Bulkreef supply hacked credit cards compromised

Well just like Kracocorals, I use something other than my normal credit cards for reef related purposes.

In fact, I have one card just for reef tank related purchases. So for anything other than reef items this card is not used. And I am glad I do it this way because about a 3 -4 weeks ago I got a call from the fraud services department asking about some questionable changers on this card. From what I could tell it looked as if someone was trying to use the information to purchase video games. Although needless to say, I had denied the charges and had them stop all transactions on the card and issue me a new one. Thankfully the were insightful enough to not let the charges go through. So I did not lose anything form it besides my time on the phone with them and wonder how they got this information, since this card is has always been in my possession and used for only one purpose, reef related purchases.

Well yesterday after seeing a post about this from a friend on Facebook, I think I have identify how and where my CC information was taken from, BRS. I still have not gotten a letter and would be surprised if I don't because this was the only place this card was use over the past 6 months.

I am actually quite bothered in how BRS is handling this. The manner in which they are disclosing is what really gets me. To me, it seems like they are trying to purposefully keep low key. I get they are offering the credit monitoring services, but that is the least they could do to keep form causing problems with their customer base. Unfortunately, the manner in which they have disclosed the information is going to create more issues than their would have been if they would have just been forthcoming with the information.

I have never had an issue with their customers service in pertaining to purchases or order resolutions, but this situation reflects some bad light form them or at least their core business practices. I also feel that how it was disclosed and the they are handling communications around it speaks volumes about the integrity of the management and quite possibly the ethics of their core business practices. This make me reconsider future business transactions with them.

Rob
 
Gosh people love complaining :roll:

I got BRSs letter in the mail today. I will not lie, I was not happy, but stuff happens man, it is just part of life. I don't think it is fair to blame BRS for being attacked. Hackers have way more power than they know what to do with.

I do agree with everyone on paypal being the "safest" checkout method.

Life will go on though.
 
Just seen this about BRS now.I had my CC hacked back in December after using BRS.My bank called and ask if i had bought airline tickets on Noraweigen Air and they stoped payment on the card.I did call BRS about this and told them what happen and they said they would pass along the info.So far for me no letter in mail.I would thought they would get a hold of people that already HAD problems.Not happy at all.
 
This is what I was afraid of is stories like this. I'm afraid this is more pr related than what they led me to believe they need to just email anyone that made purchases during that period to be safe. That's my complaint with there handling of the situation for every person that gets a letter there may be another that doesn't send out emails brs make this a big deal because for those effected it is. I know brs will take care of everyone but some may not even know there at risk and even brs may not yet know the extent of how many people s info were taken. Letting everyone know that there's a chance and to check into it is the right thing to do. Everyone that made purchases through brs in the time period should be offered credit monitoring services seems like there's still some people effected not getting letters and that's a shame
 
Oh crap honey! Looks likes someone hacked my card and purchased an Apex gold using my card! Ugggg!
What ......that new electronicky stuff in my cabinet??? That's not new... I have always had that that! Lol
Sorry.... Just trying to lighten things up :/
 
Oh crap honey! Looks likes someone hacked my card and purchased an Apex gold using my card! Ugggg!
What ......that new electronicky stuff in my cabinet??? That's not new... I have always had that that! Lol
Sorry.... Just trying to lighten things up :/

Lol that is pretty funny but it's still a serious matter for those people that have people trying to purchase 1500-2000$ plane tickets and other things. Thank god some credit card companies are doing there jobs but if they miss something then it's a ***** to get it fixed sometimes. Life will go on and we all will reef on I just hope everyone effected by this finds out and unfortunately a few already haven't and there may be more so tell fellow reefers and have them call brs get the word out there and look out for your fellow reefer
 
Back in the late 90's someone stole my sisters cell phone information ( just while she was driving around New York, they could grab stuff like that through the air back then. Anyway one day a special carrier brought her two phone book size cell phone bills for around 24k. There were telephone calls from all over the world on that bill. It still took a week or so to convince the phone company it was impossible to make a phone call in Alaska one minute, then in Miami the next.
 
