PDA

View Full Version : Baseball Mogul Credit Card system compromised


nilodor
05-31-2003, 01:09 PM
http://www.sportsmogul.com/vbulletin/showthread.php?s=&threadid=38646

This is a current thread link and here is a copy of the email I got.

==========================================================
Please note, this only applies to Baseball Mogul Online account subscribers who
were paying by credit card. It does not apply to people who've purchased the
CD-ROM products.
==========================================================

At 3:40pm yesterday (March 29th) someone hacked into the Mogul Online billing
server and took all the credit card data. To ensure that this can't happen
again, we're completely re-building the server from scratch and, for this month
(and probably next month), suspending all billing and removing all information
from the server while we look into alternative, more secure, billing methods. [
This also means the next month of Mogul Online is free for everyone...so,
there's a silver lining to everything.]

We sent an email to every person in the Mogul Online system who was affected --
Unfortunately, however, some people didn't have current email addresses, so they
didn't receive their notifications. Hopefully by sending this message through
the boards, they'll find out about the security breach and can also protect
themselves.

Please, if you were paying for BASEBALL MOGUL ONLINE by credit card:
- Call your credit card company and have the card reported stolen, and have it
re-issued.
- Check your recent activity for the account for fraudulent charges and report
them to your credit card company as fraudulent. (If done within 48 hours of the
charge, this protects you from any liability for the charge. And, after 48 hours
of a false charge being made, you are only liable for a maximum of $50 of the
charge under Federal Law - and Sports Mogul Inc. will pay any $50 liabilities if
they occur. Email Dee for Details [email protected] )

Additionally, our bank is going to notify every single issuing bank in our
records to doubly ensure that no Mogul customer is held liable for fraudulent
charges. However, the fastest way to make sure the card is resecure is to call
your issuing card company directly, since our bank won't be able to send out the
notifications until Monday.

To discuss this further, please visit the forums: Credit Card Theft Topic:
http://www.sportsmogul.com/vbulletin/showthread.php?s=&threadid=38646

Note: Credit Card numbers given to order the CD-ROM products are still perfectly
safe. We used 3rd party billing systems to take CD-ROM orders, and they're on
different systems. CD-ROM purchasers are not affected by this situation - only
Baseball Mogul Online users.

We offer our sincerest apologies for both the security breach, and the downtime.
With luck, we'll emerge from this as a stronger, more secure system.

-Dee Dreslough
[email protected]
www.sportsmogul.com

and


First, a correction:
=================
I said 'Yesterday, March 29th'...it was really May 29th when the hacking
occured. Sorry for the brain-o there. :)

Second, a Clarification:
======================
People who bought the downloadable CD-ROM products Football Mogul, Baseball
Mogul 2003 and Baseball Mogul 2004 are not affected by this. Those credit card
numbers were handled by a third party.

Third, a System for Double Checking
===================================
Feel free to email me [ [email protected] ] with the cardholder name that you
think may have been in our system, and I'll tell you if your card was
compromised or not. Because the billing system is down now, people have no way
of seeing which card they may have had in the system. I can look up cardholder
names and let you know directly if you were affected by the theft.

Thank you for your patience and understanding! Again, our heartfelt apologies
from everyone here at Sportsmogul.

-Dee Dreslough
www.sportsmogul.com


Not a good thing for this franchise, not good at all.

oykib
05-31-2003, 01:42 PM
I got the same thing. Thankfully, I haven't ordered anything from them in a long time. The CC I used is no longer active anyway.

Draft Dodger
05-31-2003, 03:01 PM
"Not a good thing for this franchise, not good at all."

I don't know, seems like a pretty classy effort on their part to get the word out, and to fix the problem. the truth is, no system is going to be completely secure against someone who really wants to get into it.

this is a good example as to why you use a credit card (not a debit card) for your online purchases.

FBPro
05-31-2003, 03:09 PM
No doubt they have had a rough go of things.

nilodor
05-31-2003, 06:59 PM
DD,

I was not refering to their response to the problem. They did exactaly the right thing for this situation. The bad thing is, in this market with the competition they have from OOTP, FOF and the other 400 studios projects, it may be hard to regain their consumer share. Who knows? Time will tell.

Draft Dodger
05-31-2003, 07:04 PM
I knew what you meant. I just didn't agree with your view.

Personally, I've never played any of their games, but their response probably gives me MORE confidence in them as a reputable company, not less. YMMV of course.

tucker342
05-31-2003, 07:21 PM
I agree with you DD.

That really sucks...