Jared, Kay Jewelers Web Vuln Exposes Shoppers' DataJared, Kay Jewelers Web Vuln Exposes Shoppers' Data
A Jared customer found he could access other orders by changing a link in his confirmation email.
December 4, 2018
Major jewelry retailers Jared and Kay Jewelers have patched a website vulnerability that compromised order information for all online customers, Krebs on Security reported this week.
The bug was discovered and reported by a Jared customer who learned he could access other shoppers' orders by altering a link in his confirmation email and pasting the link into his browser. It was a small change, the report states, but it led him to orders containing peoples' names, billing and shipping addresses, phone numbers, email addresses, items and amount purchased, delivery date, tracking link, and the last four digits of the credit card used.
Recognizing the potential for criminals to abuse this data and concerned for the safety of his own, he reached out to Signet Jewelers, parent company of Jared and Kay Jewelers. Signet reports it fixed the problem for future orders; however, the shopper who found the problem claims the company didn't address data exposure for past orders until he reported it to Krebs.
Signet states the issue was limited to online orders for both Jared and Kay, and the websites of its other companies (Zales and Piercing Pagoda among them) were not affected.
Read more details here.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023