MicroBrewMaster
Well-Known Member
Bump don't want this falling to the bottom
Midwest has handled this horribly from the start. For starters, they mishandled customers' information. Then they denied any culpability when a thread was posted in June, despite already knowing they had had a breech. Then they waited over a month to notify customers who may have been affected. Then they chose to make the announcement on a message board in the middle of a long weekend so it would get less attention. Finally, they are not offering identity theft insurance to those who had their information stolen due to MW's mishandling, but instead offer a GC, essentially requesting you trust them with your information again. I've only ordered a couple times from them, but I will definitely not be ordering from them ever again and will go out of my way to warn others that they will do the bare minimum to protect your info and then tell you to your face that they had nothing to do with it being stolen.
Just found this gem - http://doj.nh.gov/consumer/security-breaches/documents/midwest-supplies-20130827.pdf
Goes to say they received preliminary info on July 19. The first post on here was July 7 and in a later post that (or the next) day the OP confirmed his dad had contacted Midwest about it.
Is Midwest lieing to the Attorny General now?
The last sentence of the first page says "The company does not store credit card information." If that's the case then how can I order using my previous credit card info?
The conflicting statements and the initial denial by Midwest followed by an extremely slow response is enough for me to say "I'm done with them".
From my understanding, if someone else were to obtain the token they wouldn't be able to use it because the token is only acceptable for use between MW and their processor.
In this day shopping online shouldn't be a "your information will be hacked or it has been hacked" situation. There are controls in place and if they're not in place, there should be controls in place to prevent this from happening. Having your information hacked by shopping online should be a rare occurrence.I love the first world problems here: "blood money", "inconvenience while on vacation", etc.
There are two types of people who shop on-line: those who have had their info hacked and those who will.
If you're gonna shop online, make sure it is with a company with a good fraud policy.
If you don't want to risk it, just take some gold down to your LHBS, or better yet: grow your own barley and hops.
With that said, I hope midwest learned their lesson by ignoring those who posted here originally in a very respectful manner saying "hey Midwest, a bunch of customers have been hacked; might want to check it out." And responding with "thanks, but it isn't us."
With respects to the long weekend posting, I have a strange feeling that they did this thinking it would garner some kudos from the community for their attempt to notify customers in spite of the long holiday weekend. The cynic in me thinks this was a play on their part and nothing more.Midwest has handled this horribly from the start. For starters, they mishandled customers' information. Then they denied any culpability when a thread was posted in June, despite already knowing they had had a breech. Then they waited over a month to notify customers who may have been affected. Then they chose to make the announcement on a message board in the middle of a long weekend so it would get less attention. Finally, they are not offering identity theft insurance to those who had their information stolen due to MW's mishandling, but instead offer a GC, essentially requesting you trust them with your information again. I've only ordered a couple times from them, but I will definitely not be ordering from them ever again and will go out of my way to warn others that they will do the bare minimum to protect your info and then tell you to your face that they had nothing to do with it being stolen.
Even if they were PCI compliant this could have happened. It appears they were not and somewhat more importantly, their behavior when customers who have likely spent a fair amount of money on supplies from their site expressed concerns, is unforgivable. I will be surprised if they come out of this healthy.Well it looks like I won't be ordering from Midwest anytime soon. Sucks for you.
YOUR FAILURE TO PREPARE HAS CAUSED AN EMERGENCY ON OUR PART.
no bueno
HAXXOR TEH GIBSON
They claimed they hired a lawyer who specializes in this type of intrusion. I have to say, I question that because like you, they should have been advised instantly to notify customers.The only way to protect ourselves in the future from this type of crap is for people like me, who were not affected, to decide not to do business with Midwest. That way, the calculus changes the next time around and a vendor will decide that waiting nearly 3 months to talk about it is a BAD business decision.
I really think the lawyer who gave them the advice to keep quiet did a bad job as part of his/her job is to consider the client's financial interests as well. I really think they miscalculated the repercussions of this..
I read on reddit that someone received a letter via post.Very interesting... I placed an order through Midwest in June, and then had fraudulent charges on my CC (luckily Chase blocked them). Have not received anything from Midwest as stated.
Have these notifications been made over email or snail mail?
Based on the below, perhaps they did only notify NH residents. Who knows, they need to respond asap. Also, the $25 is a gift card so you can spend it on their store. They lose absolutely nothing here unless customers stand their ground and take their business elsewhere.Couple questions for Midwest Supplies:
1.) How are you determining who was affected by this?
2.) How are you notifying those affected?
3.) How are you giving the $25 credit?
( I believe I was affected but have not received any notification. )
They best hope that they didn't lie to an AG about the intrusion and they better hope they're not messing with the New Hampshire AG. NH does not mess around at all. Although little, their reach is far and NH will stop at nothing to ensure their consumers are protected.Just found this gem - http://doj.nh.gov/consumer/security-breaches/documents/midwest-supplies-20130827.pdf
Goes to say they received preliminary info on July 19. The first post on here was July 7 and in a later post that (or the next) day the OP confirmed his dad had contacted Midwest about it.
Is Midwest lieing to the Attorny General now?
Bobby_M said:I was hacked for sure and I didn't receive any contact from MW over the weekend. My fraud charges happened over a weekend when I don't often check my online ledger and they got me for at least $2000 in charges which I am still currently on the hook for. I had to file a police report, then go back and pick it up to send to my bank after getting a form notarized. At least if I got the number lifted by a waiter at a restaurant, I'd know exactly who to punch in the face.
Just found this gem - http://doj.nh.gov/consumer/security-breaches/documents/midwest-supplies-20130827.pdf
Goes to say they received preliminary info on July 19. The first post on here was July 7 and in a later post that (or the next) day the OP confirmed his dad had contacted Midwest about it.
Is Midwest lieing to the Attorny General now?
After thoroughly investigating the concerns in this thread, we do not believe they were related to purchases made at Midwest Supplies
I just want it known to the moderators that by shutting down that thread other members were not able to come forward and I don't think that is right.
Everyone who is saying they won't be ordering from Midwest again, take the time to send them a message on their site requesting they delete your account and personal information and tell them why. Quietly never buying from them again doesn't send a message, literally sending a message does.
They've explained this. The first time you enter your info the processing center creates a token and the token is stored with MW. From then on, the token is sent to the processing center.... they know what credit card it represents and use it.
From my understanding, if someone else were to obtain the token they wouldn't be able to use it because the token is only acceptable for use between MW and their processor.
Once again,this is why I use paypal whenever a site offers it. Midwest does...more recourse for me & no hacked cards.
Done, even though my account doesn't appear to have been hacked. (yet)Everyone who is saying they won't be ordering from Midwest again, take the time to send them a message on their site requesting they delete your account and personal information and tell them why. Quietly never buying from them again doesn't send a message, literally sending a message does.
Again it could have been just a coincidence or could it?
Got a letter in the mail today. Checked over last months statement and had 3 charges from Walmart.com over 2 days for the same amount. Guess I'lll chalk that up to credit card fraud. Awesome.