Wiggle data breach
Author
Discussion

lufbramatt

Original Poster:

5,584 posts

160 months

Tuesday 16th June 2020
quotequote all
Apparently wiggle / chain reaction have had a data breach with account details compromised, so worth changing your password....

Your Dad

2,210 posts

209 months

Tuesday 16th June 2020
quotequote all
Data breach, or credential stuffing because people reuse the same passwords?

Harpoon

2,465 posts

240 months

Tuesday 16th June 2020
quotequote all
Your Dad said:
Data breach, or credential stuffing because people reuse the same passwords?
Credential stuffing was my first thought when the rumours started...

TheGinger1

87 posts

90 months

Tuesday 16th June 2020
quotequote all
Credential stuffing due to people using the same password everywhere I believe

Gareth79

8,812 posts

272 months

Wednesday 17th June 2020
quotequote all
It's very common where fraudsters discover a retailer which doesn't have sufficient security in place to prevent such bulk credential testing, and presumably where the saved card can be reused without entering a CVC.

Many large retailers will use publicly available compromised credentials to test against their own customers logins and proactively disable such accounts, although I imagine a retailer of Wiggle/CRCs size would need to use external IT security services to do that (or have very good in-house staff).