Unexpectedly received a free starter kit?

Status
Not open for further replies.

flbutterfly1

Ultra Member
ECF Veteran
Jun 16, 2010
1,171
266
Interlachen, Florida
oh well I already got a reissue 24 hrs later. I caught the bogus charge a few hours after it happened I always keep an eye on it for a few days after i make a purchase. The charge was for $2.29 but I can only imagine if I wouldnt have caught it till after the weekend. All is good for now, just hope this doesnt happen again. I have had that same card # for 10 yrs and had all the #'s memorized.
 

salemgold

ECF Guru
Supporting Member
ECF Veteran
Verified Member
Jul 5, 2010
28,155
63,784
South Carolina
My bank offers the option of creating a card #, exp date and set amount for each purchase. It is all charged on my real card but even if somebody did get the info it is only useable for a certain amount and only to purchase from where I designated. I also always go online using a sandboxed web browser.
 

deusXmchna

Senior Member
ECF Veteran
Apr 11, 2010
238
3
TX
My bank offers the option of creating a card #, exp date and set amount for each purchase. It is all charged on my real card but even if somebody did get the info it is only useable for a certain amount and only to purchase from where I designated. I also always go online using a sandboxed web browser.

Sounds good.
what bank?
I've been looking to switch.
 

Magnetron

Unregistered Supplier
ECF Veteran
The site I ordered from was digitalciggz dot com. I referred my friend to the site and his card # was also stolen. I suspect the site was hacked by an outsider but can't say for sure. All I know is that I won't be ordering from them ever again.

My bank has credited me for my losses so everything will be okay.

Hi Digs, I'm concerned that you have not contacted me once either by phone or by email regarding the issue of your credit card credentials being compromised, but rather decided to post her in this thread regarding your issue. I take very serious measure to ensure that Digitalciggz dot com is secure at all times via Extended SSL certicate, Site Scanners on the front end, and a "live securty company" I employee to scan the back end of my site every hour, I do this to ensure the incident you are speaking of cannot happen at Digitalciggz.com.

I have had no other confirmed reports of any of my customers cards being stolen as of late. In the future if you have feel you have proof and absolute conformation that my site was indeed the cause of your credit card being taken I would appreciate it you would contact me directly through my support page which also has my phone number listed on it if you would like to speak with me directly. This is a very serious accusation to make about Digitalciggz.com and I hope that in the future you will do your best to speak with me about your problems rather than make accusation here without 100% proof that my store was the demise of your credit card being stolen.

Please understand that I am sorry this happened to you as I have had this happen to me before and i know its a pain in the ...... and sometimes it can be hard to point the finger directly at what was the cause.. but when you shoot blindly without back up this can be harmful to companies even if it was not your intention.

I wish you the best in recovering you stolen funds.

Michael (Owner of Digitalciggz dot com )
 

Digs

Super Member
ECF Veteran
Apr 6, 2010
677
83
Ohio
Hi Digs, I'm concerned that you have not contacted me once either by phone or by email regarding the issue of your credit card credentials being compromised, but rather decided to post her in this thread regarding your issue. I take very serious measure to ensure that Digitalciggz dot com is secure at all times via Extended SSL certicate, Site Scanners on the front end, and a "live securty company" I employee to scan the back end of my site every hour, I do this to ensure the incident you are speaking of cannot happen at Digitalciggz.com.

I have had no other confirmed reports of any of my customers cards being stolen as of late. In the future if you have feel you have proof and absolute conformation that my site was indeed the cause of your credit card being taken I would appreciate it you would contact me directly through my support page which also has my phone number listed on it if you would like to speak with me directly. This is a very serious accusation to make about Digitalciggz.com and I hope that in the future you will do your best to speak with me about your problems rather than make accusation here without 100% proof that my store was the demise of your credit card being stolen.

Please understand that I am sorry this happened to you as I have had this happen to me before and i know its a pain in the ...... and sometimes it can be hard to point the finger directly at what was the cause.. but when you shoot blindly without back up this can be harmful to companies even if it was not your intention.

I wish you the best in recovering you stolen funds.

Michael (Owner of Digitalciggz dot com )

Well I posted this before I knew that my CC# was stolen. If I had known what was actually happening I wouldn't have. I thought I should follow up and let everyone know what was going on especially since some other members seemed concerned.

When you say things like "the incident you are speaking of cannot happen", "sometimes it can be hard to point the finger directly at what was the cause" and that I'm shooting "blindly without back up" it sounds to me like you're calling me a liar and I really don't appreciate that. I think you should just admit that there was a problem.

