Concern over Northern Brewer account

Homebrew Talk - Beer, Wine, Mead, & Cider Brewing Discussion Forum

Help Support Homebrew Talk - Beer, Wine, Mead, & Cider Brewing Discussion Forum:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.

Cider123

Well-Known Member
Joined
Oct 31, 2010
Messages
1,135
Reaction score
245
So I was just visiting the Northern Brewer website and had logged into my account. I was planning on placing another order. I happened to go into the "order history" section. When I entered that area I found a whole list of orders that I never placed. When I accessed those supposed prior orders, they were the orders of some other customer. I don't know who this person is, but I was given a whole bunch of his personal information including his name, his wife's name, their address and contact information, what he ordered, how much he spent on each order, etc. I am now concerned who might have access to my personal information through this error.

I just sent an email to Northern Brewer to look into this error. I an concerned after remembering the credit card issue that happened with Midwest a while back.

I recommend you check your accounts if you have one.
 
Here is the response I received from NB today:

"A number of months ago we had an ongoing re-indexing of our website & its operating files take place from within the servers that operate our website. One effect of this process was that some data was inadvertently transposed into incorrect locations - most notably order information being misfiled among customer records. The issue was isolated to a small time frame from earlier this year & it has since been fixed. The misfiled customer information that was visible by other customers would have been limited to order histories, but not payment information - which we encrypt & process via a third part credit processor that provides no direct records of credit card information that could be maliciously used by other parties. My apologies for the error & the confusion surrounding it. Our IT team has informed us that these misfiled orders are unable to be removed from the incorrect accounts, but that the problem should not repeat itself going forward.

Please let me know if you've got any further questions & thanks for shopping with us."


Very assuring! I get to keep the personal information of someone else on my account. How nice of NB. Maybe I'll send him a Christmas card now that I have his address.
I wonder who has my personal information? Do you wonder who has yours?
 
"I wonder who has my personal information? Do you wonder who has yours?"

It sounds like quite an embarrassment for their "IT team".
However, your street address isn't exactly protected information.
The USPS will give to anyone willing to pay, same with the phone company and many others.
Like most responsible e-commerce websites, from their response it sounds like they do not store complete CC info on their server at all.
So at least your financial info was never at risk.
 
That is awful. I have never used Northern Brewer, and I'm based on this, I'm really glad I haven't. Since I don't know all the details, I may be wrong, but it almost sounds irresponsible of them not to fix this situation.

The response sounds unacceptable; to have other peoples private information in wrong accounts. If they can't fix it, they should delete everyone's order history to prevent private information getting into the wrong hands.
 
It's probably complicated to determine what is a wrong order so they prefer to leave accounts untouched.

Names and addresses are not private information. They are pretty much available to anyone. Try whitepages.com on yourself, it's free.

It is weird that this happened to people's accounts but if someone finds out what grains and hops I ordered, oh well.

If you had access to credit card info for someone that would be a huge problem. This is a minor IT goof from a server migration and those do happen.
 
" This is a minor IT goof from a server migration and those do happen."

And this is why a GOOD IT department does backups first...
 
It's probably complicated to determine what is a wrong order so they prefer to leave accounts untouched.

Names and addresses are not private information. They are pretty much available to anyone. Try whitepages.com on yourself, it's free.

It is weird that this happened to people's accounts but if someone finds out what grains and hops I ordered, oh well.

I don't think this is a minor error. I tried your link of white pages.com and they have incorrect information for me. I would prefer it to stay that way. NB should delete any incorrect information no matter what it does for their business.

Based on the fact that they do not protect information (even if credit card information is still protected), I don't think I will ever buy from them.
 
While names and addresses aren't exactly private, I personally would prefer it if NB wouldn't be just okay with leaving the accounts as they are. There has to be a way to fix that. I cannot see any orders that I did not place but that doesn't mean someone else can't see my prior orders.

I'm not running around screaming NSA leak or anything, but I would have suspected NB would have figured it out with their IT department or hire another company to assist with this supposed one-time indexing issue.
 
Names and addresses are not private information. They are pretty much available to anyone. Try whitepages.com on yourself, it's free.

How astute of you.

That said, having someone elses information show up in my account isn't the same thing as picking up the whitepages.

I don't pay any attention to the license plate numbers of cars that randomly pass my house. Park in my driveway and that's another matter entirely.
 
People can now see my order for my secret Moose Gland Porter, that's unacceptable. Your name and address are already out there somewhere else. Your financial info are still protected on a third party server and still secure. How are they to tell who's history is wrong to change it? Sometimes a glitch is hard to fix simply because it should "no way in hell have been able to happen in the first place". They made a mistake and owned up to it. They will still get my business since I don't cut off companies that make one simple mistake that doesn't actually harm me. But, that's just my opinion, I could be wrong.
 
everyone must be tired of bashing Midwest, innit?

Seems you forgot that they are joined/merged/sister companies. Essentially one in the same.

The correct way to handle this is to wipe the orders where account holder and shipping names do not match. After the wipe, notify the effected account holders to let them know old orders can be retrieved from backup if they were legitimate.
 
Seems you forgot that they are joined/merged/sister companies. Essentially one in the same.
.

naw, cowboy and/or girl, I didn't forget. I was just pointing out people go in phases on what interweb HBS is doing wrong and how everyone knows how to fix it. I'm not a guy to take too seriously unless I personally give you my address. my sarcasm is wicked awesome, yo!:rockin:
 
naw, cowboy and/or girl, I didn't forget. I was just pointing out people go in phases on what interweb HBS is doing wrong and how everyone knows how to fix it. I'm not a guy to take too seriously unless I personally give you my address. my sarcasm is wicked awesome, yo!:rockin:

I don't doubt that some people rag on a particular shop, but NB/MW hold a special place in mine and many others hearts. No company should retain any customer loyalty after the crap that they pulled.

https://www.homebrewtalk.com/f14/important-statement-midwest-supplies-429909/
 
Something tells me this is going to get interesting.

081018-love-this-thread.jpg


/grabs popcorn
 
How are they to tell who's history is wrong to change it?

To some degree, of course, they may not know if any given account history is right or wrong.

However, I'd think if you called to complain that someone elses order history is in your account they'd take a clue and at least fix them case by case.

Hey, if you don't care, that's your business. But, if someone else does care then NB should endeavour to fix it.
 
Meh, I learned a long time ago not to argue with certain types. I've made my point regarding NB/MW.

how did you know I'm handsome, witty, and funny? besides, I didn't know we were arguing. I thought I was just being my charming self!



seriously, it's nothing for anyone to be "outraged" about. if anyone's worried about the name/address on another's order history, send them some of your home brew with a note saying why. maybe you'll get some in return.:mug:
 
I myself just lost interest and walked away. They gave me some line about connecting me with their IT dept so it can be explained to me in further detail. I got bored and just cancelled my account.

Ok, I'm over it.
 
Back
Top