The Register® — Biting the hand that feeds IT

Feeds

Play.com spam points to malware downloads

Breach blamed on marketing company

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Multiple Reg readers were annoyed at receiving junk mail messages on Monday from addresses they had only registered with online retailer Play.com.

Several of these junk mail sites pointed to black hat controlled domains that served up malware, heightening complaints on online forums (discussion on MoneySavingExpert here) and sparking theories that either Play.com had been hacked or its mailing list had been stolen.

Affected users were sure that Play.com must have been associated with the malware touting emails because they used a unique email address when signing up to the site.

We put in a query to Play.com on Monday but are yet to hear back. However, we have received copies of emails sent to customer by Play.com that apologised for the incident and blamed the breach on an (unnamed) third-party marketing firm.

We are emailing all our customers to let you know that a company that handles part of our marketing communications has had a security breach. Unfortunately this has meant that some customer names and email addresses may have been compromised.

We take privacy and security very seriously and ensure all sensitive customer data is protected. Please be assured this issue has occurred outside of Play.com and no other personal customer information has been involved.

Please be assured we have taken every step to ensure this doesn’t happen again and accept our apologies for any inconvenience this may have caused some of you.

Reports on a forum on gaming site GSN.com suggested that its subscribers were also hit by a spam-based malware attack. The junk emails touted a fake Adobe update that actually contained a Trojan. ®

Agentless Backup is Not a Myth

"....a fake Adobe update that actually contained a Trojan."

As opposed to a real Adobe update that actually contains yet another bloody browser toolbar then?

I prefer the fake ones, at least the sodding AV tools don't let the unwanted bits through....

10
1

I'm one of those nerds

That uses a different address for each website - very useful for seeing who your spam comes from, but more useful for seeing the attitude of the company when you tell them "wasn't our fault, you must be mistaken", and the tech ability of the staff when you have to actually speak to them...

"Are you SURE your email address is sky@*****.co.uk".

7
0

We take privacy and security very seriously...

...and that's why we sent all your email addresses to some marketing scum who don't give 2-hoots about privacy, security, ethics....

5
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence