Update: Bank customers warned after breach at Epsilon marketing firm
IDG News Service - Citibank, JP Morgan Chase and the Kroger supermarket chain are warning customers that their names and e-mail addresses may have fallen into the wrong hands after someone broke into computer systems at e-mail marketing giant Epsilon.
Epsilon, whose other customers include Visa, Kraft, and Marriott International, acknowledged the incident in a brief statement Friday. "On March 30th, an incident was detected where a subset of Epsilon clients' customer data were exposed by an unauthorized entry into Epsilon's email system," Epsilon said. "The information that was obtained was limited to email addresses and/or customer names only."
Epsilon said it doesn't believe any other personal information was compromised, but it is now working with authorities on an investigation, a company spokeswoman said Friday.
Epsilon only learned of the breach on Wednesday and it is unclear yet how serious the issue is. On Friday, spokespeople for Chase and Epsilon declined to say much beyond their prepared statements.
In a letter to customers, Kroger said customer names and e-mail addresses were stolen. "As a result, it is possible you may receive some spam email messages," Kroger said. "We apologize for any inconvenience. Kroger wants to remind you not to open emails from senders you do not know. Also, Kroger would never ask you to email personal information such as credit card numbers or social security numbers. If you receive such a request, it did not come from Kroger and should be deleted," the letter states.
Epsilon sent 6.5 billion e-mail marketing messages in 2009, but the company also runs loyalty programs for Citi and Chase credit card users, and the kind of information stored in its databases could be extremely valuable to criminals looking to steal banking information in phishing attacks.
Because of the risk of phishing, customers should be sure to check the Email Security Zone at the top-right of Citibank emails to be sure their correct name and the last four digits of their card number appear there, Citibank said Friday.
The information obtained in the breach "was limited to customer name and email addresses of some credit card customers," Citibank said in a statement. "No account information or other information was compromised."
Epsilon told Chase that none of its customers' financial information was compromised, the bank said Friday in a press release.
Kroger has posted a frequently asked questions document about the incident.
Marriott could not immediately be reached for comment.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
Data breaches
- N.J. mayor arrested on hacking, conspiracy charges
- Security researcher urges IT to keep up with SAP patches
- Anonymous claims it hacked a DOJ site
- Banking malware spies on victims by hijacking webcams, microphones, researchers say
- Utah CTO takes fall for data breach
- UNC Charlotte: 350,000 SSNs exposed in decade-long breach
- Twitter says many leaked passwords inaccurate, duplicates
- Hackers blackmail Belgian bank with threats to publish customer data
- Russian cybercriminals earned $4.5 billion in 2011
- Nissan, Under Armor report breaches of employee information


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Business Video Empowers Social Media. Raising employee performance.
- The wisdom of a company resides in the heads of those directly responsible for the non-routine work of the organization. This, coupled with...
- Dynamic Video Collaboration in SharePoint.
- Driven by the adoption of social collaboration tools and video applications for employees, today's SharePoint managers are under more pressure than ever before...
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them. Read this...
- The Shortcut Guide to Protecting Against Web Application Threats Using SSL
- Businesses face an increasingly complex set of threats to their Web applications-from malware and advanced persistent threats (APTs) to disgruntled employees and unintentional...
- Beginners Guide to SSL Certificates
- Whether you are an individual or a company, you should approach online security in the same way that you would approach physical security... All Internet White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Internet Webcasts
