closing tag is in template navbar
timefactors watches



TZ-UK Fundraiser
Results 1 to 27 of 27

Thread: Watchfinder Data Breach

  1. #1

    Watchfinder Data Breach

    Sharing this in case any customers don’t receive the email. Beware of any emails or phone calls claiming to be from WF or asking about your watches. Not having a dig at Watchfinder as this could happen to anyone.




    Sent from my iPhone using Tapatalk

  2. #2
    Craftsman
    Join Date
    Jun 2011
    Location
    York
    Posts
    947
    Just had the same email come through.

    It could be very dangerous in the wrong hands, someone interested enough would be able to find your address with an email and phone number.
    They would also know the watches you've bought so high spenders could be flagged easily.

  3. #3
    Master
    Join Date
    Jan 2018
    Location
    UK
    Posts
    3,217
    That is very dangerous data to be out there! Just going to look back now when quoting if they ask for an address. Hopefully not.

  4. #4
    Grand Master wileeeeeey's Avatar
    Join Date
    Jan 2017
    Location
    N/A
    Posts
    19,168
    Got the email too. Thankfully I’ve never done more than enquire so it’s limited to name and email.

  5. #5
    Craftsman FellBasher's Avatar
    Join Date
    May 2014
    Location
    North West UK
    Posts
    469
    Email here too. I’ve bought and sold with WF, have an account password etc. I did wonder if it would create a thread.

  6. #6
    Craftsman
    Join Date
    Jan 2020
    Location
    Fleet
    Posts
    398
    I also received the same email today. What’s worrying is that the breach seems to have come from one of their employees !!!

  7. #7
    Master M1011's Avatar
    Join Date
    Jun 2020
    Location
    London, England
    Posts
    3,252
    Quote Originally Posted by Highroller1 View Post
    I also received the same email today. What’s worrying is that the breach seems to have come from one of their employees !!!
    To be clear, they're saying there was unauthorised access to one of their employees account, not that an employee instigated the data leak.

  8. #8
    Craftsman
    Join Date
    Aug 2010
    Location
    Hertfordshire UK
    Posts
    894
    I read it that someone accessed one of their employees accounts without authorisation.

  9. #9
    Journeyman
    Join Date
    Jun 2020
    Location
    Bristol, England
    Posts
    60
    A lot of hacks lately which are down to social engineering, rather than compromised systems. It seems a lot of businesses were unprepared for this kind of attack.

  10. #10
    Master PhilipK's Avatar
    Join Date
    Aug 2010
    Location
    Hampshire, UK
    Posts
    4,223
    Quote Originally Posted by dbrickashaw View Post
    A lot of hacks lately which are down to social engineering, rather than compromised systems.
    All security is down to three elements: "People, Process and Technology".

    I spend much of my professional lifetime in cyber security trying to get as much emphasis put on the People and Process bits as on the Technology. It's amazing how many organisations would say "but we've got a firewall and 256-bit encryption, so we must be secure", and then get quite embarrassed when you started delving into their recruitment procedures and password-change processes...

  11. #11
    Craftsman
    Join Date
    Feb 2017
    Location
    Dorset
    Posts
    437
    Hmmm, I’ve received this too but have only ever made an online enquiry so shall double check what details I left!

    Thanks


    Sent from my iPhone using Tapatalk

  12. #12
    Master
    Join Date
    Oct 2019
    Location
    East Anglia
    Posts
    1,847
    Blog Entries
    2
    I got the email today.

  13. #13
    Craftsman
    Join Date
    Jan 2022
    Location
    London UK
    Posts
    288
    Got the same email today. Have only ever enquired

  14. #14
    Master
    Join Date
    Aug 2017
    Location
    London, UK
    Posts
    2,878
    I also received the email but the wording infers my enquiry was about a watch they were selling as opposed to some I was requesting a quote to sell.

    Very big difference between an old enquiry on buying a watch and disclosing a list of watches and home address.

    I’ve asked them to clarify what data they lost.

  15. #15
    Quote Originally Posted by joe narvey View Post
    I also received the email but the wording infers my enquiry was about a watch they were selling as opposed to some I was requesting a quote to sell.

