Category: Cyber Security Breach

Screenshot from networksolutions.com requesting that users change their password.
Cyber Security BreachPhishingSecurityVulnerabiltyWeb Development

Cybersecurity Incident or Full Blown Breach at Web.com, Register.com, and NetworkSolutions.com

As painful as it is to announce this, what some consider the 5th largest domain registration company in the world has been breached. Or should we call it a cybersecurity incident as they claim in their mea culpa, comforting customers that, “No credit card data was compromised as a result of this incident?” (Emphasis ours). The mea culpa is posted on a subdomain of their website: https://notice.web.com/ where they publish the following FAQ.

Frequently Asked Questions

What happened? On October 16, 2019, Web.com determined that a third-party gained unauthorized access to a limited number of our computer systems in late August 2019, and as a result, account information may have been accessed. No credit card data was compromised as a result of this incident.

What are you doing about it? Upon discovery, we took immediate steps to stop the intrusion. We promptly engaged a leading independent cybersecurity firm to investigate and determine the scope of the incident. We notified the proper authorities and began working with federal law enforcement.We are notifying affected customers through email and via our website, and as an additional precaution are requiring all users to reset their account passwords.

What data/information was involved? Our investigation indicates that account information for current and former Web.com customers may have been accessed. This information includes contact details such as name, address, phone numbers, email address and information about the services that we offer to a given account holder.We encrypt credit card numbers and no credit card data was compromised as a result of this incident.

What can I do to protect my account? We have already taken additional steps to secure your account, and there is nothing you need to do at this time. The next time you log in to your account you will be required to reset your password.As with any online service or platform, it is also good security practice to change your password often and use a unique password for each service.

Is my credit card information at risk? We store credit card numbers in a PCI (Payment Card Industry) compliant encryption standard and do not believe your credit card information is vulnerable as a specific result of this incident. That said, it is good practice to monitor your credit card account and we encourage you to notify your credit card provider if you see any suspicious charges.

Should I reset my password as part of this? We have already taken additional steps to secure your account, and there is nothing you need to do at this time. The next time you log in to your account you will be required to reset your password.As with any online service or platform, it is good security practice to change your password often and use a unique password for each service.

FAQ on the Important Safety information at notice.web.com

KrebsOnSecurity was among the first if not the first to break the news to the public in an article published on October 30th. According to Krebs.

Web.com encourages customers to call them with any questions. The phone number is available on the notice page they published.

Our word of advice here: please do not reuse passwords and setup multifactor authentication where possible.