« The $7 quibble at the Oregon Grille restaurant | Main | Cheap tricks: calling for quick fixes »

Direct Marketing Services doesn't tell consumers about data breach

montgomeryward.jpg

How many out there know that Montgomery Ward went out of business in 2001? Now, how many know that a catalog company bought the Wards name brand out of bankruptcy in 2004? If you did, I'm awarding quality points to you. Bravo.

Now here's the bad news for anyone doing business with Wards.com and six other affiliated sites that includes three Sears brands (SearsHomeCenter.com, SearsShowplace.com and SearsRoomforKids.com). At least 51,000 records were breached at the parent company of those brands, Direct Marketing Services Inc.

Someone hacked into and stole consumer credit card information, according to DMSI, which informed its payment processor and Visa and MasterCard, and filed a report to the U.S. Secret Service.

DMSI did not, however, notify its customers about the breach.

After the Associated Press contacted the company, DMSI now plans to contact consumers. According to the story:

This hack might have stayed quiet except for online chatter detected in June by Affinion Group Inc.'s CardCops, a group of investigators who track payment-card theft for financial institutions. In Internet chat rooms frequented by card thieves, CardCops spotted hackers touting the sale of 200,000 payment cards belonging to one merchant. CardCops then intercepted several hundred of the records, along with the online handles belonging to hackers whose real names remain unknown.

Along with the card numbers, their three-digit "security codes" and expiration dates, the thieves had the cardholders' names, addresses and phone numbers. The data had been organized in the same way, indicating the numbers likely came from the same database. CardCops' president, Dan Clements, also noticed that the vast majority of the cardholders were women, a clue that the records came from a merchant catering to a certain demographic.

Need I tell you this is my Naughty Business of the Week pick? This is why 44 states have passed laws forcing companies to disclose data breaches to customers. As Liz has told you, in Maryland, the law requires businesses alert consumers when their personal information --- names, dates of birth, Social Security numbers, credit card numbers or other identifiers --- has been compromised by a lost backup tape, theft of a laptop or hard drive or the inadvertent posting of a file on a Web site.

How can you even protect yourself if you don't even know that your information has been compromised? This just shows you how important it is to look at your credit report carefully. Shame on Direct Marketing Services for leaving its consumers in the dark.

(Associated Press)

Post a comment

All comments must be approved by the blog author. Please do not resubmit comments if they do not immediately appear. You are not required to use your full name when posting, but you should use a real e-mail address. Comments may be republished in print, but we will not publish your e-mail address. Our full Terms of Service are available here.

Please enter the letter "q" in the field below:
About the blogger
A native of Vietnam, Dan Thanh Dang has lived in Maryland most of her life and has been a Baltimore Sun reporter since 1990. She's written about everything from mayoral elections and murder to energy prices and online dating. These days, she writes about a topic she's all too familiar with, spending money -- how to save more of it, blow all of it, use it wisely and avoid getting ripped off in the process.
Column archive
Contributors
• Columnist Eileen Ambrose
E-mail Eileen
Column archive

• Reporter Liz Kay
E-mail Liz
Liz also writes the weekly Watchdog column, about problems in area neighborhoods that aren't being fixed.
E-mail Watchdog
Most Recent Comments
-- ADVERTISEMENT --