Thanks xStainDx...A security hole on Tower Records' Web site exposed data on millions of U.S. and U.K. customers until it was closed late Wednesday. The glitch allowed anyone to peruse Tower Records' Web site to view its database of customer orders dating from 1996 through this week, including home and e-mail addresses, phone numbers and what music or video products were purchased. More than 3 million such records were exposed.
"It was a technical error, and when we discovered it we were fairly horrified and we fixed it in a matter of hours," a Tower representative said on Thursday. No credit card numbers appear to have been revealed, the company said.
Stephanie Wilbanks of Jonesboro, Ark., had her personal information exposed after she ordered a CD as a gift from Tower Records this week. "I'm shocked and disappointed," Wilbanks said. "I will no longer do online business with Tower Records." But another affected customer, Ivor Colwill of Haywards Heath, England, said he wasn't as concerned.
"I doubt it'll affect my shopping at Tower," Colwill said. "I honestly can't think of another site that covers so many of my musical needs in one spot or with the same quality of service. At worst, I'll telephone my orders to them."
The security leak arose out of a programming error in a script called "orderStatus.asp." When customers requested information on their order via the Tower site, the script called up the record, displaying the order number as part of the URL of the resulting page.
View: The full story
News source: c|net