Bulkreef supply hacked credit cards compromised

I just got an email from Premium Aquatics saying that one of their "fellow aquarium stores" got hacked and they went on to explain their own security protocols to help protect us. Funny how Premium Aquatics didn't get hacked, but sent out a mass email letting customers know about their systems, yet BRS never even sent out a mass email to let us know when they actually got hacked.
There are only two types of companies: those that know they've been hacked, and those that don't.
 
Received a letter today from BRS on the security situation and the steps that they are taking to prevent future mishaps. It happens even to the big guys(Target, Blue Cross & Blue Shield, Home Depot, Etc) I even have to inspect the card readers at the gas pumps from tampered card inserts in my area. Looks like its gonna be an ongoing event dealing with the HACKERS.
 
Got my letter today =(

After reading it and seeing what they are offering I will keep sending a bulk of my business there.
 
I don't believe they are hiding anything. We received written notification in the mail today. Pretty explicit I would say.....
 
Got my letter and now understand where the $75 Starbucks charges were coming from. Had 3 in one day. Card company did not call I cancelled the card.
 
BRS was hacked - I was hacked. I'm over it now.

When I received a letter from BRS explaining they were hacked, and PII (Personally Identifiable Information) was stolen, I like everyone else, was upset at the news.

I wrote a long email to BRS support outlining my concerns, posing some questions, and generally giving my professional opinion of the situation. (I work in the IT industry, and frequently deploy and maintain e-commerce solutions.) My letter was not an enraged flame, but it was in no way laudatory, and I believe I fairly delineated the consequences to businesses and consumers from such an incident, my view of a business' responsibility after such an event, and equally importantly responsibility before such and event, and some suggestions for their way forward. (I shared the message with my wife, and she gave me one of those looks and said "I would not like to receive an angry letter from you." I wasn't being angry, but I get her point.)

A few hours later, I received a call from Ryan, and we had a long conversation about the situation. I respect his initiative in addressing the damage head-on and in a personal, as well as professional and expert, manner. I believed before, and I believe now, this is a small company with integrity as a core tenet. I can't reveal all I was able to glean from the conversation, but will say that they have well and truly made every practical effort to rectify the situation in the best manner available. (Know that doing so is an extremely expensive and painful proposition for them, and as a small company with whom I like doing business, I hope their balance sheet can survive the hit. As much as we as customers may have lost potentially and in fact, BRS has lost far more.)

I empathize with everyone involved in this: myself, other customers, and BRS too. I do not sympathize, however. This sort of attack, while prevalent (anyone a Target customer?), is not unpreventable. I still maintain the best time to close the barn door, is before the horses escape. To mix metaphors, that's water under the bridge now. In talking with Ryan, I am convinced they have learned this very painful lesson. Right now, I have no doubt that one of the safest places to do business on-line is the BRS web site.

"Maybe they will make a youtube video about it....."
I complained that the time it took to communicate the issue was too long. Ryan, I could tell, was as frustrated as we all on this. I agree with him there is no perfect way to communicate, and in balance they did as good as can really be expected. The above quote was written by another poster, in humor, but Ryan shared that was literally his first impulse and wanted to do so immediately. The IT experts they brought in shot the idea down in no uncertain terms, and were right to do so. Immediately after the discovery, there were not enough facts in evidence to craft a coherent message, let alone an effective action plan for the business or consumers. Until they knew the nature and reach of the intrusion and theft, what was the message to be? "We were hacked. Data was stolen." Painful, but better to wait and have a clear message, targeted at the affected parties rather than a vague, ominous broadside aimed at everyone. (If I, for one, want the latter, I'll watch Fox news.)

Nobody will disagree this was an unfortunate situation. Bad things happen to good people. Everyone victimized here, including BRS, are good people IMHO.

I will continue doing business with BRS. Their business model and delivered value is still attractive to me. I will, as will we all, come away sadder but wiser knowing more than we care to about the dark side of doing business on-line. The suggestion to use PayPal as a payment processor backed by a credit card as the payment instrument is a good one. Secure payment processing is not BRS' core competence, it is PayPal's raison e'etre, and we all should be taking advantage of that as a prudent approach to e-commerce.
 
