Page 1 of 12 12345678911 ... LastLast
Results 1 to 10 of 111

Thread: Login database at your store hacked?

  1. #1
    Member
    Join Date
    Apr 2004
    Posts
    65

    Login database at your store hacked?

    Hi,

    Curious if I need to do anything?

    I use Avast antivirus and I just got an email that said "we’ve just found your password in a database of leaked login details. "

    It says:

    Canadaammo.com
    77,468 accounts affected
    At an unknown date, the Canadian gun and knife site Canada Ammo was allegedly breached. The stolen data contains usernames, passwords, email addresses, IP addresses, and additional personal information. This breach is being privately shared on the internet.

  2. #2
    CGN frequent flyer JaysonCraig's Avatar
    Join Date
    Jan 2007
    Location
    Vancouver
    Posts
    1,273
    idk how passwords could be stolen unless a 10 year old made the database. its pretty common to hash passwords so they never get stored, and only compared with another hash. but i have seen plain text passwords stored so its possible

  3. #3
    GunNutz Painkillers's Avatar
    Join Date
    Jan 2022
    Posts
    3,751
    Jeezus Chrisp.

    Yes you do need to do something. Assume "they" have your cc number, your address and email...perhaps phone number as well? That's more than enough to make another "you".

    Dump your cc, change all passwords and curse Canada Ammo for not informing us.
    “Victorious warriors win first and then go to war, while defeated warriors go to war first and then seek to win.” Sun Tzu, Art of War 475-221 B.C.

  4. #4
    Newbie
    Join Date
    Dec 2021
    Posts
    18
    Quote Originally Posted by JaysonCraig View Post
    idk how passwords could be stolen unless a 10 year old made the database. its pretty common to hash passwords so they never get stored, and only compared with another hash. but i have seen plain text passwords stored so its possible
    I just came across a homebrew system that was made by a guy who learned to code with no formal computer science training. His system does not hash passwords or sanitize for SQL injection, but was sold to a bunch of non-profits because that's all they wanted to pay. One even contains people's SIN.

    I also have a client and various suppliers that still take credit card numbers over the phone. And I know one of them puts them in a spreadsheet to be sent off to their accountant.

    Not that I have any data to support this, but I'm convinced that for the most of us, some criminal somewhere already has our credit card info.

  5. #5
    CGN Ultra frequent flyer Ipscshooters's Avatar
    Join Date
    Jan 2021
    Location
    OKANAGAN
    Posts
    2,600
    Thanks for sharing with us OP , geez I ordered from them during their Halloween sale , I don't recall if I have made and account with them or not.

    I have about 35 different services who direct bill to my CC, it is such a pain in the rear to get a new card and contact all my services and change the CC billing info ( literally a full 8 hour day ) ill take my chances, CC will always re imburse fraudulent charges anyways.

    Will be waiting for CanadaAmmo to chime in

  6. #6
    Member Brucy's Avatar
    Join Date
    Mar 2011
    Location
    Nova Scotia
    Posts
    57
    I got the same warning from Avast. For anyone curious, here it is.


  7. #7
    Super GunNutz NeonGreen's Avatar
    Join Date
    May 2014
    Location
    Ontario
    Posts
    4,015
    Im not very knowledgeable when it comes to tech but if peoples home addresses were also compromised couldn't this be used by criminals to target homes for theft?
    “... and they who cried: “Appease, Appease!” are hanged by men they tried to please.”

  8. #8
    Uber Super GunNutz 45CAT's Avatar
    Join Date
    Mar 2017
    Location
    Ontario Canada
    Posts
    1,910
    Quote Originally Posted by Painkillers View Post
    Jeezus Chrisp.

    Yes you do need to do something. Assume "they" have your cc number, your address and email...perhaps phone number as well? That's more than enough to make another "you".

    Dump your cc, change all passwords and curse Canada Ammo for not informing us.
    Just checked my account to change password. They do have my old credit card # on file

  9. #9
    Newbie
    Join Date
    Aug 2018
    Location
    Markham
    Posts
    12
    the attacker will use the same credential on other common site, better change the password on all of them.

  10. #10
    Member Brucy's Avatar
    Join Date
    Mar 2011
    Location
    Nova Scotia
    Posts
    57
    Quote Originally Posted by NeonGreen View Post
    Im not very knowledgeable when it comes to tech but if peoples home addresses were also compromised couldn't this be used by criminals to target homes for theft?
    Absolutely. Also I believe PAL numbers were stored in the account as well for purchasing firearms and ammo.

Page 1 of 12 12345678911 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •