Major jewelry retailers Jared and Kay Jewelers have patched a website vulnerability that compromised order information for all online customers, Krebs on Security reported this week.
The bug was discovered and reported by a Jared customer who learned he could access other shoppers' orders by altering a link in his confirmation email and pasting the link into his browser. It was a small change, the report states, but it led him to orders containing peoples' names, billing and shipping addresses, phone numbers, email addresses, items and amount purchased, delivery date, tracking link, and the last four digits of the credit card used.
Recognizing the potential for criminals to abuse this data and concerned for the safety of his own, he reached out to Signet Jewelers, parent company of Jared and Kay Jewelers. Signet reports it fixed the problem for future orders; however, the shopper who found the problem claims the company didn't address data exposure for past orders until he reported it to Krebs.
Signet states the issue was limited to online orders for both Jared and Kay, and the websites of its other companies (Zales and Piercing Pagoda among them) were not affected.
Read more details here.