When I received a letter from BRS explaining they were hacked, and PII (Personally Identifiable Information) was stolen, I like everyone else, was upset at the news.

I wrote a long email to BRS support outlining my concerns, posing some questions, and generally giving my professional opinion of the situation. (I work in the IT industry, and frequently deploy and maintain e-commerce solutions.) My letter was not an enraged flame, but it was in no way laudatory, and I believe I fairly delineated the consequences to businesses and consumers from such an incident, my view of a business' responsibility after such an event, and equally importantly responsibility before such and event, and some suggestions for their way forward. (I shared the message with my wife, and she gave me one of those looks and said "I would not like to receive an angry letter from you." I wasn't being angry, but I get her point.)

A few hours later, I received a call from Ryan, and we had a long conversation about the situation. I respect his initiative in addressing the damage head-on and in a personal, as well as professional and expert, manner. I believed before, and I believe now, this is a small company with integrity as a core tenet. I can't reveal all I was able to glean from the conversation, but will say that they have well and truly made every practical effort to rectify the situation in the best manner available. (Know that doing so is an extremely expensive and painful proposition for them, and as a small company with whom I like doing business, I hope their balance sheet can survive the hit. As much as we as customers may have lost potentially and in fact, BRS has lost far more.)

I empathize with everyone involved in this: myself, other customers, and BRS too. I do not sympathize, however. This sort of attack, while prevalent (anyone a Target customer?), is not unpreventable. I still maintain the best time to close the barn door, is before the horses escape. To mix metaphors, that's water under the bridge now. In talking with Ryan, I am convinced they have learned this very painful lesson. Right now, I have no doubt that one of the safest places to do business on-line is the BRS web site.

"Maybe they will make a youtube video about it....."
I complained that the time it took to communicate the issue was too long. Ryan, I could tell, was as frustrated as we all on this. I agree with him there is no perfect way to communicate, and in balance they did as good as can really be expected. The above quote was written by another poster, in humor, but Ryan shared that was literally his first impulse and wanted to do so immediately. The IT experts they brought in shot the idea down in no uncertain terms, and were right to do so. Immediately after the discovery, there were not enough facts in evidence to craft a coherent message, let alone an effective action plan for the business or consumers. Until they knew the nature and reach of the intrusion and theft, what was the message to be? "We were hacked. Data was stolen." Painful, but better to wait and have a clear message, targeted at the affected parties rather than a vague, ominous broadside aimed at everyone. (If I, for one, want the latter, I'll watch Fox news.)

Nobody will disagree this was an unfortunate situation. Bad things happen to good people. Everyone victimized here, including BRS, are good people IMHO.

I will continue doing business with BRS. Their business model and delivered value is still attractive to me. I will, as will we all, come away sadder but wiser knowing more than we care to about the dark side of doing business on-line. The suggestion to use PayPal as a payment processor backed by a credit card as the payment instrument is a good one. Secure payment processing is not BRS' core competence, it is PayPal's raison e'etre, and we all should be taking advantage of that as a prudent approach to e-commerce.
Very thoughtful and well reasoned post. I'm in agreement, especially the shot @ FOX news :-)
 
Got my snail mail explanation from BRS today about the hack. That explains the fraudulent charges on my CC a few weeks back. Glad I monitor my CC very closely.

Good opportunity to do some spring cleaning on my online passwords next....
 
When I received a letter from BRS explaining they were hacked, and PII (Personally Identifiable Information) was stolen, I like everyone else, was upset at the news.

I wrote a long email to BRS support outlining my concerns, posing some questions, and generally giving my professional opinion of the situation. (I work in the IT industry, and frequently deploy and maintain e-commerce solutions.) My letter was not an enraged flame, but it was in no way laudatory, and I believe I fairly delineated the consequences to businesses and consumers from such an incident, my view of a business' responsibility after such an event, and equally importantly responsibility before such and event, and some suggestions for their way forward. (I shared the message with my wife, and she gave me one of those looks and said "I would not like to receive an angry letter from you." I wasn't being angry, but I get her point.)