Gosh people love complaining :roll:

I got BRSs letter in the mail today. I will not lie, I was not happy, but stuff happens man, it is just part of life. I don't think it is fair to blame BRS for being attacked. Hackers have way more power than they know what to do with.

I do agree with everyone on paypal being the "safest" checkout method.

Life will go on though.

No doubt, but I think the criticism is in the amount of time they took to contact the affected patrons. They even admitted that they were first attacked on January 21st and secured it the next day. So they have known for almost a month to the day. I doubt it would have been too difficult to blanket email everyone one in their email list the day of. Heck I get atleast 1 email a week from them about sales.

I'm with the critics on this one. I hope they learn from this, because I'm certainly going to continue to use BRS in the future, although I try to use Paypal whenever possible. The pre-paid Visa is a great idea to though.
 
A friend had this happen over the holidays with three different cards and three different reef vendors. It happens. And for the record it is this sort of reporting (customer based) that brought HD, Target, Sony, Chase and many more into the lime light. Not the companies forth coming attitude of transparency. Not saying it is right, just a fact that NO retailer wants to tell their customers "we weren't as secure as we thought" and remember one of those listed lied about the extent of numbers compromise and for how long it went unnoticed. Sad reality, but it's the cyber world we live in.
 
My gawd guy (lonely reef) please do a little research and objectively place blame where it's deserved and understand BRS position here.

First and foremost credit card companies have to take care of this sort of thing. Thus is there agreement with consumer for which we pay fee's and interest. That same agreement is with all merchants regulated through multiple governing bodies, else no business would honor our plastic in fear of being stuck with the fraud.... Business like consumers also pay heavy fee's for the service.

Understanding BRS position is truly understanding what it is to be "stuck between a rock and a hard place". For no matter what they do they've lost, there just is no good solution but further bad. From a large business management officers perspective (my own) I'm sure for the last few months their attorneys and business partners, Board or what have you have been locked down in damage control. First order of business is emergency management, containment and clean up.
 
My gawd guy (lonely reef) please do a little research and objectively place blame where it's deserved and understand BRS position here.

First and foremost credit card companies have to take care of this sort of thing. Thus is there agreement with consumer for which we pay fee's and interest. That same agreement is with all merchants regulated through multiple governing bodies, else no business would honor our plastic in fear of being stuck with the fraud.... Business like consumers also pay heavy fee's for the service.

Understanding BRS position is truly understanding what it is to be "stuck between a rock and a hard place". For no matter what they do they've lost, there just is no good solution but further bad. From a large business management officers perspective (my own) I'm sure for the last few months their attorneys and business partners, Board or what have you have been locked down in damage control. First order of business is emergency management, containment and clean up.

I have repeatedly said I understand there position and I think they will take care of everything. I just want to make sure the word gets to everyone out there about the breach there's already been several people that have posted here saying they received no letter and have already confirmed they were hacked so how many others are there? Surely you are not criticizing someone for looking out for a fellow reefers trying to alert them to the problem why would anyone do that. Brs first and foremost is a buisness they look over there own interests first they'd be stupid not to but like an above poster has already stated a blanket email like we all get once a week to inform people there info may have been taken could be done in a day I just don't understand that. I don't really care what anyone thinks of me I'm not bashing brs they are a great company I will still say that and I'm sure if anyone gets charges or problems from this they will take care of it. Also surely there systems will be updated and secure. I'd also venture that other reefing companies will take notice and better securethere sites better.

Secondly although I'm sure brs thought they had great online security as do most companies that are hacked they obviously didn't. If it's not there fault for not having adequate security who's fault is it. Yours? The credit card is responsible for another company getting hacked? That sounds ridiculous.

Let's be realistic there a great company that had an unfortunate hack take place now there on damage control and trying to clean this up and keep it quiet a blanket email may shake consumer confidence in there company and they will lose sales surely as a buisness manager you considered this. The credit card company doesn't catch every bad sale it's the consumers job to alert them of fraud usually unless they notice a very awkward charge. It's happend to me.

