The website got hacked. What now?
May 30, 2008 8:57 AM
Subscribe
A website I programmed got hacked. Credit card numbers were compromised. What do I do now?
I found the security hole and plugged it up, but at least one or two credit cards have already been stolen. There are a few hundred orders (less than 300) in the system. According to the error logs there were hits to the backend from the UK and Africa.
Obviously, I will recommend that all of the customers be notified. I don't suppose there's any way to do this in a classy manner that won't make our client look bad.
The worst of all is that the client will obviously suffer -- who knows how many of their customers will stop buying from them -- when it was not their fault. I feel like there is nothing I can do to resolve this problem...it's like a nightmare I can't wake up from. Please, please help.
posted by anonymous to computers & internet (22 comments total)
7 users marked this as a favorite
2. Offer to modify the site to use standard practices (encryption or last 4 digits only) for a very reduced rate.
posted by hitopshelf at 9:05 AM on May 30, 2008