Community
Wiki Posts
Search

Big Crumbs Hacked?!

Thread Tools
 
Search this Thread
 
Old Jan 29, 2015, 11:04 pm
  #1  
Original Poster
 
Join Date: Aug 2011
Posts: 866
Big Crumbs Hacked?!

BigCrumbs.com is currently offline while we continue to investigate possible fraudulent activity.

UPDATE - 1/29/2015 - 11:05AM EST
Dear Valued Members,

We have determined that there has been unauthorized access to a number of member accounts. The number of confirmed affected accounts as of this writing is under 200. This number may increase as we continue to investigate.

It is important to note that this does not appear to be a "hack" or site-wide breach of the type popularized in news reports of other companies. Rather, it appears to be the compromise of a limited number of accounts that utilized common or overly-simple passwords, or otherwise re-used credentials from a different site that was previously breached.

Additional Information:

There is no evidence that our servers or databases were compromised or penetrated. We continue to research this with our hosting provider.
There is strong evidence that the means of unauthorized access were enabled via:
The attacker(s) taking advantage of the use of weak or common account passwords (including accounts for which the passwords were the same as the User IDs)
The attacker(s) utilizing user account credentials gained from breaches of other sites, wherein members used those same User ID/password combinations at BigCrumbs. Such credentials are widely sold/shared by potential attackers.
The attack appears to have started on January 18, 2015, but possibly as early as December, 2014.
Unauthorized access may have potentially revealed such member information as first and last name, e-mail address, postal address, and cash back history.
It is extremely important to avoid the use of common or overly simple passwords, as well as to avoid the reuse of account credentials at multiple sites.

What we are doing:

While we are still investigating and working to identify affected member accounts, we are also in the process of reaching out to those known to be affected, as well as our members in general.

As a precaution, the BigCrumbs.com site will remain offline until we've put into place several security measures, including:

All members will need to reset their passwords upon their next sign-in attempt after the site is restored.
Password requirements will become more stringent.
BigCrumbs will not be able to pay members who have not reset their passwords. In some cases, additional verification may be required.
BigCrumbs's next scheduled payday is February 2, 2015 (because January 31st falls on a weekend). We are working to avoid delays in payment or any additional service interruption, however, securing affected accounts ahead of issuing payments is our priority. As such, there may be delays in this period's payments for the first time in BigCrumbs history.

We will update here with any additional details as they become available.

We apologize for any inconvenience to our valued members that this unfortunate incident may have caused.

Sincerely,

Vince Martin
CEO
BigCrumbs.com
Father-of-3 is offline  
Old Jan 30, 2015, 4:47 am
  #2  
XP1
 
Join Date: Aug 2014
Posts: 282
If you read the message, Big Crumbs did not get hacked. The users got hacked.
XP1 is offline  
Old Jan 30, 2015, 4:54 am
  #3  
 
Join Date: Aug 2014
Posts: 31
LOL Bad controls then blame mom and pop for their password.
jimmyjackfunk is offline  
Old Feb 1, 2015, 2:40 pm
  #4  
Original Poster
 
Join Date: Aug 2011
Posts: 866
Originally Posted by XP1
If you read the message, Big Crumbs did not get hacked. The users got hacked.
Agreed, but click bait requires a much better title to get you to click.
Father-of-3 is offline  
Old Feb 21, 2015, 5:02 pm
  #5  
Suspended
 
Join Date: Jun 2011
Posts: 639
Originally Posted by Father-of-3
Agreed, but click bait requires a much better title to get you to click.
My friend got hacked
member7777 is offline  
Old Feb 21, 2015, 6:02 pm
  #6  
Original Poster
 
Join Date: Aug 2011
Posts: 866
Big Crumbs Hacked?!

What was the result??
Father-of-3 is offline  
Old Feb 22, 2015, 6:26 pm
  #7  
 
Join Date: Feb 2014
Location: SQSP
Programs: 1&2
Posts: 167
Update from website

UPDATE - 2/18/2015 - 11:23AM EST

We are working tirelessly to bring BigCrumbs back online and we are aggressively projecting to be back up within the next 2-3 days.

Hang in there. Won't be much longer now!
brero is offline  
Old Mar 22, 2015, 9:48 pm
  #8  
 
Join Date: Aug 2013
Posts: 240
still nothing...
Silverthunder is offline  
Old Mar 23, 2015, 5:33 am
  #9  
FlyerTalk Evangelist
 
Join Date: Sep 2007
Location: BOS
Programs: DL DM 2MM, Marriott LT Titanium, Hertz PC, Avis PC
Posts: 15,206
I wonder if they're essentially done with. Been out for too long, previous users have and will probably move on to other cash back sites.
rylan is offline  
Old Mar 23, 2015, 9:09 am
  #10  
 
Join Date: Mar 2007
Location: S Cal
Programs: AA Lifetime Plat, United Silver, Marriott Plat, IHG Plat
Posts: 1,142
The opposite might be the case. If this were my business, after such a prolonged blackout, I would consider offering a special bonus once the site is up and running again as an inducement to get my old customers back.
GetawaysRus is offline  
Old Mar 31, 2015, 2:08 pm
  #11  
 
Join Date: Oct 2013
Posts: 920
They changed their name to mainstreet shares. They've also wiped out all my pending CB. I still see my "shares", but literally all of my funds seem to be gone. Anybody seeing theirs?
hitman1420 is offline  
Old Mar 31, 2015, 2:10 pm
  #12  
 
Join Date: Oct 2013
Posts: 920
They no longer do cash back either. Only a "Share" of company revenue. Smells like an exit scam to me.
hitman1420 is offline  
Old Mar 31, 2015, 2:54 pm
  #13  
 
Join Date: Jul 2008
Posts: 245
Fortunately I got the $40 they owed me without having to chase it down. I certainly won't be using them again.

If BF or TCB pulls the same thing it will be alot worse.
nmp0 is offline  
Old Mar 31, 2015, 8:06 pm
  #14  
Original Poster
 
Join Date: Aug 2011
Posts: 866
What a scumbag way to 'reinvent' yourself. I won't be using them anymore. Topcashback has been getting my business this year.
Father-of-3 is offline  
Old Mar 31, 2015, 11:14 pm
  #15  
 
Join Date: Feb 2009
Posts: 3,737
Originally Posted by Father-of-3
What a scumbag way to 'reinvent' yourself. I won't be using them anymore. Topcashback has been getting my business this year.
Seems that market is already very saturated and they may have been struggling. They were very open/honest in the forums about Amex GC's and gave some insight to the company. After the hack I'm sure that had a huge effect on their business and I can only guess that they needed to reinvent themselves? Kind of like companies that change their name after ruining their public image with a scandal or accident.

The new system seems a bit confusing.
Astrophsx is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.