Big Picture Big Sound

Vudu May Want to Hire Better Security After Major Break-in

By Ian White

Yesterday afternoon, a rather disturbing email showed up from movie steaming service, Vudu, that made us run to our computers to immediately reset our passwords. Apparently, some brazen criminals decided to physically break into Vudu's Santa Clara-based head office and steal hard drives filled with customers' personal information.

We've almost become used to cybercrime where hackers break through firewalls and steal our credit card information with the click of the mouse, but an old fashioned robbery where the thieves, apparently, knew where to find the server room and take specific hard drives loaded with all of our personal account information? Inside job?

One good piece of news is that Vudu only stores the last four digits of your credit card, so the enterprising criminals have some work to do before going shopping.

We were almost impressed with Vudu's responsible email that assured customers that steps were being taken to ensure the safety of your money - until we found out that the robbery took place on March 24th.

650-vudu-logo-650x0.jpg
Why it took Vudu two weeks to notify millions of potential victims of identity theft that their personal information was stolen is not only perplexing, but suspicious.

Vudu, which is owned by WalMart, did take steps according to their press release to block your old password, but why didn't the email go out sooner when they knew the extent of the break-in?

Vudu's official confirmation of the break-in is on their website, and their official statement on the matter follows:

On March 24, 2013, there was a break in at the VUDU office and a number of items were stolen, including hard drives. These hard drives contained customer data including names, email addresses, mailing addresses, account activity, dates of birth, and encrypted passwords, but NO full credit card numbers. We are proactively retiring and resetting all passwords and notifying all customers. As another level of protection for customers we are also providing AllClear ID identity protection services. We reported the theft to law enforcement immediately, and are cooperating fully with their investigation.

One security item to think about is - do you use the same password for your Vudu account elsewhere on the internet?

If you do, now would be the time to change those other accounts. Right now.

What did you think?

View all articles by Ian White
Big News
Newsletter Sign-up
 
Connect with Us