Things aren't looking so hot for approximately 40,eroticism000 OnePlus customers. And no, not because they'll probably have to wait until June to upgrade to the OnePlus 6.
It turns out that the company's website was hacked, and in the process credit card numbers and other payment information was likely stolen.
SEE ALSO: OnePlus issues statement as some buyers complain of credit card fraudAccording to a statement issued by the Chinese smartphone manufacturer, "a malicious script was injected into the payment page code to sniff out credit card info while it was being entered."
What this means in practice is that, from roughly mid November of 2017 to January 11, 2018, any customer who put their credit card into OnePlus.net could have had it lifted by hackers. Some customers are already reporting fraudulent charges.
"The malicious script operated intermittently, capturing and sending data directly from the user's browser," the company said in a statement. "It has since been eliminated. We have quarantined the infected server and reinforced all relevant system structures."
OnePlus emailed the customers it believes might have been affected, and noted that both card expiration dates and security codes could also have been stolen.
Security researchers at Fidus Information Security looked into the breach, and what they found doesn't look so good for OnePlus. According to a Fidus blogpost, "OnePlus do not appear to be PCI compliant, nor do they mention this anywhere on the website."
Why does this matter? PCI is short for Payment Card Industry Data Security Standard, and, according to the PCI Security Standards Council, the standards are "the operational and technical requirements for organizations accepting or processing payment transactions, and for software developers and manufacturers of applications and devices used in those transactions."
In other words, according to Fidus, OnePlus may not have been taking basic steps to protect its customers data. Like we said, not looking good.
So, what can you do if you got an email from OnePlus notifying you of the breach? Not much, unfortunately. OnePlus says you should check your bank statement for fraudulent charges, and reach out to the company for any "enquiries."
OnePlus will also offer "one year of credit monitoring to affected customers," according to a company spokesperson.
Somehow, for those who already had their credit cards stolen, we don't imagine these measures will provide much solace.
This story has been updated to note that OnePlus is offering limited credit monitoring.
Topics Cybersecurity OnePlus
(Editor: {typename type="name"/})
Dyson Supersonic deal: Save $100 on the blow dryer
Ticketmaster disaster: The 11 best tweets from Taylor Swift fans' very bad week
Anelise Chen: A Mollusk’s Guide to “Clamming Down”
Elias Sime’s Art Repurposes Electronic Waste from Abbis Ababa
Xbox Elite Series 2 controller deal: Get it at its lowest price ever
Photos from Our 2017 Spring Revel
May Swenson’s “Daffodildo,” a Lusty Poem for May
Tech workers turned sex workers: why they changed careers
NYT Strands hints, answers for December 8
Bayou Fever: Romare Bearden’s Dynamic Collages
Amazon Big Spring Sale 2025: All the best Roomba deals
NYT's The Mini crossword answers for November 9
接受PR>=1、BR>=1,流量相当,内容相关类链接。