UK Gaf: Boomerang rentals (possibly) hacked.

Used Boomerang years ago, but used a 3V top up card that has since been deactivated anyway, so should be safe.

They should admit being hacked if they have, so customers have a chance to avoid fraudulent charges by warning their banks, not hope it all goes away and people forget.
 
just cancelled my card as I had a £4.48 itunes payment I didn't know anything about, hopefully got it stopped before anything more serious came out.

And yes, I used Boomerang about a year ago for a month or two.
 
Boomerang offer a great service since they sorted themselves out but their PR is absolutely ridiculously shit. They are a complete shambles.

When LoveFilm went down and everyone switched to Boomerang they couldn't cope with the uplift in subscribers and their service was terrible for a short time, getting a game could take 3 weeks. Their FB and Twitter was full of ppl asking questions and they just completely ignored everyone. Didn't even make a statement until about 2 months into the issue and even then it was a shit one.

They really need to sort out their comms. It is letting the whole business down.
 
Geez...2014-2015 is the year of cyber attacks.
At this rate, Congress and the EU/UK will need to pass a stronger digital protection law and make PCI a law requirement instead of an industry standard.
And all the governments need to beef up their cyber counterattack department as well.
 
I've had nothing odd on my account although there isn't actually that much to spend there. Probably still cancel my card anyway, anyone know what the quickest was to cancel my account with boomerang is?
 
Boomerang have just posted a statement to Facebook
Boomerang Video Ltd
12/1/2015
Following an initial enquiry at the end of last week, we have had a number of customers raise concerns regarding fraudulent payment attempts on their card details that are also registered with us.
We are fully investigating this issue and have temporarily removed access to our website while this continues.
We have contacted our Payment Provider Sagepay and our Merchant Bank World Pay and neither have any reported concerns relating to us.
However, please be assured we are treating this with the utmost urgency and can provide more information on our findings as they become available.
If you have any concerns, please contact your card issuer.
We apologise for any inconvenience the removal of our site has caused and thank you for your patience as we continue to investigate further.
 
Hadn't heard of boomerang rentals before.

Peaked my interests though, how's the service? Can you rent current gen titles on that £3.99 deal?

Read on other rental sites they don't offer current gen rentals 'till you're paying over £15.

Once all this fraudulent behaviour as tied over, would it be worth signing up?
 
Hadn't heard of boomerang rentals before.

Peaked my interests though, how's the service? Can you rent current gen titles on that £3.99 deal?

Read on other rental sites they don't offer current gen rentals 'till you're paying over £15.

Once all this fraudulent behaviour as tied over, would it be worth signing up?

You can't get PS4/Xbone on the £3.99 package, have to be on the Unlimited 1 at least which is £9.99
 
I have had no issues with Boomerang up until now, If it is them of course that has been breached, I am a priority member who gets 2 new games at a time, I always get them on release day, And have saved alot of money by using them as a service as im the kind of gamer that buys games, Completes them and sells them on so renting them suits me.

I hope they treat this as serious as it seems alot of us have been hit who rent with them, And they will lose valued customers if they try sweep it under the carpet.

cancelled my card ASAP anyway.
 
One more here - recently had my bank contact me to investigate some suspicious looking transactions and it turns out they weren't made by me.

Thankfully they caught it and contacted me before allowing the money to be taken, but have had to cancel my card and have another sent.

The attempted transactions were for top ups on Vodafone and O2 mobiles, by the looks of it. Not heard a peep about it from Boomerang though, who I am a current subscriber with.
 
Different experience to me. I can count on one hand the number of times in the 5 years I haven't got a new release game on day one.

I have to agree, only been subscribed for about a month and a half but the service I was received was excellent. My only problem is I was considering cancelling it anyway because I have too much to pay already
 
Not been hit yet, ordered a new card anyway. Been checking my internet banking fascinated to see when/if the cunts try, but it seems almost assured this must be Boomerang related now.

Dunno what to do about my sub. I assume it cant continue once the card details they have are cancelled, but they must understand nobody is gonna be giving them shit in the short-term if the whole thing is shagged?

