DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

If it’s Friday, it’s time to reset almost 18 million passwords? (Corrected)

Posted on December 30, 2011 by Dissent

Care2 has notified users of a security breach. In its FAQ, the online community said that it discovered the breach on December 27, but as of December 28, “We are currently unable to determine the full extent of the security breach.” The site is forcing a password reset and urging members to change their passwords on other sites if they re-use passwords.

A copy of the e-mail notification sent to members  today was forwarded to DataBreaches.net by a recipient:

To All Care2 Members:

We have discovered that Care2.com servers were attacked, resulting in a security breach. The hackers were able to access login information for Care2 member accounts. Our team has worked to secure Care2.com against this type of attack from recurring.

To protect Care2 members we are resetting access to all Care2 accounts. The next time you login to Care2, you will be automatically emailed a new password, which will enable you to access your Care2 account as usual.

To recover your password, you can also visit our password retrieval form http://www.care2.com/go/z/e/Ag5Vq/zLzm/SxwU and enter your username or email. Your password will be emailed to you.

To secure your privacy, we highly recommend you immediately change your password for any accounts that share the password you previously used on Care2.

If you have any questions or concerns, please email us at: [email protected].

We sincerely apologize for this inconvenience. We take the security of our members very seriously and are taking these extreme steps to reduce the chances of any possible negative consequences.

Randy Paynter
Founder & President, Care2

Care2’s home page indicates it has 17,900,617 members, but the notification says that the  hackers were (only?) able to access login information for a “limited number” of Care2 member accounts.  I wonder what they consider “limited number.” And I wonder what other information the hackers acquired.

Significantly, perhaps, a number of commenters noted that they were surprised to learn of a breach involving their login information as they had never signed up for an account.  An administrator commenter replied:

To the best of my knowledge, anyone who has ever signed a petition at the Petition Site run by Care2, is automatically given a profile / account. That may be how many of you were added. Also, long ago, Care2 had a number of very popular newsletters, and people who subscribed to those were given profile pages when the newsletters were turned into groups. [See CORRECTION BELOW]

So I also wonder whether Care2.com ever sought or obtained consent to create profile pages for individuals who only signed up to receive a newsletter by e-mail.

And I wonder why they are reportedly e-mailing passwords to users in clear text.

CORRECTION OF 1-15-12: I erroneously attributed a comment above to an administrator. See Comment below.

Category: Breach IncidentsHackMiscellaneousOf NoteU.S.

Post navigation

← Hospital employee allegedly makes fun of patient's medical condition on Facebook; officials investigating
United flyer finds dozens of passengers’ info online →

2 thoughts on “If it’s Friday, it’s time to reset almost 18 million passwords? (Corrected)”

  1. Zen says:
    January 15, 2012 at 1:58 am

    The quote above, attributed by you to a Care2 ‘administrator’, was lifted from comments posted on the blog of Care2 CEO Randy Paynter, and was part of a comment made by me, republished here without my consent.

    http://www.care2.com/care2blog/to-all-care2-members-security-breach.html#ixzz1hsvRhXtM

    I am not a Care2 administrator, nor did I claim to be one, as a quick perusal of the profile page of the person who posted that comment (me) would have shown. I am just a member of the site, I do not work for Care2.

    1. admin says:
      January 15, 2012 at 9:45 am

      Thanks for pointing out the error in attribution. I’ve corrected it above.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.