This article is from the source 'bbc' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at http://www.bbc.co.uk/news/technology-27046971

The article has changed 3 times. There is an RSS feed of changes available.

Version 0 Version 1
LaCie warns of suspected credit card data breach LaCie warns of suspected credit card data breach
(35 minutes later)
French computer storage specialist LaCie has said credit card details and passwords of shoppers who used its site may have been stolen.French computer storage specialist LaCie has said credit card details and passwords of shoppers who used its site may have been stolen.
The hard-disk maker said the FBI had alerted it to "indications" of a hacker having used malware to copy details entered into its online store.The hard-disk maker said the FBI had alerted it to "indications" of a hacker having used malware to copy details entered into its online store.
It added that the suspected breach was thought to have lasted from 27 March 2013 to 10 March this year.It added that the suspected breach was thought to have lasted from 27 March 2013 to 10 March this year.
Experts said it was unusual for such a problem to go unnoticed for so long.Experts said it was unusual for such a problem to go unnoticed for so long.
"It is a major breach," Ron Austin, senior lecturer in computer security at Birmingham City University, told the BBC."It is a major breach," Ron Austin, senior lecturer in computer security at Birmingham City University, told the BBC.
"LaCie is a fairly big company and you would question their information security policies."LaCie is a fairly big company and you would question their information security policies.
"No expert can guarantee 100% security, but it goes back to compliance and ensuring that if you're offering services out on to the web that you are carrying out regular checks.""No expert can guarantee 100% security, but it goes back to compliance and ensuring that if you're offering services out on to the web that you are carrying out regular checks."
LaCie was taken over by US tech company Seagate in 2012, but still sells goods using its name.LaCie was taken over by US tech company Seagate in 2012, but still sells goods using its name.
The attack, if confirmed, could be particularly damaging for LaCie as the brand has security products among its wares.The attack, if confirmed, could be particularly damaging for LaCie as the brand has security products among its wares.
Independent tech consultant Graham Cluley said the company had been left with "egg on its face".Independent tech consultant Graham Cluley said the company had been left with "egg on its face".
"In an ideal world, attacks get prevented in the first place and you have done enough work to secure your website and maybe hired some penetration testers to see if there are vulnerabilities," he said."In an ideal world, attacks get prevented in the first place and you have done enough work to secure your website and maybe hired some penetration testers to see if there are vulnerabilities," he said.
"If you can't prevent it in the first place, hopefully you can pick it up while it's occurring and deflect it."If you can't prevent it in the first place, hopefully you can pick it up while it's occurring and deflect it.
"Clearly LaCie did fail in some way. They should have spotted something was happening.""Clearly LaCie did fail in some way. They should have spotted something was happening."
Adobe flawAdobe flaw
A statement on LaCie's website said that shoppers should check their bills for fraudulent charges and that they would need to change their logins when its store reopened.A statement on LaCie's website said that shoppers should check their bills for fraudulent charges and that they would need to change their logins when its store reopened.
"The information that may have been accessed by the unauthorised person may include customers' names, addresses, email addresses, and payment card numbers and card expiration dates," it said."The information that may have been accessed by the unauthorised person may include customers' names, addresses, email addresses, and payment card numbers and card expiration dates," it said.
"Customers' LaCie website user names and passwords could also have been accessed, which is why we required a reset of all passwords.""Customers' LaCie website user names and passwords could also have been accessed, which is why we required a reset of all passwords."
The statement said that LaCie was alerted to the problem by the FBI on 19 March.The statement said that LaCie was alerted to the problem by the FBI on 19 March.
However, security blogger Brian Krebs had warned the company earlier that month that its site might have had credit card data stolen by a criminal gang exploiting vulnerabilities in Adobe's ColdFusion web application development software.However, security blogger Brian Krebs had warned the company earlier that month that its site might have had credit card data stolen by a criminal gang exploiting vulnerabilities in Adobe's ColdFusion web application development software.
On 17 March Mr Krebs reported that LaCie had told him that its preliminary investigation had found no indication that customer data had been compromised.On 17 March Mr Krebs reported that LaCie had told him that its preliminary investigation had found no indication that customer data had been compromised.
But in a follow-up article, Mr Krebs said that LaCie had now acknowledged there were "indications" that someone had used malware that exploited the flaws in Adobe's code.But in a follow-up article, Mr Krebs said that LaCie had now acknowledged there were "indications" that someone had used malware that exploited the flaws in Adobe's code.
Mr Krebs added that other companies that had fallen victim to related attacks included the US credit card processor SecurePay and the jam-maker Smuckers.Mr Krebs added that other companies that had fallen victim to related attacks included the US credit card processor SecurePay and the jam-maker Smuckers.
A spokeswoman for Adobe could not be reached for comment. A spokeswoman for Adobe was unable to provide comment.