I hate to be the bearer of bad news, but I thought this was pertinent to the community since I believe some of us have purchased yarn and other stuff from Knit Picks.
If you ordered something from the Knit Picks online store from late 2012 to 2013 then you need to call your CC company/Bank post haste to report the card lost/stolen and to see if there are any fraudulent charges. Someone used a security exploit of the web software that handles transactions to gain access to the consumer database for online orders. They say even if you did not order from KP recently but in the near past, it is a good idea to report the card you used and check your statements. I ordered from them a few years back and did not hesitate to report my card and cut it up just now.
Here's the official statement from the CEO.
Here is a guide (unofficial) for those who might have been compromised.
The facebook page for KnitPicks is alive with discussion about this mess.
If you ordered something from the Knit Picks online store from late 2012 to 2013 then you need to call your CC company/Bank post haste to report the card lost/stolen and to see if there are any fraudulent charges. Someone used a security exploit of the web software that handles transactions to gain access to the consumer database for online orders. They say even if you did not order from KP recently but in the near past, it is a good idea to report the card you used and check your statements. I ordered from them a few years back and did not hesitate to report my card and cut it up just now.
Here's the official statement from the CEO.
Here is a guide (unofficial) for those who might have been compromised.
The facebook page for KnitPicks is alive with discussion about this mess.
(no subject)
Date: 2013-02-20 07:37 pm (UTC)(no subject)
Date: 2013-02-20 08:12 pm (UTC)I'm more concerned about the fact they had credit card numbers unencrypted on their system in the first place; I seriously doubt they're PCI compliant (because that's a bitch and a fucking half) -- they shouldn't store customer credit card data at all, anywhere, without that.
(I do love the people on Facebook who are like "this is why I pay with PayPal, it's safer!" Um, no, it really, really isn't...)
(no subject)
Date: 2013-02-20 08:18 pm (UTC)The only problem is that some people who haven't ordered with KP in a while have recently received fraudulent charges on the card they used with KP, so even if you may not have ordered with them recently, you may still be affected, letter or not. (ravelry members have reported this occurrence)
(no subject)
Date: 2013-02-20 09:05 pm (UTC)I haven't received a letter yet, either, but I'm Canadian and the letter from the CEO did say that the Canadian letters haven't been sent yet.
(no subject)
Date: 2013-02-20 10:36 pm (UTC)(no subject)
Date: 2013-02-21 12:07 am (UTC)I'm more concerned about the fact they had credit card numbers unencrypted on their system in the first place;
I'm seriously concerned about this bit. I love their products, but I'm not sure about buying from them in the future, or doing it without looking into ways of protecting the number from them (or just biting the bullet and getting a card just for buying online).
(no subject)
Date: 2013-02-21 12:13 am (UTC)(no subject)
Date: 2013-02-21 02:39 am (UTC)(no subject)
Date: 2013-02-21 04:14 pm (UTC)(no subject)
Date: 2013-02-21 03:32 am (UTC)I heard about this from a friend before the linked blog post, and still haven't heard from Knitpicks.
(no subject)
Date: 2013-02-21 04:09 am (UTC)(no subject)
Date: 2013-02-22 07:00 pm (UTC)It's kind of a relief to know where my number was compromised.
(no subject)
Date: 2013-03-13 04:43 am (UTC)