Shop for herbs and other supplements on Amazon
Thread Closed

FYI - dnevitamins.com site hacked!

#1

FYI - dnevitamins.com site hacked!
May 31 2008 at 5:51 AM riven_one (Login riven_one)

--------------------------------------------------------------------------------

FYI-

DNE has been recommended here by several users, so I placed an order. Subsequently my credit card number was stolen and was used to purchase various things. I got all of the charges reversed but it created quite a mess, and took a lot of time. I have an e-mail into DNE expressing my displeasure at their business operations; and i'm not for sure if I will ever order from them again. My credit card details are posted quite blatently in a thread on a warez type message board along with dozens of others. For obvious reasons I will not post that link up here. I have reported the crime to the government internet crime people for all of the good that will do.

If you have been the victim of credit card theft and placed an order with DNE between February 27, 2008 to March 2, 2008 then that is how your card # got into circulation.

I received this information in an e-mail from someone else that had been hacked and who sent an e-mail to all of the affected users whose credit card info was in that hacker message thread:

"I contacted DNE this evening to be told that they were aware of the security compromise and that I needed to contact someone named MichelleR@DNEPharm.com. She was not available at the time I called. She can be reached at the email address I just listed or at DNE Customer Service during normal business hours. The number is 1-800-221-1833. I am upset that DNE knew about this, yet failed to contact their customers to let them know. I am certain some sort of legal action can be taken against them if any of you have fraudulent charges on your credit cards"

Riven




Author Reply
Deb
(Login ddover) Re: FYI - dnevitamins.com site hacked! May 31 2008, 11:12 PM


Oh my! I've ordered from them for about 2 years now and have NEVER had a problem. Thanks for letting us know about this because I was getting ready to place another order.

I had the same thing happen to me about a month ago and it was because I used my debit card at TJMaxx. Someone purchased tickets to Uraguay (sp?) for over 800.00. I got the charges reversed, like you, but also like you, it was a big mess and a pain to deal with. TJMaxx is currently in a law suit because they knew their customer database had been hacked and refussed to up the security on it because they fell that they are right where they need to be with their security levels. Yeah right!




Princes Pearl
(no login) Re: FYI - dnevitamins.com site hacked! June 2 2008, 8:11 AM


*cursing*

that must be where my mess started...I had to close and reopen my checking account. Big pain in the butt. I did order from them around the time frame that Riven mentioned.

they sent all kinds of crap to my house as well as tried to buy a tv in another state, a lot of fraud. it is all taken care of now, but it was a real pain with lots of red tape.

Thanks for the heads up as to what happened to you. Now I am sure it was DNE that leaked my number or was hacked like you said, Riven One.


Edit Message Delete Message

waxingmoon
(Login waxingmoon)
SENIOR MEMBER Re: FYI - dnevitamins.com site hacked! June 5 2008, 5:45 PM


I ordered some vitamins from DNE way back in November 2007. My account got attacked in March. I was racking my brains trying to figure out how the thieves got my info since there were no online purchase in 2008 on that account.

Now I know. At least I am pretty sure. The hackers must have been able to go way back into the account histories.

I don't know if I will ever do credit card internet business again. I always assumed the thefts would occur from some breach in my own computer and I have a lot of protection from that. To find out that hackers can get at a business and use data that is months old... that is horrible.

Got all the money back ... eventually... my bank was the one who tipped me off about the theft. So no money lost on my end but man what a nightmare anyway... grrr!

waxingmoon


Edit Message Delete Message

jellyDeeee....
(Login jellyboobs)
SENIOR MEMBER Re: FYI - dnevitamins.com site hacked! June 6 2008, 12:34 AM


Girls/ guys does that site have a security pad lock n????
My husband said you should be safe it it has so Id like to know please love jelly....


Edit Message Delete Message

riven_one
(Login riven_one) Re: FYI - dnevitamins.com site hacked! June 6 2008, 5:09 PM


The "security pad" you see means that the data that is exchanged between your web browser and their web site is encrypted (as it should be for credit card transactions), and I do believe that the dne website uses this encryption. However, once your transaction has been processed then the data from it is stored somewhere on a server which is (in this case) being accessed by hackers due to some kind of missing or lax security, or their web site is susceptible to a "sql injection" kind of attack. One of the cardinal rules of dealing with credit card numbers is that they should always be stored in an encrypted form to guard against a hacker getting ahold of them. Had dne stored the card numbers this way then even if a hacker had gotten the credit card data from the server or from an "sql injection" attack then it would be useless to him. The fact that their server/web site is not secure, and the fact that their credit card numbers are not encrypted when they are stored on a server tells me that whoever built their on line store was not concerned whatsoever about the security of the data. It is possible that their merchant agreement could be revoked if their credit card processor ever finds out about these serious security breaches.


