E90Post
 


Extreme Powerhouse
 
BMW 3-Series (E90 E92) Forum > E90/E92/E93 Marketplace (For Sale / Trade / Wanted) > Vendor Comments/Review/Feedback Forum > GetBMWParts aka Tischer Internet Parts Security Breach



Reply
 
Thread Tools Search this Thread
      07-10-2014, 12:17 PM   #1
Augster
Master Gunner
78
Rep
435
Posts

Drives: 2008 335i Sport
Join Date: Aug 2013
Location: Sandy Eggo

iTrader: (0)

Garage List
Angry GetBMWParts aka Tischer Internet Parts Security Breach

Anyone else get a letter from MileOne Automotive?

First I had my personal data and credit card info stolen off of Target's databases which my bank discovered illegal charge attempts against my account, just before the huge data theft made headline news nation/world-wide.

Now I get a notice from GetBMWParts that their website sales vendor, TradeMotion, just had a "Security Breach" wherein customer credit card information was stolen.

I'm getting pissed off with retail/online vendors in their apparently insufficient protection of our personal credit information.

This is only going to get worse unless significant changes are made to electronic payment methods, such as the proposal to incorporate smart chips into credit cards.
__________________
2008 335i Alpine White Sport Sedan AT | Avant Garde M364 Staggered 19"
Appreciate 0
      07-10-2014, 12:19 PM   #2
bimmerdavid
Lieutenant
bimmerdavid's Avatar
United_States
25
Rep
432
Posts

Drives: 2017 BMW M3
Join Date: Mar 2013
Location: Sherwood, OR

iTrader: (1)

Garage List
2009 BMW 135i  [0.00]
2017 BMW M3  [0.00]
Yep, got the same thing!
__________________
2017 M3 - Long Beach Blue, Competition Package, Burger Performance Intake
2009 135i - Dinan CAI, Dinan Exhaust, Turbonetics FMIC, Dinan Stage 2
Appreciate 0
      07-10-2014, 12:38 PM   #3
JS82
Captain
JS82's Avatar
United_States
31
Rep
659
Posts

Drives: '08 E92 328i 6MT Jet Black
Join Date: May 2010
Location: PA USA

iTrader: (12)

I got the same letter.
Had to get a new card because illegal charges were made against my account because of that.
Really annoying!!!!!!!!
Appreciate 0
      07-10-2014, 12:43 PM   #4
NightStalker
NightStalker's Avatar
275
Rep
2,741
Posts

Drives: Audi
Join Date: Nov 2008
Location: New York City

iTrader: (12)

I usually order from "the bmw part store" never had problems like this with them
Appreciate 0
      07-10-2014, 01:11 PM   #5
John 070
Lieutenant General
1751
Rep
14,825
Posts

Drives: 335i cpe
Join Date: Oct 2006
Location: ZSP/ZPP/ZCW

iTrader: (0)

Don't you love when a health care (PPO or HMO) loses all member information (like 300,000+) because someone at a health fair had it on a thumb drive, lost it, and couldn't find it? All kidding aside since HIPPA you don't hear of that happening as much. But these eTailers are free to do what they want, and likely farm out their IT work to insecure and possibly shady vendors.
Appreciate 0
      07-10-2014, 01:16 PM   #6
iturbo_bmw
Major
iturbo_bmw's Avatar
United_States
94
Rep
1,101
Posts

Drives: 335i, 530i
Join Date: Oct 2012
Location: San Jose

iTrader: (0)

hhm i didn't get a letter yet... but wells fargo did send me a credit card with a chip in it after the target thing...
Appreciate 0
      07-10-2014, 01:34 PM   #7
Zach1328
First Lieutenant
39
Rep
315
Posts

Drives: 2008 535i / 2007 335i
Join Date: May 2014
Location: United States

iTrader: (0)

Quote:
Originally Posted by John 070 View Post
Don't you love when a health care (PPO or HMO) loses all member information (like 300,000+) because someone at a health fair had it on a thumb drive, lost it, and couldn't find it? All kidding aside since HIPPA you don't hear of that happening as much. But these eTailers are free to do what they want, and likely farm out their IT work to insecure and possibly shady vendors.
IT work could be a part of it, but not even vendors can see their customers credit card info if they're using PayPal. On my E-Commerce site I don't accept orders over the phone for this very reason. Online payments only - all secured by PayPal.

