Skip to main content
Back
Vibram USA, Inc.

Vibram USA, Inc. Data Breach (2014)

Vibram USA, Inc.

lowVERIS
Disclosed

June 6, 2014

4312 days ago

Records

Undisclosed

Confirmed

Root Cause

Hacking

Industry

Manufacturing

Description

It appears that from June 6th until July 7th that the hosting provider for Vibram was the victim of a targeted attack. Seems that the hosting provider's security failed Vibram allowing the attackers to help them selves to data. A five finger discount, if you'll pardon the pun. As a result, your Vibram customer data was potentially compromised if you made a purchase on their website during that time frame. From customer notification: Vibram USA Inc. contracts with a third-party web hosting provider to manage its website: www.vibramfivefingers.com. Our records show that you made a purchase from this website during the period of June 6 - July 7, 2014. We have been informed that this website was the victim of a targeted hacking attack potentially causing your credit card number to be compromised. The root of the problem was that the web server had been compromised and malicious code installed by miscreants. Vibram took the step of dumping their hosting provider for a new one as well as implementing stricter security controls. While it is unfortunate that their site was breached, coming close on the heels of losing a large lawsuit, I am happy to see that they took some steps to better secure their site. Lesson to be learned here is that when you have other players introduced into your digital supply chain that you take the time to ensure that they can be counted on as your trusted partner. Don't be afraid to ask your supply chain partners the tough questions.

Vibram USA, Inc. Data Breach (2014) | ExposedMap