DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

SuperValu warns customers of data breach (update 4 with numbers, Stena Line, other countries also affected, statement from Loyaltybuild)

Posted on November 4, 2013 by Dissent

Conor Pope reports:

SuperValu has been forced to contact thousands of customers who have bought its “getaway breaks” after a security breach at the company that oversees the scheme left sensitive financial data potentially compromised.

The “getaway breaks” vouchers are a key loyalty reward programme run by the US-owned company Loyaltybuild, which is based in Co Clare. It is reviewing the security of the personal and payment card information held on its booking system.

“This review is necessary as Loyaltybuild has advised its client base in Ireland that its system may have been compromised by a third party,” said SuperValu in a statement.

“This issue is exclusive to ‘Getaway Breaks’. It does not impact SuperValu’s other websites or any other customer transactions by payment card,” a spokesman said.

Read more on Irish Times.  The SuperValu.ie  site currently has this notice on its “Getaway Breaks” page:

We are experiencing technical issues and we are hard at work to bring SuperValu Getaway Breaks and Bonus Rewards back online. Thank you for your patience, we apologise for any inconvenience caused.

I hate when sites suggest they are down for “maintenance” or a “technical” problem when they know they’re looking into a security breach. But then, I guess under Ireland’s laws, they don’t have to post anything on their web site about this, and reportedly, the data were encrypted and they have no evidence of acquisition or misuse. So….

Update 1: Today’s RTÉ reports that more than 30,000 customers were affected by this breach. They report that another Loyaltybuild client, Axa, also had customers affected (approximately 4,000).

Update 2: And now it’s more than 140,000  who have personal and payment card info at risk, including 40,000 Irish customers of Supervalu, Axa, and Stena Line, and 100,000 consumers in Norway, Italy, and Sweden.

Loyaltybuild posted the following statement on their site yesterday:

On Friday 25th October our data security team identified a suspected system breach.  From the moment Loyaltybuild discovered the breach we took immediate action to rectify the situation and protect stored data.

We immediately engaged the services of a firm of leading, international, online security experts.  They are conducting a forensic investigation to help us identify whether any of our stored data was compromised, and, if so, to what extent.  As of 1pm today the forensics team reported there had been no signs of person or payment databeing extracted or compromised, but the forensic examination is ongoing. The Irish Data Protection Commissioner and all affected clients have been informed of the suspected breach.

Unfortunately, the threat of cyber-attacks is increasingly becoming a reality of doing business today. To this end, we employ systems which operate to the highest level of encryption and security standards and we constantly monitor and test our systems.

To minimise risk we operate a policy of maintaining as little personal information as possible; credit card numbers are encrypted and we deliberately do not store CVV numbers – the card verification value – which is a 3 digit number found on the back of a credit / debit card. All payment details are deleted 90 days after a consumer has travelled.

We are working around the clock with our security experts to get to the bottom of this and to further enhance our security.

As soon as we have more information from the forensics team we will publish an update.

We regret any inconvenience caused and are taking every necessary action to rectify this issue.

For customer queries please call the Loyaltybuild Helpline on 065 686 5200. The helpline is open Monday to Sunday from 9am to 8pm.

Update 3: SuperValu has revised its estimate upwards to report that 62,500 of their customers may have been affected.

Update 4: Now the total number across EU is estimated at 500,000

Category: Business SectorHackNon-U.S.Of Note

Post navigation

← NZ: Westpac remains tight-lipped about privacy incident
Debt Collection Employee and Son-in-Law Sent to Prison for Identity Theft Tax Scheme →

2 thoughts on “SuperValu warns customers of data breach (update 4 with numbers, Stena Line, other countries also affected, statement from Loyaltybuild)”

  1. IA Eng says:
    November 7, 2013 at 12:53 pm

    Add another “value site” to the compromised list = \

    http://news.softpedia.com/news/Harbor-Freight-Tools-Hacked-Payment-Processing-System-Compromised-397103.shtml

    1. Dissent says:
      November 7, 2013 at 3:13 pm

      I had reported that breach last week, here: http://www.databreaches.net/harbor-freight-tools-usa-notifies-customers-that-payment-processing-system-was-hacked/

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.