Search By Topic:

Popular Topics:



News & Features | Jan 25th, 2011

Credit Fraud: Cosmetics Company Lush Shuts Down UK Website, Speaks Directly to Hacker

Elaine Rigoli

In a rare business move, cosmetics company Lush has deactivated its main e-commerce website for customers in the United Kingdom and posted a one-page message about the hacker who broke into the company’s database and stole thousands of credit card numbers.


The main website also speaks directly to the hacker:

If you are reading this, our web team would like to say that your talents are formidable. We would like to offer you a job - were it not for the fact that your morals are clearly not compatible with ours or our customers'.

The company sent an email to all customers who have placed an online order between October 4, 2010, and January 20, 2011, urging them to check their statements and contact their banks for advice as their card details may have been compromised.

The company is “erring very much on the side of caution” by notifying more customers than required, since customers have already experienced unauthorized use of their credit cards.

How did this happen? The company says it is still investigating, though one likely scenario is that the online retailer simply did not encrypt the customer details it held within its database. Interestingly, the company has now implemented a new credit-card encryption system called Retail Suite.

The all-natural cosmetics company has completely retired its UK website, saying it refuses to put customers at risk of another theft. It will launch a new, temporary website in a few days, perhaps signaling this data breach is atypical of a scenario involving a lone hacker simply breaking into the central database. The new website will initially accept only PayPal payments.

Meanwhile, the company’s U.S. team has put on a happy face, saying customers here can shop "without concern for their privacy” because the North American websites operate on a separate platform.

Will this news deter you from shopping at this and other online retailers? What security steps do you take to ensure the websites you visit are safe places to shop?

Associated Topics:

Associated Topics:


Related Posts

Protecting Your Identity with the Internet of Things

Thought Leadership
Eva Velasquez | May 21st, 2015

The internet of things—or IOT, as it’s commonly known—was once the stuff of science fiction, a newfangled “wave of the future” concept only experienced at futuristic demonstrations like the World’s Fair. But now many of these devices are already in use in millions of households around the world. They’ve become an interesting yet somehow still unknown entity in the world of technology, and industry experts have stated these products will be the norm just a handful of years from now. Read More

Tips to Protect Your Digital Identity

Thought Leadership
Nikki Junker | Apr 29th, 2015

Within the last decade, our senses of self and identity have made a major shift.  Whether we’ve noticed it or not, the items that used to define our identities have gone from hard copy items, such as birth certificates and Social Security cards, to online banking passwords, Facebook logins, and mobile wallets stored in our smartphones.  While we still need to safeguard and protect those hard copy documents, we also have to focus on our digital identities. Read More

Why I Started Private Communications Corporation

Thought Leadership
Kent Lawson | Apr 28th, 2015

Kent Lawson, Founder and CEO of Private WiFi, talks about what inspired him to start the company. This is the first in a series of weekly CEO blog posts on this and other topics. Read More

New Hotel WiFi Vulnerability

Thought Leadership
Alok Kapur | Apr 9th, 2015

Earlier this year, the FTC declared a critical announcement for travelers: hotel WiFi is dangerous. Many people assume that because they are paying for it the network must be safe, but that is a dangerous assumption. Hotel WiFi networks are completely insecure; the bad news is that a new exposure in hotel WiFi has just been found. Read more to find out how you can keep yourself protected. Read More


Thank you for subscribing to our newsletters

Your email has been added to our system. You will be e-mailed shortly with a request to confirm your membership. Please make sure to click the link in that message to confirm your subscription.