Epsilon data breach results in a huge loss of customer data

Epsilon, the world’s largest provider of permission-based email marketing, has suffered a huge data breach. That means hackers may have swiped customer data belonging to the world’s biggest brands.

Epsilon sends more than 40 billion emails a year on behalf of 2,500 brands. Security Week said the breach has affected a number of those brands, including grocery retailer Kroger, TiVo, Marriott Rewards, Ritz-Carlton Rewards, US Bank, JPMorgan Chase, Capital One, Citi, McKinsey & Company, New York & Company, Brookstone, and Walgreens.

At first, the breach was believed to have affected only Kroger. But more and more companies have been confirming that they have had their data stolen as well. Epsilon builds and hosts customer databases for brands, making it a prime target for hackers. In many cases, the data lost is simply someone’s email address. But Security Week says that’s all that a hacker needs to try a targeted phishing attack against the customer, who will expect to have communication from these brands. You might, for instance, receive a message from Brookstone about a special offer addressed to your name. But it may be carrying a virus that exposes you to data theft if you simply open the email. These kinds of phishing attacks are likely to have a higher success rate.

Marriott Rewards and Ritz Carlton Rewards told SecurityWeek that their customer names, email addresses, and member point balances were exposed. Citi warned customers via Twitter about the incident. Epsilon disclosed the breach late Friday.

[image credit: alertsec]

  • http://recodss.blog138.fc2.com/blog-entry-5.html resume services

    The last product could possibly be the placement question.

  • http://profiles.google.com/vincekye Vince Sipocz

    CollegeBoard was affected too.I would upload a screencap, but when I try to upload a JPEG or a GIF, the comment box says that it “only supports uploading images.” #fail

  • gabediaz

    Yes, I woke up today to emails from Disney Destinations and HSN saying emails were obtained.

  • http://privacysecuritymatters.default.wp1.lexblog.com/2011/04/major-e-mail-data-breach-occurs-at-mega-marketer/ Major e-mail data breach occurs at mega-marketer | Data Breach, Data Breach Notification, phishing | Privacy & Security Matters

    [...] VentureBeat [...]

  • http://invenioit.com/archives/231 How to keep your online identity protected | Invenio IT

    [...] fairly common due to its relative ease, since all the hackers need is your name and email address. Epsilon’s recent data breach was a great example of the possibility of phishing. Their network was hacked [...]

  • http://invenioit.com/business-technology/how-to-keep-your-online-identity-protected/ How to keep your online identity protected | New York, NY 10022

    [...] Epsilon’s recent data breach was a great example of the possibility of phishing. Their network was hacked into and thousands of names and email addresses were exposed, making thousands of people vulnerable to phishing attempts. [...]

  • http://blog.eset.com/2011/04/04/information-wants-to-be-free-so-epsilon-thinks Information Wants to be Free – So Epsilon Thinks | ESET ThreatBlog

    [...] This is a real concern and the phishing has commenced, but some people are really taking it too far. One report speculates that  “You might, for instance, receive a message from Brookstone about a special offer addressed to… [...]

  • http://danburyit.wordpress.com/2012/05/15/protect-your-online-identity-with-these-suggestions/ Protect Your Online Identity With These Suggestions « DanburyIT – Blog

    [...] recent data breach suffered by Epsilon is a great example of how phishing can occur. The people that hacked Epsilon’s network [...]

  • http://blog.imonsite.net/2011/04/protect-your-online-identity-with-these-tips/ Protect your online identity with these tips | YCSI Blog

    [...] recent data breach suffered by Epsilon is a perfect example of how phishing can occur. The people that hacked Epsilon’s network [...]

  • http://blog.patternbuilders.com/2011/04/05/espsilons-data-breach-be-careful-out-there/ Epsilon’s Data Breach: Be Careful Out There | Big Data Big Analytics

    [...] works for more than 2500 brands and sends more than 40 billion emails a year on their behalf (that’s how they got your [...]

blog comments powered by Disqus