They'd just started to get vaguely good after a year of being pretty shit with new releases. Nowhere near the LoveFilm hayday though, sorely missed :(
 
Boomerang have decent 1-2-1 customer service, but its situations like this, or the shambles of when LoveFilm closed that they seem to bury their heads in the sand.

I've not been hit.
 
I wrote them an email yesterday to say I'd been hit, just had a response. It's just a rehash of the previous statement, but at least they're writing to people:

Good afternoon Turnstyle,


Thank you for your email and sorry to read that you experienced fraudulent activity on your bank account.


Following an initial enquiry at the end of last week, we have had a small number of customers raise concerns regarding fraudulent payment attempts on their card details that are also registered with us.


We are currently investigating this issue and have temporarily removed access to our website while we investigate.


We have contacted our Payment Provider Sagepay and our Merchant Bank World Pay and neither have any reported concerns relating to us.

However, please be assured we are treating this with the utmost urgency and can provide more information on our findings as they become available, if you would like us to.

If you do have any concerns, please contact your card issuer.

We apologise for any inconvenience the removal of our site has caused and thank you for your patience as we continue to investigate further.
 
I got hit yesterday with 2 transactions. One for £900 which they authorized and a second for £1200 which they blocked.

Card has been cancelled and now have to wait for card issuer to send a letter for me to sign before they give me a refund of the £900 back onto my account!

I can't believe how Boomerang are pretty much denying it too. I saw the reddit thread and then a day later my card has fraudulent transactions!

It's not a coincidence!
 
Very disappointed to learn about this through social media first.

Not at all acceptable and informed them I want my account cancelling.

Two attempted charges through John Lewis for me.
At the price given I can only assume iPads

Give me paypal
 
Storing card details to charge every month seems odd to me anyway. Why not set up direct debits or allow paypal use? I'm so annoyed right now and have cancelled my sub!
 
Checked today. £3000 used to buy Microsoft products. The irony.

Cards cancelled, fraud protection kicked in, so that's fine. Question is; what do I do now? I really like Boomerang, but is cancelling the smart thing to do? If they've got my details but I've swapped cards, I'm now 'safe' - but is there an increased/decreased chance they'll be hit again? Would changing password do anything?

Thanks.
 
I've contacted my bank, better to be safe than sorry and cancelled my card.

They say no pending charges are waiting - so fingers crossed.

Boomerang have been great in my experience and share many of the sentiments here. Such a shame and I hope this doesn't do any long term damage.

Personally, I was thinking about cancelling anyway, largely due to the fact I have a huge backlog of bought games.

Good luck to everyone getting their money back, your bank is generally very forthcoming and quickly sort these things out.
 
I got hit yesterday with 2 transactions. One for £900 which they authorized and a second for £1200 which they blocked.

Card has been cancelled and now have to wait for card issuer to send a letter for me to sign before they give me a refund of the £900 back onto my account!

I can't believe how Boomerang are pretty much denying it too. I saw the reddit thread and then a day later my card has fraudulent transactions!

It's not a coincidence!
That was when they'd only had a couple of people mention it.

You could most likely take those couple of people and find another tie. All shopped in Tesco, all ate at McDonalds, all used Amazon - the list could go on.

The important bit they missed out in their initial response though was that they would conduct a thorough investigation regardless, to their defence they did change their tune once a lot more came forward.

But has it been poorly handled? Yes.
 
Got hit last night, £670 from Sonos. My bank blocked it and called this morning to check it was genuine. Card cancelled.

Anyone that's not already, I'd probably phone and cancel your card even if you've not been hit yet, seems like it's just a matter of time before they try your card.
 
I'd mentioned this to my parents yesterday as we signed up for the Boomerang free trial a few years ago, just found out they've now been hit. We haven't had any card details on the Boomerang site for around 2 years but someone still got them.
 
I'd mentioned this to my parents yesterday as we signed up for the Boomerang free trial a few years ago, just found out they've now been hit. We haven't had any card details on the Boomerang site for around 2 years but someone still got them.
Yeah, there's multiple people reporting cards entered but inactive for years have been misused.

