DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Travel insurer Staysure warns 93,389 customers after card data hacked

Posted on January 4, 2014 by Dissent

Bob Howard reports:

The travel insurer Staysure has warned customers that some of their sensitive bank card details may have been stolen after its IT security was breached.

Some 93,000 people who bought policies prior to May 2012 may be at risk, it said.

Staysure said it believed hackers may have stolen the three digit Card Verification Value (CVV) numbers of some policy holders.

Read more on BBC. It appears that card information was encrypted but CVV numbers, stored under their legacy system, were not encrypted.

Yesterday the firm posted this notice on their website, linked from their home page:

In December 2013 we wrote to a group of our customers to tell them that our systems suffered a cyber attack during the second half of October 2013.

In that attack, encrypted payment card details of customers who purchased insurance from us before May 2012 were stolen, along with CVV details and customer names and addresses. From May 2012 we ceased to store this data.

We became aware of the problem on November 14, and quickly informed the relevant card issuing bodies and subsequently The Financial Conduct Authority, the Information Commissioner’s Office and the Police. We immediately hired independent forensic data experts to fully ascertain the extent of the problem and have written to 93,389 affected customers, which represents fewer than 7% of our customer base, to warn them and to ask them to check that they have not been the victims of any fraud as a result.

We have also offered those customers free access to Data Patrol, a comprehensive, identity monitoring service provided by Experian. The service offers 24/7 online identity fraud monitoring, alerting by email if any customer data is compromised. This is supplemented by a telephone based fraud resolution service.

We continue to work with those groups and independent security experts. We immediately removed the software and systems that the attackers exploited, and we are confident that we have taken the right steps to protect our customers in the future.

We are deeply sorry that this has happened and are working diligently to make sure that inconvenience to customers is minimised.

Ryan Howsam
Chief Executive Officer

Action to take:

If we have not written to you, you will not be amongst those affected.

If you are amongst those affected please follow the suggested course of action in our letter, which is to contact your card issuer, check your statements and then take advantage of the free subscription to Data Patrol.

If you are in receipt of our letter and have any concerns or queries please call the numbers provided and we will be pleased to assist you.

Contact Numbers:
0800 007 4540
01604 214 575

Media Enquiries:
If you are a journalist please call our media team on 0207 781 2362

Category: Business SectorHackNon-U.S.

Post navigation

← NC DHHS: Almost 49,000 Medicaid cards with children's personal information mailed incorrectly (update 1)
House Plans Vote On Security Requirements For Health Insurance Exchange →

4 thoughts on “Travel insurer Staysure warns 93,389 customers after card data hacked”

  1. D Ethell says:
    January 5, 2014 at 9:14 am

    Please confirm that I am not one of those affected by the breach

    KR

    Derrick Ethell

    1. Dissent says:
      January 5, 2014 at 9:22 am

      This is a breach blog, not a personal service. 🙂 You need to contact them yourself if you haven’t heard from them and are concerned.

    2. Anonymous says:
      January 6, 2014 at 2:02 pm

      Cheap travel insurance results in poor risk management and protection for customers, what a suprise!

  2. Rosie Evans says:
    February 1, 2014 at 6:13 pm

    I have previously purchased insurance from you. I purchased a policy in the last week..and immediately was the victim of an attempted card fraud. It was only the prompt action of the issuer that saved me. I had not used the card for anything else. “Last transaction “..(I asked the issuer ?).
    “Staysure !!”..they answered !!

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Washington Post investigating cyberattack on journalists, WSJ reports
  • Resource: State Data Breach Notification Laws – June 2025
  • WestJet investigates cyberattack disrupting internal systems
  • Plastic surgeons often store nude photos of patients with their identity information. When would we call that “negligent?”
  • India: Servers of two city hospitals hacked; police register FIR
  • Ph: Coop Hospital confirms probe into reported cyberattack
  • Slapped wrists for Financial Conduct Authority staff who emailed work data home
  • School Districts Unaware BoardDocs Software Published Their Private Files
  • A guilty plea in the PowerSchool case still leaves unanswered questions
  • Brussels Parliament hit by cyber-attack

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe
  • Would you — or wouldn’t you?
  • New York passes a bill to prevent AI-fueled disasters
  • Synthetic Data and the Illusion of Privacy: Legal Risks of Using De-Identified AI Training Sets
  • States sue to block the sale of genetic data collected by DNA testing company 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.