An IT worker would still need to hack the cipher text which can't be understood by individuals, so a computer would need to format it into understandable information.

Anyways, GetBMWParts only uses a 128-bit encryption which is significantly less protective than a 256-bit encryption used by companies like PayPal. A 128-bit can be cracked in less than 1/4 of the time it takes to crack a 256-bit.
__________________
07 335i
Mods: JB4 + MHD BEF, RB Twos Plus, Phoenix PI Manifold, Dual Walbro 450 LPFP's, DCI, VRSF DP's, VRSF 7.5" FMIC, VRSF CP + TiAL BOV, VRSF inlets & aluminum outlets, TC Kline SA, M3 F/R control arms, M3 subframe bushings
Appreciate 0
      07-10-2014, 01:46 PM   #8
Zach1328
First Lieutenant
39
Rep
315
Posts

Drives: 2008 535i / 2007 335i
Join Date: May 2014
Location: United States

iTrader: (0)

Wow. I'm surprised how outdated their security is.

They are using TLS 1.0 which came out in 1999! That's 15 years ago!!!
A security system developed in 1999 simply can't match a hacker with the technology available today.
__________________
07 335i
Mods: JB4 + MHD BEF, RB Twos Plus, Phoenix PI Manifold, Dual Walbro 450 LPFP's, DCI, VRSF DP's, VRSF 7.5" FMIC, VRSF CP + TiAL BOV, VRSF inlets & aluminum outlets, TC Kline SA, M3 F/R control arms, M3 subframe bushings
Appreciate 0
      07-10-2014, 01:59 PM   #9
Ilove2dubb
Lieutenant
39
Rep
487
Posts

Drives: E46 ///M3
Join Date: Oct 2013
Location: Montreal

iTrader: (1)

I also received it yesterday and I'm in Canada. I checked my credit card account and I do see charges which appear to be fraudulent.
Appreciate 0
      07-10-2014, 02:12 PM   #10
Johnny Boost
Colonel
No_Country
326
Rep
2,016
Posts

Drives: '21 M850i GC
Join Date: May 2013
Location: TBD

iTrader: (0)

There's nothing you can really do about it except pay in cash from now on in retail stores.
__________________
WedgePerformance E40 MHD | Performance Exhaust Mod | BMS DP | Vibrant 1790 | BMS Intake | VRSF CP | xHP Stage 3
Michelin PSS | M3 Control Arms
LUX v4 LEDs | Shadowline Grills | Lip Spoiler
Appreciate 0
      07-10-2014, 02:30 PM   #11
ken1137
Brigadier General
ken1137's Avatar
United_States
92
Rep
3,731
Posts

Drives: BMW S1000XR
Join Date: Jun 2011
Location: Gilbert, AZ

iTrader: (7)

Garage List
2009 e90 335i  [6.40]
Yeah, I received notification trade in motion but have not seen any illegal purchases.

I am all for a smart chip as long as it is not RFID (constant radio signal emitted). Thats another manner in which your personal data can be obtained by someone close or next to you if they have the appropriate equipment.
__________________

BMWCCA member
Appreciate 0
      07-10-2014, 03:05 PM   #12
alexwhittemore
Lieutenant Colonel
118
Rep
1,951
Posts

Drives: 2009 Crimson 328i
Join Date: Oct 2012
Location: Los Angeles

iTrader: (0)

You'd be scared shitless just how secondary the concerns of security and privacy are on the internet. You'd be scared slightly-less-shitless at the proportion that's willful ignorance and development cost savings vs ineptitude. http://stilldrinking.org/programming-sucks
__________________
Appreciate 0
      07-10-2014, 03:06 PM   #13
fravel
Colonel
fravel's Avatar
United_States
1648
Rep
2,494
Posts