That shouldn't happen, under PCI guidelines they aren't even allowed to store CV2 numbers after processing, so it suggests they either didn't implement the guidelines properly (some web developers just ignore the PCI guidelines for ease and then tell the client they comply) or somebody hacked them years ago and has been storing the details themselves (a technique called CMS skimming).
 
I'd mentioned this to my parents yesterday as we signed up for the Boomerang free trial a few years ago, just found out they've now been hit. We haven't had any card details on the Boomerang site for around 2 years but someone still got them.

I removed my card details when I cancelled my sub nearly a year ago myself.

Either the hackers have been harvesting card details over the last 2+ years or Boomerang have been keeping our card details. The latter seems more likely to me.
 
Seeing what some people got hit for I'm lucky it was just a £20 Vodafone top up on my credit card last Friday. Barclaycard flagged it as suspicious and contacted me, which is how I got to knowing about this. Just waiting for the new card now.

Think I'll probably end up sending back the games I have and cancelling, but not until I can get on the site to clear my rental list. Cancellation will be accompanied by an e-mail demanding the complete removal of all my details from their system.
 
Man looks like I'm lucky I changed bank a couple of months ago. Shame as I quite liked Boomerangs service and only stopped using them as I was trying to cut back on expenses.
 
Wow so there's people without credit card details on the site anymore for years and they still got hacked, shit. Better cancel my card just in case.

I gotta say, not looking good for Boomerang.
 
Seeing what some people got hit for I'm lucky it was just a £20 Vodafone top up on my credit card last Friday. Barclaycard flagged it as suspicious and contacted me, which is how I got to knowing about this. Just waiting for the new card now.

Think I'll probably end up sending back the games I have and cancelling, but not until I can get on the site to clear my rental list. Cancellation will be accompanied by an e-mail demanding the complete removal of all my details from their system.

I wouldn't worry too much. If they get through this I think they will have to invest in security and overhaul their procedures. You can survive a hack like this but not many survive two hacks. Shopto survived a similar ordeal but if they got hacked a second time I think they would struggle to recover.
 
http://ow.ly/d/2SlQ

They have posted a pdf press release, can some one do a copy and paste (it is tricky on my phone).


Edit: in summary they will introduce a token system instead of storing payment details, considering PayPal, and the will email all customers soon.

Site will remain offline until these changes have been made.
 
What happened

On Friday we were contacted by a customer who was concerned that a fraudulent charge had been attempted on his credit card, and he was worried that our system had been compromised. He quoted another person who had made a comment on Twitter of a similar issue.

What we did

We began an investigation as soon as additional concerns were raised. Credit card data is stored in a strongly encrypted format and not viewable to any internal staff, however, at that stage, we felt we should take the concerns seriously. Over the weekend, we noticed other people online reporting similar issues and we became increasingly concerned. So, based on the information available at the time and conscious of the concern, we made the decision on Sunday afternoon to take the site off line while we continued our investigations.

Where we are


By Monday morning, we had been contacted directly by a small number of additional customers. We contacted the fraud department of our merchant bank, but they knew of no issue. We also contacted our payment gateway provider and they also had no concerns. They are assisting us in a consultative capacity. By this time we could see lots of people talking about this online, but only a few people had contacted us directly.
To date we have not found any evidence of a breach of our systems. We are continuing to investigate and continue to take this issue very seriously. We have also made the decision to very quickly move over to a token method of payment which obviates the need to have encrypted data on our servers, to give our customers further reassurance.
We would not ever wish to be the source of customer card information being compromised, so are making this change urgently. This work will take about a week, and we have removed the card details in their encrypted form, from our online
system, and are removing the facility to update or provide card details until the work is complete. Subscriptions will be processed daily each weekday morning under further supervised controls. Once the new system is in place, we will be able to collect payments through the token system.

We will also investigate the possibility of introducing PayPal as a form of payment as well, to offer our customers further choice.

What next

First we will start to process incoming and outgoing rentals. Then, once we are satisfied that our investigations are complete, we will bring our website back on line so existing customers can see their rental lists. We apologise for the inconvenience caused to our customers while this work is undertaken. Once everything is running again, we will be back in touch and will include updates at that time.

