Unconfigured Ad Widget

Collapse

AIM Surplus had a data breach

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • bender152
    Veteran Member
    • Nov 2006
    • 4237

    AIM Surplus had a data breach

    Here's a thread on it on their arfcom industry page.
    True or not? Apparently customer ID images, FFL images, order history were compromised; and AIM sent notice to affected customers. I have not been notified yet.--Edit to add: The notification letter


    I have not received a letter, but others in the thread above are confirming that they have.

    Below is a pic of the letter going out (not mine).
    Here's a link to a larger version: http://imgur.com/POn92B0

  • #2
    elSquid
    In Memoriam
    • Aug 2007
    • 11844

    Got the letter today. 2 pages, double sided.

    They're offering a year of credit monitoring by Experian. Must register by July 31.

    -- Michael

    Comment

    • #3
      SonofWWIIDI
      I need a LIFE!!
      • Nov 2011
      • 21583

      Thanks for the headsup.
      Sorry, not sorry.
      🎺

      Dear autocorrect, I'm really getting tired of your shirt!

      Comment

      • #4
        frank8097
        Banned
        • Feb 2010
        • 814

        Wtf? save that stuff on a flash drive for f's sake. last time i ordered from these turkeys, was maybe 2 years ago or a little less. hope someone doesn't take out a loan under my name.

        Comment

        • #5
          MarikinaMan
          Veteran Member
          • Nov 2015
          • 4864

          Crap.

          Comment

          • #6
            peterabbits
            • Apr 2010
            • 1266

            I got my letter last night. It's been at least 3 years since I bought from them, but still.

            Comment

            • #7
              Mac Attack
              Senior Member
              • Apr 2008
              • 2126

              Dang I have bought from them within the last 3 years.

              Comment

              • #8
                LowThudd
                Veteran Member
                • Dec 2011
                • 3608

                Dam. I was just about to order from them as well.

                So, I take it from the ARF.com thread, it is mainly that images of drivers licenses and FFLs were breached?

                Comment

                • #9
                  Paulo
                  Member
                  • Apr 2014
                  • 258

                  sucks. I don't recall uploading any images to their site though. I mainly bought spare AR parts.

                  Comment

                  • #10
                    beanz2
                    I need a LIFE!!
                    • Nov 2008
                    • 12032

                    I think the data they'd get from what I uploaded can already be obtained from my FB page.
                    sigpic
                    The wife will be pissed, but Jesus always forgives.

                    Comment

                    • #11
                      CALI-gula
                      Calguns Addict
                      • Jan 2006
                      • 7047

                      I read through the AR15.com thread, but I did not see any of my concerns addressed:

                      1) Any indication of how far back of orders they were holding DL imagery?

                      2) Last I ordered from them, I had a P.O. Box for billing, and all orders shipped to my office; however, my DL would have my home address on it like most other people. So to what address are they sending the letters? (So far, no letter for me but if they sent it to my prior ship-to or P.O. Box, worse still I won't get it but someone else might!)

                      3) If it's images breached, does that mean that saved PDFs of the order receipts would also have been captured? They aren't specifying what images were accessed.

                      4) WHY would they hold onto DL images for so long? I get it might be a CYA thing, but they should have purged those files at 6 months max or saved them off their network. Stupid.

                      .
                      ------------------------

                      Comment

                      • #12
                        pbsmind
                        Senior Member
                        • Jun 2011
                        • 527

                        Got my letter today. Might of exposed my DL and C&R License. Letter said financial data wasn't leaked but their uploaded documents were.
                        "He is no fool who gives what he cannot keep to gain that which he cannot lose." - Jim Elliot

                        Comment

                        • #13
                          hermosabeach
                          I need a LIFE!!
                          • Feb 2009
                          • 19392

                          who cares about financial data.... what a way to target homes to burglarize
                          Rule 1- ALL GUNS ARE ALWAYS LOADED

                          Rule 2 -NEVER LET THE MUZZLE COVER ANYTHING YOU ARE NOT PREPARED TO DESTROY (including your hands and legs)

                          Rule 3 -KEEP YOUR FINGER OFF THE TRIGGER UNTIL YOUR SIGHTS ARE ON THE TARGET

                          Rule 4 -BE SURE OF YOUR TARGET AND WHAT IS BEYOND IT
                          (thanks to Jeff Cooper)

                          Comment

                          • #14
                            CALI-gula
                            Calguns Addict
                            • Jan 2006
                            • 7047

                            Originally posted by hermosabeach
                            who cares about financial data.... what a way to target homes to burglarize
                            CA DOJ/BOF DROS filing website on deck.

                            .
                            ------------------------

                            Comment

                            • #15
                              laurelpark
                              Senior Member
                              • Aug 2011
                              • 1013

                              Not sure if their username/password database was breached or not - but it would be wise to make sure that you don't re-use the username/password combo on any other site... Most people re-use them all over the place, so if one place gets hacked, all of a sudden the bad guys have your credentials in many other places.

                              Comment

                              Working...
                              UA-8071174-1