A few hours later, I received a call from Ryan, and we had a long conversation about the situation. I respect his initiative in addressing the damage head-on and in a personal, as well as professional and expert, manner. I believed before, and I believe now, this is a small company with integrity as a core tenet. I can't reveal all I was able to glean from the conversation, but will say that they have well and truly made every practical effort to rectify the situation in the best manner available. (Know that doing so is an extremely expensive and painful proposition for them, and as a small company with whom I like doing business, I hope their balance sheet can survive the hit. As much as we as customers may have lost potentially and in fact, BRS has lost far more.)

I empathize with everyone involved in this: myself, other customers, and BRS too. I do not sympathize, however. This sort of attack, while prevalent (anyone a Target customer?), is not unpreventable. I still maintain the best time to close the barn door, is before the horses escape. To mix metaphors, that's water under the bridge now. In talking with Ryan, I am convinced they have learned this very painful lesson. Right now, I have no doubt that one of the safest places to do business on-line is the BRS web site.

"Maybe they will make a youtube video about it....."
I complained that the time it took to communicate the issue was too long. Ryan, I could tell, was as frustrated as we all on this. I agree with him there is no perfect way to communicate, and in balance they did as good as can really be expected. The above quote was written by another poster, in humor, but Ryan shared that was literally his first impulse and wanted to do so immediately. The IT experts they brought in shot the idea down in no uncertain terms, and were right to do so. Immediately after the discovery, there were not enough facts in evidence to craft a coherent message, let alone an effective action plan for the business or consumers. Until they knew the nature and reach of the intrusion and theft, what was the message to be? "We were hacked. Data was stolen." Painful, but better to wait and have a clear message, targeted at the affected parties rather than a vague, ominous broadside aimed at everyone. (If I, for one, want the latter, I'll watch Fox news.)

Nobody will disagree this was an unfortunate situation. Bad things happen to good people. Everyone victimized here, including BRS, are good people IMHO.

I will continue doing business with BRS. Their business model and delivered value is still attractive to me. I will, as will we all, come away sadder but wiser knowing more than we care to about the dark side of doing business on-line. The suggestion to use PayPal as a payment processor backed by a credit card as the payment instrument is a good one. Secure payment processing is not BRS' core competence, it is PayPal's raison e'etre, and we all should be taking advantage of that as a prudent approach to e-commerce.

The only question I would have asked is "Was BRS PCI Compliant at the time of the hack"?

If they were, I am at a loss as to how any credit card information was stolen that would not have been encrypted as per the PCI spec. If they were complaint, I would love to know who the assessor was that issued the certificate of compliance....clearly they were not.
 
Everyone – first of all, thank you for your patience. We can’t tell you how sorry we are about this. It has been a difficult period for our customers and everyone here at BRS. We know you are frustrated and encourage you to call our customer service team at 763-432-9691 if you have any questions or concerns.

Was Bulk Reef Supply PCI Compliant at the time its systems were compromised in June 2014?
 
So far pretty much everyone has said their banks caught it. Has anyone's bank not caught it and has anyone actually lost any money? Other than the inconvience of getting your cards canceled it sounds like there is a pretty good system that prevents this kind of stuff.
 
I'm dumb what is PCI compliant

https://www.pcisecuritystandards.org/

The PCI Data Security Standard represents a common set of industry tools and measurements to help ensure the safe handling of sensitive information. Initially created by aligning Visa's Account Information Security (AIS)/Cardholder Information Security (CISP) programs with MasterCard's Site Data Protection (SDP) program, the standard provides an actionable framework for developing a robust account data security process - including preventing, detecting and reacting to security incidents.
 
Last edited:
I've worked in the payments processing industry for Elavon, one of the largest networks in the world. I know pci compliance back to front and please do not peg it as Some sort of fraud shield that would have made BRS impervious to a breach. I also run an online retail site and have gone through the pci compliance from the business side as well and it is not an active shield like say Norton antivirus is for a computer. It is just a display of due diligence that you have all the security measures in place per the card company and processing network guidelines. breaches happen whether your site is pci compliant or not. If the hacker wants in and they are good enough, there isn't anything in existence that will stop them. There is no 100% safeguard and certainly not from a compliance program.
 
