News: 1592323210

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

No Wiggle room: Two weeks after angry bike shop customers report mystery orders on their accounts, firm confirms payment cards delinked

(2020/06/16)


Updated Brit cycling equipment shop Wiggle confirmed to The Reg today it was delinking customers' payment cards from their accounts, two weeks after first receiving complaints that orders were appearing on customers' accounts that they had not made themselves.

Ross Clemmow, CEO at Wiggle, told The Reg : "[W]e understand a small number of customers' login details have been acquired outside of Wiggle's systems and some have been used to gain access to Wiggle accounts and purchases made."

"We have taken steps to identify these compromised accounts and we will be individually contacting these customers. All impacted customers will be refunded.

"To protect our customers, all accounts will require the re-entry of card details for the next purchase."

He went on to say that credential-stuffing crooks who'd obtained nicked login details (and ostensibly, reused passwords) via other methods had used them to "gain access to genuine customer accounts" - adding that the firm "recommended our customers change their password if they have any concerns".

He did not explain why Wiggle had seemingly kept silent on the issue for days nor why it seemingly had taken so long to take remedial action.

A Twitter user called Omid told The Reg [1]earlier today : "Various people have had money stolen and Wiggle are not responding, or are dragging their heels."

Over the past few days, Wiggle appeared to be asking users to contact it via direct message. An operator of the firm's Twitter account told a user today at [2]15.28 BST : "Our systems remain secure but we're investigating currently. Additional security is in place and account issues have been prioritised. DM your information ASAP and we'll respond urgently. Apologies."

Customers first began making the apparently fraudulent orders public as far back as [3]2 June , with [4]irate cyclists complaining both that mysterious orders were appearing in their accounts and that their account credentials had been changed without their knowledge.

[5]@Wiggle_Sport My account has been hacked and an order for £72 spent on my debit card. I've logged it via your contact form but wonder if you can deal with it quicker than the 4-6days stated as the order is to be delivered to the fraudster tomorrow!Seems unfair he gets the jacket! — Miss Lang (@Miss_Lang_BMA) [6]June 2, 2020

Hey [7]@Wiggle_Sport , some naughty fraudster has been in my Wiggle account and ordered a bunch of stuff. I tried to cancel the orders within 10 mins of them being placed but apparently it's already too late even though you've not processed them yet. — Gavin (@MisterOnions) [8]June 10, 2020

In an incautious Twitter reply to one affected punter, Wiggle noted:

Hi Kobi. There is nobody from Customer Services monitoring Twitter posts so I have forwarded this and asked them to get back in touch. — Wiggle (@Wiggle_Sport) [9]June 15, 2020

The corporate Twitter account has since begun replying to customers' Twitter enquiries, albeit with a copy-pasted message promising someone will be in touch.

Road magazine was [10]first to reveal that the retailer, which sells everything from expensive figure-hugging bodysuits to specialised road bicycles and aerodynamically sculptured helmets, had apparently "fallen victim to a cyber security breach."

Placing orders and changing address details in an online account requires a successful login - and the credential-stuffing explanation is a plausible one - but it raises some questions. We have asked Wiggle about the speed of its security incident response and its lack of public comment up to this point.

Informed readers will also be raising questions about things like rate-limiting logins and enforced password changes.

Wiggle will be required to report the incident to the Information Commissioner's Office within 72 hours of becoming aware of it. As [11]Uber previously found out , credential stuffing attacks are also a notifiable data protection incident. The Register has asked the UK watchdog whether Wiggle has done so. ®

Updated at 17:52 BST to add

Wiggle has been in touch to tell us: "It has been in the last 24 hours where Wiggle has seen a small but still significant spike in alerts by customers and has devoted additional resources to responding to these inquires and introduced additional steps, such as delinking payment cards, as a precaution. As mentioned Wiggle is also recommending customers update their passwords for further protection. Wiggle is also currently working with the ICO and following their guidance."