Drives: Monaco Blue '06 330i
Join Date: Aug 2012
Location: The Nasti 'Nati

iTrader: (1)

Got the letter, haven't seen anything fraudulent yet though.
Appreciate 0
      07-10-2014, 03:44 PM   #14
getBMWparts
getBMWparts's Avatar
735
Rep
12,478
Posts

Drives: BMW Parts
Join Date: Jul 2007
Location: Silver Spring, MD

iTrader: (16)

Dear valued getBMWparts.com customers and forum members,

Regarding the security breach notice our Corporation - MileOne Automotive recently sent only to customers recognized as potentially at risk - we can certainly understand your questions and frustration. As stated in the notification letter, however, the security incident did not occur on MileOne's systems or on our GetBMWParts.com or SubaruPartsDepot.com websites. Rather, the incident originated at one of our third party vendors, TradeMotion. TradeMotion is an e-commerce service provider that we, and hundreds of other online retailers (including other vendors on these forums), use to process online transactions including payment processing. Nonetheless, we recognize that you purchased one or more of our products and we take the privacy and security of our customers extremely seriously. That is why, despite the fact the incident did not originate with our systems, we took proactive steps to help you minimize potential harm from the incident.

As to any concerns regarding the timing of the incident and the notification, the dates identified in the letter reflect the period of time that TradeMotion has determined account information was vulnerable to unauthorized acquisition. The March 5, 2014 date is not the date when the security incident was discovered. Rather, it is the beginning of the security breach period which was determined after the breach was discovered and TradeMotion completed its investigation. The notice was provided only to customers identified as potentially at risk after TradeMotion completed its investigation, including the following:
  • Notifying the appropriate law enforcement authorities;
  • Investigating to determine the cause and scope of the breach;
  • Investigating to determine which businesses' customer information was affected (because TradeMotion is a service provider for more than just GetBMWParts.com and SubaruPartsDepot.com);
  • Implementing corrective action to secure the system to protect customer information from further compromise; and,
  • Identifying the affected customers and the customer information that may have been compromised.

We continue to encourage you to take advantage of the complementary ProtectMyID program being offered through the notice. In addition to the ProtectMyID program, you are also encouraged to consider the "Additional Actions" described in the notice, including:
  • Placing a fraud alert on the your consumer reporting agency file;
  • Placing a security freeze on your consumer reporting agency file;
  • Obtaining a copy of your free annual credit report from reporting agencies and reviewing it carefully for any discrepancies;
  • Reviewing account statements carefully for signs of unauthorized transactions; and,
  • Reviewing the FTC's identify theft website for additional information.
Should you have any additional questions or comments regarding this matter, please do not hesitate to contact us at getHelp@getBMWparts.com - further questions will not be answered here.

Sincerely,

getBMWparts.com
MileOne Automotive
Email: getHelp@getBMWparts.com
Appreciate 0
      07-10-2014, 04:27 PM   #15
FitzMLife
Second Lieutenant
FitzMLife's Avatar
31
Rep
257
Posts

Drives: 2021 Hockenheim Silver M2C
Join Date: Oct 2012
Location: WA

iTrader: (0)

Garage List
2021 BMW M2C  [0.00]
I had several fraudulent charges back in March/April, this explains a lot.
Appreciate 0
      07-10-2014, 11:01 PM   #16
roadkillrob
Major General
896
Rep
5,476
Posts

Drives: 08 335i,22 X3M, 2012 C63 Black
Join Date: Jul 2007
Location: NH

iTrader: (15)

Quote:
Originally Posted by Fitz335 View Post
I had several fraudulent charges back in March/April, this explains a lot.
Me too, Amex had to reissue my card in April!
__________________
2025 X5 Msport
2008 E93 335i FBO
2012 Mercedes C63 Black Series Alanite Grey
Appreciate 0
      07-10-2014, 11:26 PM   #17
007_e350
Lieutenant Colonel
007_e350's Avatar
United_States
230
Rep
1,909
Posts

Drives: 335i 2008 MHD'd / x5d E70
Join Date: May 2013
Location: left lane

iTrader: (3)