    Very big difference between an old enquiry on buying a watch and disclosing a list of watches and home address.

    I’ve asked them to clarify what data they lost.
    My email stated:

    The records in question may include your e-mail address, telephone number and/or any watches that you have expressed an interest in. They do not include any postal addresses, passwords, credit card details or other banking information.

  16. #16
    Master
    Join Date
    Aug 2017
    Location
    London, UK
    Posts
    2,878
    Thanks. I will sure their response.

  17. #17
    Grand Master MartynJC (UK)'s Avatar
    Join Date
    Dec 2008
    Location
    Somewhere else
    Posts
    12,361
    Blog Entries
    22
    Got my email today. Thanks WF
    “ Ford... you're turning into a penguin. Stop it.” HHGTTG

  18. #18
    Master
    Join Date
    Jan 2018
    Location
    UK
    Posts
    3,217
    Quote Originally Posted by MacDeath View Post
    My email stated:

    The records in question may include your e-mail address, telephone number and/or any watches that you have expressed an interest in. They do not include any postal addresses, passwords, credit card details or other banking information.
    Just spotted the email in my junk today. Was sent yesterday. Mine said the same as above.

    If a user account was compromised probably all their account data was compromised. I would like to know how they are so sure that ‘postal addresses’ are not compromised.

  19. #19
    Master
    Join Date
    Dec 2013
    Location
    Chester and Merseyside, UK
    Posts
    4,330
    Somewhere in Russia, a teenager right now is highlighting the name and address of Nadeem Malick and thinking he’s hit the jackpot.

  20. #20
    From the handbag thread someone pointed out for a fee a company will provide an address if you have their mobile number

  21. #21
    Master
    Join Date
    Aug 2017
    Location
    London, UK
    Posts
    2,878
    Response from WF

    We discovered unauthorised access to an employee account which contained lists of our current and prospective customers. The lists contain e-mail addresses, telephone numbers, purchase histories and watches in which customers have expressed an interest. They do not include postal addresses passwords, credit card details or other banking information.

  22. #22
    Master M1011's Avatar
    Join Date
    Jun 2020
    Location
    London, England
    Posts
    3,252
    Quote Originally Posted by Boss13 View Post
    Just spotted the email in my junk today. Was sent yesterday. Mine said the same as above.

    If a user account was compromised probably all their account data was compromised. I would like to know how they are so sure that ‘postal addresses’ are not compromised.
    Presumably because the employee didn't have access to postal addresses, not unusual for access to be related to the employees job. They probably had a list of names, emails and phone numbers for marketing/sales purposes I'm guessing.

  23. #23
    Master ozzyb123's Avatar
    Join Date
    Jun 2019
    Location
    London
    Posts
    1,029
    Is getting the email

    The new getting the call?


    Sent from my iPhone using Tapatalk

  24. #24
    Craftsman
    Join Date
    Aug 2010
    Location
    Hertfordshire UK
    Posts
    894
    I've bought and sold with them and can't say I'm overly amused by this. Took a little longer for them to email me, but there it is.

  25. #25
    Master
    Join Date
    Feb 2010
    Location
    Cheshire
    Posts
    1,791
    I've had it too.

    After receiving a dismal offer to trade them one of my watches a few weeks ago, I thought I'd try again last weekend and went through the online process. Within seconds of me hitting submit, another dismal offer was generated. Times, they are a changing.

  26. #26
    Master
    Join Date
    Sep 2016
    Location
    UK
    Posts
    1,723
    I use unique addresses for each company I deal with.

    Received an unsolicited email today signing me up to digital assets company called Nexo.

  27. #27
    Master
    Join Date
    Dec 2013
    Location
    Chester and Merseyside, UK
    Posts
    4,330
    Quote Originally Posted by Chalet View Post
    I use unique addresses for each company I deal with.

    Received an unsolicited email today signing me up to digital assets company called Nexo.
    Yes, NEXO have just sent me a similar email. Seems probable they have that Watchfinder data....

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Do Not Sell My Personal Information