Finally, we would like to re-emphasise that we have not found any evidence of a breach in our systems (our systems were regularly tested for vulnerabilities by a 3rd party specialising in this) but our Engineers and Technical Advisors continue to investigate.
We are aware of the interest and concern this situation has raised and care about our customers and our reputation greatly and are urging our customers to get in touch with us immediately if they have any concerns. We will shortly be sending an email directly to each of our customers.

Telephone: 01604 654140
Email: customersupport@boomerangrentals.co.uk

.
 
"We also contacted our payment gateway provider and they also had no concerns."

Pro-tip: They should no longer be your payment gateway provider because theyre fucking reckless, shit, lazy, and seemingly clueless.
 
Cancelled my card last night just to be on the safe side. I tweeted them last night asking if I could cancel my subscription while the site was down and I got this reply:

H7yOAof.png


They later tweeted me and asked me to DM them to get it cancelled but that's just :/

I'm still amazed they haven't sent an email out to customers either. Their most recent statement says they will shortly but its been just short of four days since the first reported incident.
 
They can't find any evidence of wrong doing? hmmmmmm

Maybe the wrong people are looking. Or it could have been a clever hack or even an inside job.

The circumstantial evidence is overwhelming but the physical evidence might be harder to find. They might have to hire someone who actually knows what to look for.

"We also contacted our payment gateway provider and they also had no concerns."

Pro-tip: They should no longer be your payment gateway provider because theyre fucking reckless, shit, lazy, and seemingly clueless.

How sure are you the flaw was in the system of the payment processor? They (boomerang) already admitted to storing card info, even from cancelled accounts, on their own systems - encrypted or not.


Cancelled my card last night just to be on the safe side. I tweeted them last night asking if I could cancel my subscription while the site was down and I got this reply.
I'm still amazed they haven't sent an email out to customers either. Their most recent statement says they will shortly but its been just short of four days since the first reported incident.

RE: cancelling. They have deleted all payment details (so they claim) - so if you send all the games back then you are essentially cancelled as they have no card details to bill you with. Just formally cancel by email or when the site is back up.
 
"We also contacted our payment gateway provider and they also had no concerns."

Pro-tip: They should no longer be your payment gateway provider because theyre fucking reckless, shit, lazy, and seemingly clueless.
It would be very unlikely to be the payment processor. If it was the payment processor then there'd be thousands of people going 'my account and monies and blah blah blah!'.
 
It would be very unlikely to be the payment processor. If it was the payment processor then there'd be thousands of people going 'my account and monies and blah blah blah!'.

Their payment processor is Sage Pay, who are big. The other company is WorldPay, who are huge.

It likely isn't them. Boomerang have a single server running, for example, their cart PHP system (on MySQL, which stores CC info) -- along with an old install of Wordpress with a known exploitable template on the same MySQL database. Have a look yourself, it is text book breach material.

It's all remotely managed, and their IT is outsourced to Freetimers.com, who also work remotely. It also appears to be single factor authentication, no antivirus. Anybody who also works in security (hello) will know the problems here.

Edit - breaches like this also sometimes stem from databases being backed up elsewhere, then the backups being owned. Given the number of people affected, somebody screwed up somewhere.
 
How sure are you the flaw was in the system of the payment processor? They (boomerang) already admitted to storing card info, even from cancelled accounts, on their own systems - encrypted or not.

It would be very unlikely to be the payment processor. If it was the payment processor then there'd be thousands of people going 'my account and monies and blah blah blah!'.

While I doubt its SagePay, for me its the language Boomerang has used throughout where its like "no concerns". Yeah, none, really? Everythings fine, go back to sleep. I imagine SagePay would have at least said "you need to seriously check your shit on your end" or offered some advice the more this became obviously tied to Boomerang.

Is Boomerang run mainly by non-English-as-a-first-language people because thats the feeling I get often with them. The website always seemed like cobbled together shit, and well, now its most damning aspect has come to light.
 
Top Bottom