Sponsored: [12]The Service Mesh Era: Architecting, Securing and Managing Microservices with Istio



[1] https://twitter.com/omidpyc/status/1272862097190400000

[2] https://twitter.com/Wiggle_Sport/status/1272898945107271682

[3] https://twitter.com/Miss_Lang_BMA/status/1267904162441965569

[4] https://twitter.com/MisterOnions/status/1270734498875965441

[5] https://twitter.com/Wiggle_Sport?ref_src=twsrc%5Etfw

[6] https://twitter.com/Miss_Lang_BMA/status/1267904162441965569?ref_src=twsrc%5Etfw

[7] https://twitter.com/Wiggle_Sport?ref_src=twsrc%5Etfw

[8] https://twitter.com/MisterOnions/status/1270734498875965441?ref_src=twsrc%5Etfw

[9] https://twitter.com/Wiggle_Sport/status/1272426462549807105?ref_src=twsrc%5Etfw

[10] https://road.cc/content/news/wiggle-investigating-suspected-cyber-attack-274553

[11] https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2018/11/ico-fines-uber-385-000-over-data-protection-failings/#:~:text=The%20ICO%20investigation%20found%20'credential,access%20to%20Uber's%20data%20storage.

[12] https://go.theregister.com/tl/1956/-8476/the-service-mesh-era-architecting-securing-and-managing-microservices-with-istio?td=wptl1956

There is no breach

Pascal Monett

There's just idiots with money who reuse their password.

They are now learning the hard way that that is something you do not do.

Re: There is no breach

Stuart 22

The bigger issue is allowing a retailer to store card details so you can cut 3 nanoseconds off placing your order or having to hunt for the last pocket/wallet you *think* you left the real card in.

I'm surprised a few retailers do have my credit card details ready despite not wanting them stored. Whether it's because the checkbox was well hidden or I checked when I meant not too (or t'other way round) I've no idea. But it would be good if GDPR could force them to make you go through a few more hoops if you really, really wanted this facility.

Chris G

That Lycra suit cost almost as much as my mountain bike did a few years back, I find a normal pair of shorts and a teeshirt adequate for a bit of off road pedaling, never fancied becoming a Lycranthropist.

At Chris G, re: Lycranthropist.

Shadow Systems

Please enjoy a pint with my compliments for making me think of "Lycranthropy" as a form of affliction for cyclists.

Instead of turning into furry beasts with fangs & claws & bad breath, they gain slick skin, skid marks up their backsides, & *really* bad breath.

=-)P

Re: At Chris G, re: Lycranthropist.

Chris G

You are welcome, although I do realise that due to the current sensitivity to words, I may offend a few werewolves.

If that happens I will try to placate them with a steak through the heart.

Re: At Chris G, re: Lycranthropist.

Joe W

You have never ridden more than 100km, nor in the rain, I guess. I used to wear lycra shorts because they dry quickly for the commute back, and on longer rides the stuff does not chafe. So do I think I look good in that stuff? Hell, no! Would I wear it off the bike? No.

Warm Braw

If you had an aerodynamically sculptured helmet, though, a figure-hugging bodysuit would allow its novelty to be better appreciated.

Not Wiggle's fault?

Phil S

I forgot I had a Wiggle account, but my bank sent me a message last night with an authorisation code for £111.73 (oddly specific price, but whatever) for some trainers from them.

I went to the site and saw the trainers in my basket, a new delivery address (I'm assuming DE in US is Delaware?), and new phone number registered. Changed password to boot them out, took some screenshots and checked all was ok. Luckily it was.

Going through a password check, for some reason I had Wiggle as the only site with card details using a burner password I use for sites I need to login to see something as a one-off (read a pdf, get a whitepaper etc).

I did know that list had been compromised thanks to the lovely chap at HaveIBeenPwned, but when I'd looked through the 80+ sites it was used for, I missed Wiggle (probably due to being in alphabetic order, and my own lack of concentration).

Totally my own fault, and wouldn't have blamed Wiggle at all if it got through, but, thankfully I've got the authentication for payments set up which caught it.

Most annoying thing was trying to report it to "someone" in case others had been as daft as me. Action Fraud site had categories that this didn't fit into, bank aren't answering phones (and they did their bit), and as far as I was concerned, Wiggle hadn't done anything wrong.

I got away with it, no thanks to my own laxness at some point, but thankfully it's not been as expensive reminder for me. As a self-punishment I'm making myself change the other non-card-linked passwords, so that'll be a fun weekend!

IRQ-problems with the Un-Interruptable-Power-Supply