Feeds

Watchdog washes hands of Lush hack

Soft soap for hippy soap seller

Choosing a cloud hosting partner with confidence

The Information Commissioner's Office is facing criticism today for its failure to punish online retailer Lush for losing 5,000 customer debit and credit card details

Lush, home to fruit-based soaps, shampoos and bath bombs, was forced to temporarily shut its website after losing the details late last year.

It advised punters who'd made purchases through the site between 4 October 2010 and 20 January 2011 to check their accounts for fraudulent use of cards.

But the ICO is happy to have got Lush to sign a letter promising to obey the law in future.

Lush received 95 customer complaints before it acted.

The ICO said the soap seller failed to keep proper records of suspicious activity on its website which meant there were delays in stopping the breach and protecting customers.

SecurEnvoy's co-founder Steve Watts said: “What we have here is a major e-commerce Web portal - run by a consumer-friendly company that prides itself on its eco-friendly products and stance generally – that was solidly hacked for four months over the busy Christmas period, and essentially has got away scot-free,”

He said the lack of punishment showed the weakness of UK data protection law - "if the watchdog that enforces the rules feels it cannot penalise a company whose database has been hacked for 120 days without its IT staff being aware of the incursion."

The European Commission is taking the UK government to court for failing to adequately protect the data of UK citizens. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.