Edit Message Delete Message

jelly
(Login jellyboobs)
SENIOR MEMBER Re: FYI - dnevitamins.com site hacked! June 8 2008, 12:35 PM


WHOOOOOO>>>>>.... scary !!!! thankyou Riven one Im so sorry that happened to you and the others love jelly.....




Wonderpuff
(Login Wonderpuff) Re: FYI - dnevitamins.com site hacked! June 19 2008, 8:18 PM


Wow, I haven't been here forever and was just going to check in and I see this. I have been driving myself crazy about a charge on my card that I didn't make and I couldn't think of how my number might have been compromised. Well guess what? I used this card to place an order to DNE way back in Nov. 2007! I guess that teaches me to shop at sites that I have never heard of before! I was lucky though, I noticed the charge immediately and reported it and had new account numbers issued. What a joke! There are a lot of pathetic people out there who have nothing better going on in their life than to screw with other people. I hope everyone that has had problems with this gets it resolved quickly. I believe in karma and I just smile thinking about the payback these idiots have coming to them. Anyway, good luck to each of you with all your endeavors!
#2

DNEVITAMINS.COM IS A SCAM
May 31 2008 at 7:11 AM Kitty (no login)

--------------------------------------------------------------------------------

**** sorry guys but I am so pissed off right now. I ordered some pills from DNEvitamins.com on the 27th they called me back on the 28th for the card number and **** today my boyfriend looks in his account and we have ****ing 10 dollars left! They bought all sorts of **** like 150 dollar shoes, match.com, pizza hut and all kinds of crap -_- what the hell is this??????????




Author Reply
Jessica
(no login) DNE is a SCAM! May 31 2008, 7:13 AM


The DNE site for sure is a scam -_- I ordered some PO on the 27th they emailed me twice the same day saying my account didnt go through so we called the number provided on the email which is the same as the number on the dne website and we confirmed the order number and the card number. They said it went through. We called them back on the 28th by the way, the following day of the email. Today we get a call from our bank about some purchases and someone has been using our card since the 28th! Buying 150 dollar shoes, pizza hut, and all sort of crap -_- a bunch of purchases made til today! And my order isnt on site or as one of the purchases. I hope they take care of this soon cause we will file charges -_-




riven_one
(Login riven_one) Re: DNEVITAMINS.COM IS A SCAM May 31 2008, 1:07 PM


Their web site got hacked.




Shoe49
(Login Shoe49) Re: DNEVITAMINS.COM IS A SCAM June 1 2008, 1:02 PM


Anyone looking for alternate supply for porcine ovary might consider Bayho: http://www.bayho.com/p/413105.html

I've used them in the past for other supplements and was satisfied with their service and products.


Edit Message Delete Message

Les
(no login) Re: DNEVITAMINS.COM IS A SCAM June 4 2008, 9:06 AM


riven_one can I ask did their website definitely get hacked for sure or is it maybe all some kind of con?


Edit Message Delete Message

riven_one
(Login riven_one) Re: DNEVITAMINS.COM IS A SCAM June 4 2008, 2:19 PM


I have no definite proof but I did receive an e-mail (since our e-mail addresses were posted in the thread on the hacker site along with our credit card numbers, I have a printed copy of that thread) from someone who claimed to also be a victim. Apparently this person had been able to narrow down their own usage of their card and traced it back to a purchase they had made at dne. I also made a purchase at dne on feb 29th, which was in the time period that the e-mail claimed that card numbers had been stolen. The one thread that each of us seem to have in common is a purchase at dne before our cards were used to buy pizza and iphones. Here is the text of the e-mail that i received:

(I have removed personally identifying info)
(if you notice the person sending the e-mail claims that dne acknowledged knowing about the problem)

To All,

I am writing because it seems we have all been hacked. All purchases made on the https://dnevitamins.com/ website from February 27, 2008 to March 2, 2008 were hacked and everyone on this email's personal information (this includes your ADDRESS, FULL NAME, EMAIL ADDRESS, CREDIT CARD USED FOR THE PURCHASE ALONG WITH THE EXPIRATION DATE AND THREE DIGIT SECURITY CODE) is posted on a hacker site.

I am writing everyone because I was made aware of this just today by a good Samaritan who emailed me and let me know. Sure enough I visited the website and had to register as a member to view the forum thread. After much research, I narrowed down the transaction and the site I made the purchase from. I contacted DNE this evening to be told that they were aware of the security compromise and that I needed to contact someone named MichelleR@DNEPharm.com. She was not available at the time I called. She can be reached at the email address I just listed or at DNE Customer Service during normal business hours. The number is 1-800-221-1833. I am upset that DNE knew about this, yet failed to contact their customers to let them know. I am certain some sort of legal action can be taken against them if any of you have fraudulent charges on your credit cards.

In the meantime, all of our information is available for everyone to see. If you have had fraudulent transactions on your cards you probably already know about this. Luckily, my credit card company contacted me to verify a purchase that was not mine and I reported my card stolen. If you have not already, I suggest you call your credit card company used for the transaction and have it declared stolen. Also, contact this "Michelle R" at DNE for an explanation of why they are not protecting their customer's information.

To visit this hacker site to see for yourselves please visit:

(url removed)

You must register, it is free, and go to the above forum. Visit the post: Some Hacked Credit Cards... by Invisible Master

You will see this thread:

Sorry to all admins and to all peoples here... I didn't be on this forum because I got some problems with AIO Forum! I can't load page correctly with mozilla ! But that is no problem at the same time! Now i want to share some credit cards! Don't tell this no work because some of credit cards are declined by BANK!

So lets start! Say THANKS or Reply to see credit cards !

GO TO THE BOTTOM RIGHT AND CLICK THANKS...this reveals all of the credit card information. You may want to print it in case you want to take legal action. I am contacting the authorities as we speak and the local television station as well.

Again, This is not a HOAX email, I am a victim as all of you are. Some may be unaware. I am taking it upon myself to all of you know because someone was kind enough to tell me.

Thank you for your time,

Sincerely,

(name removed)


I did contact the michelle person and got this response:

Dear ****,

Please accept our sincerest apologies for this gross inconvenience. D&E Pharmaceuticals takes credit and personal information security very seriously. All orders placed online through DNEVitamins.com are via a secure server using (GeoTrust) SSL 128-Bit security technology. At no time during the order process is your information viewable to unauthorized personnel. We assure you that we were not aware that your personal information was posted on an illegal website. For your security, we do not even house your online orders on site. We have contacted our internet provider, and steps are being taken as I write to you to ensure our site’s security. Thank you for bringing this important matter to our attention. We hope that this experience will not influence your decision to shop with us in the future.



Wishing you good health,

Michelle Rivera
Account Executive
D&E Pharmaceuticals Inc.
206 Macopin Rd.
Bloomingdale, NJ 07403
1-800-221-1833
973-838-5254 ext-115
fax 973-838-0560
http://www.dnevitamins.com


SSL only protects the data being transmitted back and forth from your web browser, it does nothing for data at rest on a server. Also, the claim about housing order data may be technically true that they don't house it "on site", but it has to be housed somewhere, and I suspect that is where the security breach occurred.

Anyway, that is my .02 on the matter, and we may never know conclusively that it was dne, but dne seems to be the common denominator.

riven


Edit Message Delete Message

riven_one
(Login riven_one) Re: DNEVITAMINS.COM IS A SCAM June 4 2008, 2:24 PM


Also, as far as DNE being a scam I have placed two orders with them and both times received my orders promptly. It was unfortunate that my first order resulted in a credit card theft. I placed a subsequent order before I was aware that they may possibly have an unsecured server, so I am now watching that card very carefully.


Edit Message Delete Message

riven
(Login riven_one) Re: DNEVITAMINS.COM IS A SCAM June 4 2008, 4:29 PM


well, so much for that. my latest cc # has been stolen again. as i said before i placed another order with dne before i found out that dne might be leakig credit card numbers, so i get burned again. coincidence?


Edit Message Delete Message

Les
(no login) Re: DNEVITAMINS.COM IS A SCAM June 8 2008, 7:35 AM


Your report was talking of a problem between 27 Feb and 2 Mar, but the impression I got from the first message in this thread is that the 27th May was referred to, not 27th Feb. Unless I read it wrong?


Edit Message Delete Message

riven_one
(Login riven_one) Re: DNEVITAMINS.COM IS A SCAM June 8 2008, 9:15 AM


I just reposted the e-mail that I received. I have no idea of what the actual exposure dates were. I did make an order to dne on feb 29th, and that CC# was stolen. But as I posted I made a subsequent order to dne several weeks later using a different CC# that was outside of the dates posted and that CC number was stolen again. Coincidence? I dunno.


Edit Message Delete Message

Davilee
(Login Davata) OMG! July 16 2008, 9:34 AM


Wow.....I had no idea what was happening...
I ordered something awhile back....I cant even recall when now...around the first of the year.
I should check this out. I havent had any problems though,although,my card had a odd charge for Itunes in CA...for 100 dollars;but,it was remedied within the same day,it was changed in the statement.
So,wow...Im scared about this now that Ive seen what y'all are writing.

Please believe me....they are a good company,I got my P.O. very quickly and I had no problems,they send me huge glossy catalogs all the time now also....not that that means anything really;but,I'm just tryinmg to make a point that they are legitamate,..albeit irreponsible as heck.
This really sucks.

I hope everyone gets a good resolution to the problem. ^_^

>Davilee
Thread Closed

Shop for herbs and other supplements on Amazon




Users browsing this thread: 1 Guest(s)



Shop for herbs and other supplements on Amazon


Breast Nexus is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.


Cookie Policy   Privacy Policy