Was Bulk Reef Supply PCI Compliant at the time its systems were compromised in June 2014?
doesn't matter. You think target wasn't pci compliant when they suffered their breach? they would need to be compliant to be processing transactions. No card processing network would let one transaction go through If they didn't pass pci compliance Which must be renewed annually.
 
Last edited:
The only question I would have asked is "Was BRS PCI Compliant at the time of the hack"?

If they were, I am at a loss as to how any credit card information was stolen that would not have been encrypted as per the PCI spec. If they were complaint, I would love to know who the assessor was that issued the certificate of compliance....clearly they were not.

the compliance is enforced by whoever their card processing network is. It's no guarantee either. do not put a lot of weight into pci compliance. Plus as I said above their card processor would not allow them to process transactions if their security measures were not pci compliant. It must be renewed annually and if not the payment processing is suspended.
 
Last edited:
the compliance is enforced by whoever their card processing network is. It's no guarantee either. do not put a lot of weight into pci compliance. Plus as I said above their card processor would not allow them to process transactions if their security measures were not pci compliant. It must be renewed annually and if not the payment processing is suspended.

Having worked for high volume e-commerce websites for over a decade, PCI compliance is the ONLY thing that matters.

Compliance is not enforced by the processing network. Compliance is mandated by the bank that you do business with. It is there so the bank knows who to go after legally to recoup lost funds and apply penalties to for non-compliance.

"they would need to be compliant to be processing transactions", not a true statement at all. Anybody can sign up to process transactions and do so the very same day. Also, If I was already a vendor selling something, and I go through an assessment and am deemed not to be in compliance the process does not cut me off right there, it makes me submit a plan to become complaint, and business continues uninterrupted.

"It must be renewed annually"-- depends on the number of transactions you process, if it is high enough you will be required to have quarterly scans. Fact is that it only proves you were complaint on that day. If the next day you remove a part of the process etc, you are not compliant anymore. The only way their processor and/or bank would know that they weren't complaint is if BRS told them they weren't complaint.

"[PCI] is just a display of due diligence that you have all the security measures in place per the card company and processing network guidelines" TRUE!, so I think my question is a valid starting point "Was Bulk Reef Supply PCI Compliant at the time its systems were compromised in June 2014" If they aren't even doing that, they don't deserve my or anyone else's business.
 
Having worked for high volume e-commerce websites for over a decade, PCI compliance is the ONLY thing that matters.

Compliance is not enforced by the processing network. Compliance is mandated by the bank that you do business with. It is there so the bank knows who to go after legally to recoup lost funds and apply penalties to for non-compliance.

"they would need to be compliant to be processing transactions", not a true statement at all. Anybody can sign up to process transactions and do so the very same day. Also, If I was already a vendor selling something, and I go through an assessment and am deemed not to be in compliance the process does not cut me off right there, it makes me submit a plan to become complaint, and business continues uninterrupted.

"It must be renewed annually"-- depends on the number of transactions you process, if it is high enough you will be required to have quarterly scans. Fact is that it only proves you were complaint on that day. If the next day you remove a part of the process etc, you are not compliant anymore. The only way their processor and/or bank would know that they weren't complaint is if BRS told them they weren't complaint.

"[PCI] is just a display of due diligence that you have all the security measures in place per the card company and processing network guidelines" TRUE!, so I think my question is a valid starting point "Was Bulk Reef Supply PCI Compliant at the time its systems were compromised in June 2014" If they aren't even doing that, they don't deserve my or anyone else's business.


hmmmm.....agree to disagree with some and most of this.
 
Noticed that someone bought a free lunch with my card the other day in Washington at Buffalo Wild Wings. Promptly called Chase and got my card shut off.

Sigh.
 

IF YOU HAD TO TAKE A REEFING EXAM, WOULD YOU PASS?

  • Yes!

    Votes: 32 45.7%
  • Not yet, but I have one that I want to buy in mind!

    Votes: 9 12.9%
  • No.

    Votes: 26 37.1%
  • Other (please explain).

    Votes: 3 4.3%
Back
Top