Play.com spam points to malware downloads
Breach blamed on marketing company
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
Multiple Reg readers were annoyed at receiving junk mail messages on Monday from addresses they had only registered with online retailer Play.com.
Several of these junk mail sites pointed to black hat controlled domains that served up malware, heightening complaints on online forums (discussion on MoneySavingExpert here) and sparking theories that either Play.com had been hacked or its mailing list had been stolen.
Affected users were sure that Play.com must have been associated with the malware touting emails because they used a unique email address when signing up to the site.
We put in a query to Play.com on Monday but are yet to hear back. However, we have received copies of emails sent to customer by Play.com that apologised for the incident and blamed the breach on an (unnamed) third-party marketing firm.
We are emailing all our customers to let you know that a company that handles part of our marketing communications has had a security breach. Unfortunately this has meant that some customer names and email addresses may have been compromised.We take privacy and security very seriously and ensure all sensitive customer data is protected. Please be assured this issue has occurred outside of Play.com and no other personal customer information has been involved.
Please be assured we have taken every step to ensure this doesn’t happen again and accept our apologies for any inconvenience this may have caused some of you.
Reports on a forum on gaming site GSN.com suggested that its subscribers were also hit by a spam-based malware attack. The junk emails touted a fake Adobe update that actually contained a Trojan. ®
COMMENTS
"....a fake Adobe update that actually contained a Trojan."
As opposed to a real Adobe update that actually contains yet another bloody browser toolbar then?
I prefer the fake ones, at least the sodding AV tools don't let the unwanted bits through....
I'm one of those nerds
That uses a different address for each website - very useful for seeing who your spam comes from, but more useful for seeing the attitude of the company when you tell them "wasn't our fault, you must be mistaken", and the tech ability of the staff when you have to actually speak to them...
"Are you SURE your email address is sky@*****.co.uk".
We take privacy and security very seriously...
...and that's why we sent all your email addresses to some marketing scum who don't give 2-hoots about privacy, security, ethics....

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider