Jared, Kay Jewelers Web Vuln Exposes Shoppers' DataJared, Kay Jewelers Web Vuln Exposes Shoppers' Data
A Jared customer found he could access other orders by changing a link in his confirmation email.
December 4, 2018

Major jewelry retailers Jared and Kay Jewelers have patched a website vulnerability that compromised order information for all online customers, Krebs on Security reported this week.
The bug was discovered and reported by a Jared customer who learned he could access other shoppers' orders by altering a link in his confirmation email and pasting the link into his browser. It was a small change, the report states, but it led him to orders containing peoples' names, billing and shipping addresses, phone numbers, email addresses, items and amount purchased, delivery date, tracking link, and the last four digits of the credit card used.
Recognizing the potential for criminals to abuse this data and concerned for the safety of his own, he reached out to Signet Jewelers, parent company of Jared and Kay Jewelers. Signet reports it fixed the problem for future orders; however, the shopper who found the problem claims the company didn't address data exposure for past orders until he reported it to Krebs.
Signet states the issue was limited to online orders for both Jared and Kay, and the websites of its other companies (Zales and Piercing Pagoda among them) were not affected.
Read more details here.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication Methods
Oct 26, 2023Modern Supply Chain Security: Integrated, Interconnected, and Context-Driven
Nov 06, 2023How to Combat the Latest Cloud Security Threats
Nov 06, 2023Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and Phishing
Nov 01, 2023SecOps & DevSecOps in the Cloud
Nov 06, 2023