Wiggle data breach
Wiggle data breach
Author
Discussion

lufbramatt

Original Poster:

5,672 posts

163 months

Tuesday 16th June 2020
quotequote all
Apparently wiggle / chain reaction have had a data breach with account details compromised, so worth changing your password....

Your Dad

2,284 posts

212 months

Tuesday 16th June 2020
quotequote all
Data breach, or credential stuffing because people reuse the same passwords?

Harpoon

2,518 posts

243 months

Tuesday 16th June 2020
quotequote all
Your Dad said:
Data breach, or credential stuffing because people reuse the same passwords?
Credential stuffing was my first thought when the rumours started...

TheGinger1

93 posts

93 months

Tuesday 16th June 2020
quotequote all
Credential stuffing due to people using the same password everywhere I believe

Gareth79

9,020 posts

275 months

Wednesday 17th June 2020
quotequote all
It's very common where fraudsters discover a retailer which doesn't have sufficient security in place to prevent such bulk credential testing, and presumably where the saved card can be reused without entering a CVC.

Many large retailers will use publicly available compromised credentials to test against their own customers logins and proactively disable such accounts, although I imagine a retailer of Wiggle/CRCs size would need to use external IT security services to do that (or have very good in-house staff).