Shouldn't affect PayPal right?? I paid them thru that
Appreciate 0
      07-11-2014, 12:23 AM   #18
nccoupe
Private First Class
8
Rep
172
Posts

Drives: 15 LSB M5
Join Date: Aug 2012
Location: Asheville, nc

iTrader: (0)

thought it was something local, got a call from my bank's fraud department that someone in Illinois had purchased $2600 in pizzas, shopping stuff (pier one, vicki's secret, gap) and was happy they caught it.... 4 days later i got a letter.... little bastards.

any way of getting a large discount on part for my troubles? jk
Appreciate 0
      07-12-2014, 01:51 AM   #19
iameric
New Member
0
Rep
12
Posts

Drives: Lexus IS 250 Manual - totalled
Join Date: Apr 2013
Location: United States

iTrader: (0)

These things do happen unfortunately just be glad they disclosed it. I'm a project manager for an $8MM a year ecommerce company and during an audit we identified an unknown file on our server which was saving credit card information and being retrieved every few days. The source of the problem was a vulnerability in the ecommerce platform. Of course we told our customers effected and informed the authorities. The FBI got involved and we gave them complete access so they could run their own audits.

Attacks like this assuming it wasn't negligent are ultimately very hard to protect against 100% of the time. If there's a will there's a way.
Appreciate 0
      07-12-2014, 12:06 PM   #20
moonsin
First Lieutenant
moonsin's Avatar
32
Rep
345
Posts

Drives: 2021 X3 MC
Join Date: Feb 2012
Location: NJ

iTrader: (1)

I also received this letter few days ago....This may explain the false charges on my account back in May
Appreciate 0
      07-12-2014, 12:17 PM   #21
Augster
Master Gunner
78
Rep
435
Posts

Drives: 2008 335i Sport
Join Date: Aug 2013
Location: Sandy Eggo

iTrader: (0)

Garage List
Quote:
Originally Posted by Jason@Tischer View Post
As stated in the notification letter, however, the security incident did not occur on MileOne's systems or on our GetBMWParts.com or SubaruPartsDepot.com websites. Rather, the incident originated at one of our third party vendors, TradeMotion. TradeMotion is an e-commerce service provider that we, and hundreds of other online retailers (including other vendors on these forums), use to process online transactions including payment processing. Nonetheless, we recognize that you purchased one or more of our products and we take the privacy and security of our customers extremely seriously. That is why, despite the fact the incident did not originate with our systems, we took proactive steps to help you minimize potential harm from the incident.
Where the breach occurred is irrelevant nor how many commercial companies may be served by this "third party": GetBMWParts aka Tischer Internet Sales knowingly and deliberately contracted with this company to provide it's online transaction processing and customer information handling, therefore, is just as culpable in the insecurity of our personal information. Simply deflecting blame as being a "third party" problem is typical and pure equine excrement "damage control."

If the information posted from other members regarding the use of older and/or lesser security technology by this "third party" is true, then GetBMWParts aka Tischer Internet Sales is even more culpable because they did not do proper due diligence nor vetting of TradeMotion to ensure it truly can provide the necessary safeguards to protect private and privileged customer information.
__________________
2008 335i Alpine White Sport Sedan AT | Avant Garde M364 Staggered 19"
Appreciate 0
      07-12-2014, 12:32 PM   #22
FlowState
///M Driver
FlowState's Avatar
112
Rep
1,973
Posts

Drives: 07 JB E90 335, 20 TRM F97 X3M
Join Date: Jan 2011
Location: Chicago, IL

iTrader: (4)

I got the letter too. Actually had two rounds of fraudulent purchases from some 3rd party vendor in Early May. Had to get a new card and all.

Definitely makes me not want to purchase from them again..
__________________

| 07 Jet Black 335 - N54 Single Turbo | 20 Toronto Red X3M |
Appreciate 0
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 07:10 AM.




e90post
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
1Addicts.com, BIMMERPOST.com, E90Post.com, F30Post.com, M3Post.com, ZPost.com, 5Post.com, 6Post.com, 7Post.com, XBimmers.com logo and trademark are properties of BIMMERPOST