I spoke with my friend whose CC# was also stolen just to ask him who it was that told him. He told me that DigitalCiggz had e-mailed him saying that the site wasn't encrypted during the time of his purchase and that his CC# may have been compromised. The email also said that the security issues were fixed. When he called his bank he found that there was a charge on his account that wasn't his. Considering this and the fact that your Web site is the only one we have both placed orders on in the last year I'm pretty sure that's where my # was stolen from.

I'm not trying to harm your company, I'm just following up with my post and stating the facts. I always do quite a bit of research before I order anything. There were several companies to choose from when I ordered my atomizers and I chose yours so that says a little something. It's just unfortunate that this had to happen.
 

Magnetron

Unregistered Supplier
ECF Veteran
Well I posted this before I knew that my CC# was stolen. If I had known what was actually happening I wouldn't have. I thought I should follow up and let everyone know what was going on especially since some other members seemed concerned.

When you say things like "the incident you are speaking of cannot happen", "sometimes it can be hard to point the finger directly at what was the cause" and that I'm shooting "blindly without back up" it sounds to me like you're calling me a liar and I really don't appreciate that. I think you should just admit that there was a problem.

I spoke with my friend whose CC# was also stolen just to ask him who it was that told him. He told me that DigitalCiggz had e-mailed him saying that the site wasn't encrypted during the time of his purchase and that his CC# may have been compromised. The email also said that the security issues were fixed. When he called his bank he found that there was a charge on his account that wasn't his. Considering this and the fact that your Web site is the only one we have both placed orders on in the last year I'm pretty sure that's where my # was stolen from.

I'm not trying to harm your company, I'm just following up with my post and stating the facts. I always do quite a bit of research before I order anything. There were several companies to choose from when I ordered my atomizers and I chose yours so that says a little something. It's just unfortunate that this had to happen.

PM Sent to you for further discussion Digs.
 

zoiDman

My -0^10 = Nothing at All*
Supporting Member
ECF Veteran
Apr 16, 2010
41,616
1
84,722
So-Cal
...

I have had no other confirmed reports of any of my customers cards being stolen as of late. In the future if you have feel you have proof and absolute conformation that my site was indeed the cause of your credit card being taken I would appreciate it you would contact me directly through my support page which also has my phone number listed on it if you would like to speak with me directly. This is a very serious accusation to make about Digitalciggz.com and I hope that in the future you will do your best to speak with me about your problems rather than make accusation here without 100% proof that my store was the demise of your credit card being stolen.

...

Michael (Owner of Digitalciggz dot com )

The thing I’m curious about is why is it when I do a Google search with the keywords: “Digitalciggz.com Credit Card” that I get hits about people having problems? Correct me if I'm wrong, but this seems like this isn't the first time something like this has happened.
 

Magnetron

Unregistered Supplier
ECF Veteran
The thing I’m curious about is why is it when I do a Google search with the keywords: “Digitalciggz.com Credit Card” that I get hits about people having problems? Correct me if I'm wrong, but this seems like this isn't the first time something like this has happened.

Digs and zoidDman,

PLEASE READ CAREFULLY

I think what is being reffed to here is an old incident that happened back in November of 2010 or before this date to be specific on 11/12/2010. It is unclear form Digs post whether he is referring to a purchase that was during this time that my site was compromised a time long ago when his credit card was taken or within the the last 7 days.
I suspect that Digs is referring to a time on or before 11/15 2010 If Digs is referring to a purchase made recently I will look into it if he decides to contact me and give me the details of the order when,what time and what card was used..I will absolutely investigate it further. But I belive this will help clear up some mis communication.

This unfortunate event took place back in November 2010. I was very forward with every single one of my customers about what happened, and offered all the help I could to help people who were effected by my site begin compromised. I even got on the phone and started calling folks to let them know they could have been compromised. I was and still am honest and open about what crime were committed against Digitalciggz.com and its customer at that time.

JUST TO BE VERY CLEAR this site has been fine ever since that date, and I have not one single incident of hacking take place because of the added security measures I put into place that day.

The Reason you can find things related to Digitalciggz and credit card fraud in goggle is because YES it did happen to Digitalciggz.com and Yes it was horrible, for everyone including me as the business owner.

I feel that I did the right thing then and now.

I have include the exact letter that was sent out immediately upon learning of the compromise so everyone here can now read how I handle the situation and have better understanding about what happened and how it was fixed.

HERE IS THE COPY OF THE ORIGINAL LETTER SENT OUT DATED 11/12/2010

Dear Valued Customer,


The purpose of this letter is to notify you that Digitalciggz.com recently discovered on Nov 11th, 2010 that customer information, including Visa and MasterCard credit card information, may have been compromised. In particular, it is possible that an unauthorized person may be in possession of your name, credit card number, expiration date, and card verification number. We are still investigating the details of this incident , but it appears that an unauthorized individual may have accessed this information by hacking our e-Commerce website. We cannot say exactly when (what date) this malicious code was injected into our website so we have chosen to stay on the side of safety in inform all of our customers who have purchased from the since the day we went live 4/4/2010.


To protect against possible financial loss, we encourage you to review your Visa or MasterCard credit card account and bank statements , and request a NEW credit card number for ( any and all credits cards that you have used at Digitalciggz.com.)


The call-in number to assist you with questions or concerns you may have related to this incident. All questions should be directed to 1-707-637-2457 (Michael Mullins Owner) or support@digitalciggz.com I will do my best to answer further questions you may have.



As you can only imagine we are mortified that this has happened to our website and potentially our customers and we hope that you will take this letter in good faith that we care very much about your security and safety as an online consumer, and are so very grateful to have you as our customer.


We hate the thought that you have to go through this because of shopping at our website, and we can only hope that our excellent customer service, and reputation as a leading supplier will win your confidence back to shop with us again.


We take this breach of our data seriously, We immediately reported this crime to local law enforcement authorities, as well as other federal authorities. We also reported the incident to Visa and Mastercard. We have engaged an outside, highly recognized security firm to determine how this incident occurred and to confirm that information we obtain is protected to the fullest extent reasonably possible. Here is what we have done at Digitalciggz.com to ensure this cannot happen again.


1:The malicious hacker code that was the root of this incident has been permanently removed from the website. THIS WAS THE ROOT OF THE PROBLEM and was fixed at exactly 11/11/2010 at 11:20 PM PST.


2: The whole website has been moved to new dedicated secure server.


3: The SSL Certificate has been upgraded to a more advanced encryption bit.


4: The Website and all its files are now scanned hourly by a private company to ensure that there is no way that any malicious code can be injected on the website again.


At no charge, you can have the three major credit card agencies place a "fraud alert" on your file that alerts creditors to take additional steps to verify your identity prior to granting credit in your name. This service can make it more difficult for someone to get credit in your name. Note, however, that because it tells creditors to follow certain procedures to protect you, it also may delay your ability to obtain credit while the agency verifies your identity. As soon as one credit bureau confirms your fraud alert, the others are notified to place fraud alerts on your file. Should you wish to place a fraud alert, or should you have any questions regarding your credit report, please contact any one of the agencies listed below.


Agency Toll-Free Website


Experian 888-397-3742 Credit Report, credit score and credit check from Experian

Equifax 800-525-6285 Credit Reports, Credit Scores & Identity Theft Protection from Equifax

TransUnion 800-680-7289 TransUnion - Check Your Credit Report and Credit Score Online, Instantly and Securely

You are also entitled under U.S. law to one free credit report annually from each of the three major credit bureaus. To order your free credit report, visit AnnualCreditReport.com or call toll-free (877) 322-8228. For additional information on how to further protect yourself against identity theft, you may wish to visit the web site of the U.S. Federal Trade Commission at Deter. Detect. Defend. Avoid ID Theft, or, for California residents, the web site of the California Office of Privacy Protection at California Office of Privacy Protection.


Additional Phone numbers


Mastercard Hotline: 1-800-627-8372


Visa Hotline: 1-800-847-2911


Again, we deeply regret this incident and any inconvenience or concern it may cause you. We are working diligently to ensure that this can never happen again. The Website is now fixed and is 110% secure as it should be.


Sincerely and Respectfully,


Michael Mullins

Owner of Digitialciggz.com
 

Elendil

Assclown Exterminator
Supporting Member
ECF Veteran
Verified Member
Mar 28, 2009
10,413
678
IL USA
The conversation about digitalciggz is over in this thread. Both sides have had their say. I invited the supplier to post in this thread since his company name was mentioned originally. Anyone reading can judge for themselves the situation and make their own choice. If the parties want to continue to communicate in private that is fine but I have to ask that the discussion regarding this particular situation not be continued in this thread.
 
Status
Not open for further replies.

Users who are viewing this thread