Brs is a great company ran by good men but it's still a business and businesses look after themselves first it's the way of the world. They have to limbo between saving face not losing business and taking care of consumers effected. A very hard thing no doubt.

My whole goal is to try to alert fellow reefers they may have been subjected to problems because it is quite obvious just based on the few posts here that there have been people that haven't received letters or been alerted about this yet and have already been hacked and had problems. A blanket email like they are able to do every week for sales could alert thousands instantly they obviously won't do that so its reefers job to share this info and let each other no to be on alert and contact brs and find out if you were effected.

So for everyone saying don't bash brs I'm not there a good company but they are doing what's best for them not for us there a buisness first. If they were doing what's best for us there would be a blanket email and a banner on there homepage saying please check your cards and change your passwords on the site. Anyone that disagrees with this I really can't understand why you wouldn't want to alert all your friends and fellow reefers as soon as possible to a potential problem. I love this community and have never met a bad reefer or another person in the hobby I didn't like so when I have the chance to possible alert others to a problem after all the help I've received I'm doin it.
 
I don't think BRS security was lacking because most companies that experience this don't lack in that area. What happens is some social engineering, and an employee lets the intruder in through an infected email attachment, etc.
 
I don't think BRS security was lacking because most companies that experience this don't lack in that area. What happens is some social engineering, and an employee lets the intruder in through an infected email attachment, etc.

I agree with you its total bs brs is a good company
 
Also forgot to mention I did receive my letter from brs today so they are sending them out to everyone. I would have preferred a quicker way to respond after talking with someone from my local reef society who is heavily envolved with this type of problem without explaining it has assured me they did a good job finding it quickly and coming up with a plan. He also said there pr could use a little work I guess that's the disconnect for me. I realize I've been the most disgruntled but I'm placing another order with them soon. I just think the way this was acknowledged could have been handled much much better. But kudos to them for finding the problem so quickly and addressing it. Brs isn't going anywhere and will be safer than ever I'm guessing from this point forward
 
Yep, the credit card hacking game is actually pretty easy for semi-sophisticated hackers now, low risk and big payoffs. Credit cards are inherently flawed due to being a "pull" transaction method. I can't wait for the broader public to move to more secure payment methods that are "push" based like Bitcoin.
 
Thanks LONELYREEF for this thread! I would have NEVER known about this had I not run into this thread. I'm on BRS regularly and have to say I didn't even see that small Security Update link and even if I had seen it, I probably wouldn't have clicked on it cause it seems like it was some type of software update or something. I know things like this happen online, but geez, at least let your customers know about it by mass email or something. I know hackers will hack and BRS probably had good security protocols, but when it comes to having peoples info hacked, time is critical. I shop regularly at BRS, and just last month my cc company sent me new cards cause they said my cc could have been compromised recently. I haven't received a letter and don't know if it was actually BRS, but man, at least let me know so that I could've scrutinized my cc charges more closely.
 
My account was hacked and I got the letter yesterday. I monitor my credit anyway so I am not worried. This has unfortunately become commonplace in our world and is one of the accepted perils of shopping online. BRS did not ask to be hacked and all computer systems are setup by man so it wont be perfect. Is their method of disclosing the breach suspect to criticism?...sure, there can always be more to do. Bottom line...if you shop online you run the risk of being involved in a breach. It is not up to anyone else to provide 100% of your security. Online retailers can only do so much to prevent a breach. Take the necessary precautions to protect yourself and you can mitigate any damage that might befall you. Change your passwords periodically and monitor your credit. This can be done for free at annualcreditreport.com. No spam, no junk mail, no autosubscriptions. Take responsibility for your own security. This sure stinks but it will be made right per the letter I received.
 
Last edited:

IF YOU HAD TO TAKE A REEFING EXAM, WOULD YOU PASS?

  • Yes!

    Votes: 32 45.7%
  • Not yet, but I have one that I want to buy in mind!

    Votes: 9 12.9%
  • No.

    Votes: 26 37.1%
  • Other (please explain).

    Votes: 3 4.3%
Back
Top