BookaTrack Scam
BookaTrack Scam
Author
Discussion

996TT_STEVO

Original Poster:

4,078 posts

250 months

Monday 6th April 2015
quotequote all
Anyone else receive email and text today from both BookaTrack and the Scammers?

I'm concerned as the text clearly mentioned my name and username, so they obviously have details

AdiT

1,025 posts

179 months

Monday 6th April 2015
quotequote all
I got the e-mail but not the text... unless that was the one sent to my landline from an unknown number. Deleted the text without listening to it and read then deleted the e-mail. I'm surprised Jonny hasn't been on here posting anything about it.

AndyDubbya

985 posts

306 months

Monday 6th April 2015
quotequote all
I got a text from a random number, the link took me to a page with all my details on it, but asked for mother's maiden name, credit card numbers etc, which rang alarm bells. Got a warning text from the real BaT 2 hours later, saying it was a scam, email to follow, but no email yet. Guess their database has been hacked.

shim

2,050 posts

230 months

Monday 6th April 2015
quotequote all
i got the text which is weird coz i am banned form BaT trackdays it seems

got a text straight after from BaT saying it was a scam.

996TT_STEVO

Original Poster:

4,078 posts

250 months

Monday 6th April 2015
quotequote all
Yeah, worrying as (like most) details/passwords are used on a lot of web pages... I just wonder how much info has been obtained by scammers

Silent1

19,761 posts

257 months

Monday 6th April 2015
quotequote all
Sounds to me like BaT have been hacked, change any passwords you use that are the same and probably get your cards changed as it sounds to me like they've done nothing to secure any of your details pre hacking rolleyes

996TT_STEVO

Original Poster:

4,078 posts

250 months

Monday 6th April 2015
quotequote all
Silent1 said:
Sounds to me like BaT have been hacked, change any passwords you use that are the same and probably get your cards changed as it sounds to me like they've done nothing to secure any of your details pre hacking rolleyes
a LOT of pages whistle

UKAutospark

30 posts

174 months

Monday 6th April 2015
quotequote all
I got the first text, and suspected a scam, I checked online on BATs website. A message box from Jonny popped up so I asked the question and was informed it was a scam. 5 mins later I got the warning from BAT.

roddo

584 posts

217 months

Monday 6th April 2015
quotequote all
I got the text from BAT before I got the text from the scammers

jonnyleroux

1,511 posts

282 months

Monday 6th April 2015
quotequote all
Safe to say that was one of the most stressful days of my life so far. 12 hours of solid emails and live-chat and still got a full inbox to face tomorrow.

Posted an update to our website for anyone who's interested/affected:- http://www.bookatrack.com/blog/view/89

Jonny

censored
Sorry but sigs not allowed.

Edited by Big Al. on Friday 15th May 22:22

Silent1

19,761 posts

257 months

Tuesday 7th April 2015
quotequote all
jonnyleroux said:
Safe to say that was one of the most stressful days of my life so far. 12 hours of solid emails and live-chat and still got a full inbox to face tomorrow.

Posted an update to our website for anyone who's interested/affected:- http://www.bookatrack.com/blog/view/89

Jonny
BaT
Why were you storing old data on a site you apparently weren't using any more?
What have you put in place to make sure it doesn't happen again, you mention that passwords are encrypted using md5, how? Are they salted?
You mention penetration testing and PCI DSS compliance, what penetration testing have you done? What have you done to re-certify your PCI DSS compliance (PCI DSS being a fairly easily attainable standard which I presume your site already complied with, it's pretty hard not to.)
Are you still storing partial card details after processing, if so why? Why were you storing them before?

Eta. You mention you have previously done pen testing and PCI dss compliance so I take this to mean you've not done this since the hack?

I don't want to come across as difficult but your statement says very little and I'd like to understand what you've done now to make sure this doesn't happen again past saying our current site is secure so it won't happen again.

Edited by Silent1 on Tuesday 7th April 00:42

mmm-five

12,020 posts

306 months

Tuesday 7th April 2015
quotequote all
Got a text at 12:52 yesterday, and any email must have gone to an old email address anyway.

I went to the website - using a W7 VM on my Mac I use for plausible deniability - to see what it was about. Details showed a very old credit card number and was asking for me to update it, provide mother's maiden name and my bank details.

Contacted Jonny straight away and he mentioned he had his hands full.

Wh00sher

1,743 posts

240 months

Tuesday 7th April 2015
quotequote all
I received a text to my landline, but that was all.

Whilst it`s good to hear it`s now sorted and secure, the fact this happened at all is rather worrying.

PW1962

75 posts

140 months

Tuesday 7th April 2015
quotequote all
Got the scam .. Then five minutes later the email from Bookatrack
Was going to post a thread last night but thought it was upto BAT to raise the alarm ....

jonnyleroux

1,511 posts

282 months

Tuesday 7th April 2015
quotequote all
apologies all - posting to the numerous forums I frequent is not high on my list of priorities at the moment unfortunately but I am aware that forums are a two-way medium for us and will endeavour to update when I get a bit more time.

Many thanks to all those who have offered support (both moral and technical). Sarah and I have had 36 hours of utter hell and are now enjoying a quick glass of wine before heading to bed - ready to face another day of it tomorrow.

Jonny
censored

Sorry but sigs not allowed.

Edited by Big Al. on Friday 15th May 22:22

TypeRTom

520 posts

179 months

Wednesday 8th April 2015
quotequote all
I didn't get a scam text (maybe because I didn't register on the old site?), did get a text from the real BaT but not an e-mail.

MD5 is no longer considered a good choice for password hashing.
http://security.blogoverflow.com/2013/09/about-sec...
There is plenty of other info out there about it too.

shim

2,050 posts

230 months

Wednesday 8th April 2015
quotequote all
how does one delete all information on the BaT account?

I have managed to change my old details but it seems even for those of us that are not welcome, we can still have accounts and they cant be deleted!

QBee

22,049 posts

166 months

Wednesday 8th April 2015
quotequote all
Thanks for the warning Jonny. I am on your mailing list but have never booked with you, so didn't get a scam email or text.
You have my sympathy. I wish you success sorting it all out. You are good guys, a small company, and don't deserve st like this.

Don

28,378 posts

306 months

Wednesday 8th April 2015
quotequote all
TypeRTom said:
I didn't get a scam text (maybe because I didn't register on the old site?), did get a text from the real BaT but not an e-mail.

MD5 is no longer considered a good choice for password hashing.
http://security.blogoverflow.com/2013/09/about-sec...
There is plenty of other info out there about it too.
Yes I'm afraid MD5 is no longer considered good enough. I've been involved in securing financial services websites recently and best practice is now to use something like SHA256 or better and, importantly, to "salt" the hash to defend against brute force password crackers, rainbow tables and the like.

This article is illuminating for those of a technical bent https://crackstation.net/hashing-security.htm

Sorry to hear of your troubles, Jonny. I sincerely hate the hacking barstewards too. It sounds like you've done all you can.

TuxMan

9,011 posts

260 months

Friday 10th April 2015
quotequote all
Thanks for the update Jonny , what a sad world we live in !!!! Hope you get it sorted soon .

Tux