"Sam's Club" Hacked, Info Leaked Online

The Scarlet Pimp

Supreme Member
Joined
Apr 2, 2008
Messages
1,408
Reaction score
4,440
Sam's Club resets passwords after thousands of logins posted online...

Over 14,000 usernames and plain-text passwords for the retail giant's online store were posted online over the weekend.

Wholesale retail giant Sam's Club has reset passwords for thousands of customers after their account details were posted online.

In an email to members obtained by ZDNet, the Walmart-owned company said that it had begun resetting passwords after it found that "someone might be trying to take advantage" of customer accounts.

It comes after over 14,600 email addresses and plain-text passwords associated with Sam's Club's online store were dumped on Pastebin, a text sharing site, on Saturday.

The title of the password dump said that the accounts listed belonged to the retail giant. The company which has over 650 locations across the US and tens of millions of members.

But the company denied that it had been hacked.

"We've looked into this issue and there is no indication of a breach of our systems. It is most likely a result of one of the past breaches of other companies' systems.

Because customers often use the same usernames and passwords on various sites, bad actors will typically test the credentials they obtain across many popular sites. Unfortunately this is an industry-wide issue," said Walmart spokesperson Dan Toporek in an email.

http://www.zdnet.com/article/sams-club-resets-passwords-after-thousands-of-logins-posted-online/
 
I got to go offtopic because im curious, even if what they are saying is true why would anyone and especially big companies save passwords without hashing them?
 
I got to go offtopic because im curious, even if what they are saying is true why would anyone and especially big companies save passwords without hashing them?

Sam's Club = Wal Mart. Wal Mart can do whatever they want. They are by far the largest corporation in the world, both by revenue and employees.
 
Aren't these passwords encrypted somehow?

like sony pictures did with their passwords a year ago? most of these large companies are staffed by people who know or care very little about security.

client privacy is someone else's problem.
 
I got to go offtopic because im curious, even if what they are saying is true why would anyone and especially big companies save passwords without hashing them?
One possible reason would if they want to send the old password in email instead of resetting them. Nevertheless, that would be a bullshit logic.
 
not sure what someone could do with all these logins. sams club doesn't store payment information as far as i know. perhaps the world will know i buy too much toilet paper...
 
This is hardly news. Another popular forum has had a large userbase of people selling these accounts for years now. I think the going rate is around 30% of the accounts value.
 
Back
Top