Fun Publications has sent out a message to all Transformers Club members this weekend notifying the members that there was indeed a security breach related to their e-commerce database.
In a written statement sent to members, Brian Savage says that "Fun Publications has determined that there is a security issue with our e-commerce systems."
Citing that members' information submissions assisted in determining the flaw, Mr. Savage also says that the source and the extent of the breach is currently unknown, but that multiple parties are assisting in finding out the source of the breach.
He apologizes for the inconvenience this breach has caused and suggests that members continue to be vigilant on their credit cards and activities on accounts with similar login information (Tformers Community member Robimus Prime says that his PayPal account was also compromised).
Also, consider maybe replacing any cards that may have been used to make a purchase on the club's store within the last year.
We at Tformers appreciate Mr. Savage's announcement here. While Fun Publications was previously not forthcoming, we believe they provided a reasonable explanation why they were not originally willing to do so.
As Mr. Savage says in the released statement, nobody should be out any money in this breach. Keep an eye on your bank statements and credit card transactions by checking once a week to ensure that they are in order.
If not, please contact the respective organization immediately to ensure that everything is resolved as quickly as possible.
FULL STATEMENT
Fun Publications wants to take this opportunity to apologize to all of our members.
After many days of analysis, Fun Publications has determined that there is a security issue with our e-commerce systems. We appreciate all of you who have sent in your details. Your help has allowed us to ferret out several different patterns of fraudulent charges that have appeared on some members' cards (any that have been used over the last year with both the club store and our event registration system).
We have several different internet/networking companies looking into the matter. Unfortunately, as of yet, we have not been able to identify any forcible entry either into our internet service provider's servers or network. This is like chasing a ghost through the wires, as unfortunately, the perpetrator did not leave a trail, foot prints or finger prints.
For those of you who have been affected, we apologize for all of your time this has wasted and any inconvenience it has caused you. We understand your frustration as this same type of fraud has happened to everyone in our office on our personal credit cards at some point in the past. Our merchant services provider wants us to remind everyone that even though this can be a huge annoyance for you, the customer, your issuing bank will not hold you responsible for any fraudulent charges that might be placed on your card(s).
We know that this issue has been a huge topic of discussion on all of the boards for the past few weeks. However, we are required to investigate to determine and confirm a security issue thoroughly before making any public statements. This is why we put out a general alert statement two weeks ago.
Until the analysis is finished (can take several weeks) we don't know if the shut down by our former (Jan 31st) e-commerce provider caused the security issue or not. We do know that it has not been limited to those who have purchased before the change to our new provider.
Please, watch your cards closely as this type of security issue appears to be on the increase across the net. No site is 100% safe. You may want to consider having any cards you have used with Fun Publications in the last year replaced.
At this time, we do not know how long our e-commerce site will be offline for both the store and registrations. We will get back to you once we have a solution for this security issue.
Thanks for your support - Brian