standards relating to card payment security. Had they done this, it may have prevented the fraud taking place and could have saved the victims a great deal of worry and time invested in claiming their money back.

She went on to say that retailers had to recognise the value of the information they hold and realise that "their websites are a potential target for criminals."

Lush has now signed an undertaking to take the necessary security steps. It must also ensure that it only stores the minimum amount of payment data necessary to receive payments. In addition all future payments will also be managed by an external provider compliant with the Payment Card Industry Data Security Standard

 

 

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Child Exploitation and Online Protection Centre logo

CEOP fixes security flaw found in its online reporting form

Online form used to report suspicious activity was not encrypted, but the Information Commissioner's Office says people's personal details are now secure

Lexar Echo MX

Lewisham and Wandle tenants' personal details left in a pub

Information Commissioner's Office warns Lewisham Homes and Wandle Housing Association to encrypt records kept on portable storage devices

police

ICO reprimands Lancashire Police Authority over data breach

Police authority published private details of an individual's complaint online

Question & Answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Q.Can I open my old genealogy files or have they gone...

> Read the answer

Q.Why are odd patterns appearing on my monitors shortly...

> Read the answer

Best deals on the web

img

Samsung RV520-A07

£356.50- Buy it now

img

Acer Aspire 5750G (LX.RXP02.019)

£399.99- Buy it now

img

Apple MacBook Pro (MD313B/A)

£904.37- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

VGA

Video Graphics Array. Standard socket for connecting a monitor to a computer.

Great shopping deals from Computeractive