Wiggle data breach

Author
Discussion

lufbramatt

Original Poster:

5,421 posts

140 months

Tuesday 16th June 2020
quotequote all
Apparently wiggle / chain reaction have had a data breach with account details compromised, so worth changing your password....

Your Dad

1,995 posts

189 months

Tuesday 16th June 2020
quotequote all
Data breach, or credential stuffing because people reuse the same passwords?

Harpoon

1,946 posts

220 months

Tuesday 16th June 2020
quotequote all
Your Dad said:
Data breach, or credential stuffing because people reuse the same passwords?
Credential stuffing was my first thought when the rumours started...

TheGinger1

72 posts

70 months

Tuesday 16th June 2020
quotequote all
Credential stuffing due to people using the same password everywhere I believe

Gareth79

7,975 posts

252 months

Wednesday 17th June 2020
quotequote all
It's very common where fraudsters discover a retailer which doesn't have sufficient security in place to prevent such bulk credential testing, and presumably where the saved card can be reused without entering a CVC.

Many large retailers will use publicly available compromised credentials to test against their own customers logins and proactively disable such accounts, although I imagine a retailer of Wiggle/CRCs size would need to use external IT security services to do that (or have very good in-house staff).