Regarding “Apology and Notice Regarding Credit Card Information Leakage Due to Unauthorized Access to Our Website,” we have compiled the frequently asked questions below.
Q) The period during which there was a possibility of leakage is said to be from November 27, 2020 to December 9, 2020. I made a payment outside that period, so is it safe?
A) We are conducting an investigation by a third-party research organization. Aside from the 195 credit cards paid for during the above period, there is no possibility of leakage. Please rest assured. If you have any questions, please feel free to contact our inquiry desk. In addition, after analyzing the purchase dates of customers whose cards were actually used fraudulently, the cases are concentrated among customers who made purchases on 12/2, 12/3, 12/4, 12/8, and 12/9.
Q) Will I be able to use the service safely going forward?
A) We take this matter very seriously and have implemented all necessary measures to improve security as instructed by the third-party investigation agency. We will continue to work to improve security and do our utmost to restore our customers' trust.
Q) It took a great deal of time to respond to fraudulent use, reissue cards, and complete change procedures. Is there any compensation?
A) As explained in the main text, we will bear all costs related to fraudulent use and card replacement expenses. We deeply regret the trouble caused to our customers and once again offer our sincere apologies. We will provide updates on the measures and responses we take going forward, so we kindly ask for your continued understanding and cooperation.
Q) The initial discovery was on 12/9/2020, and the announcement was on 3/29/2021. Why was the announcement delayed so much?
A) We worked day and night with credit card companies and investigative firms with the goal of notifying our customers as quickly as possible, but we sincerely apologize that the notification ended up being at this time. We had been consulting with the credit card companies, but to avoid unnecessary confusion, we were unable to contact customers earlier. After the third-party investigation agency completed its investigation and we received confirmation from each card company, we were finally able to notify our customers.
Q) Please tell us about the security improvements you have implemented so far.
A) To ensure that a similar incident never happens again, we implemented the following measures.
・We immediately fixed the vulnerability in the file upload function and enabled SELinux, improving security against tampering. (December 2020)
・We migrated the server environment to a secure public cloud environment built with the latest OS/middleware. (December 2020)
・We introduced a high-performance firewall (WAF) and implemented measures to block unauthorized access and attacks. (January 2021)
・We introduced two-factor authentication for the server environment and management tools. (February 2021)
・We installed antivirus software on the server and perform regular virus checks. (February 2021)
・We regularly apply critical OS/middleware-level patches. (March 2021)
・We introduced an FIM (File Integrity Monitoring) solution to detect file tampering. (April 2021)
・In addition to the above, we have also implemented various other security enhancement measures.
Q) Please tell us about the security improvements you plan to implement going forward.
A) Under the guidance of the third-party investigation agency and a security specialist company, we plan to implement the following measures.
・Regular security assessments by a security specialist company.
・Regular internal vulnerability assessments.
・Long-term log retention through the use of SIEM (Security Information and Event Management)
・In addition to the above, we will continue to implement measures to strengthen system robustness.
Q) Were credit card details (card number, expiration date, security code) stored on the server?
A) No. We used a PCI-DSS-compliant non-retained (JavaScript-based) payment service provided by Stripe, and no customer credit card information was stored on our servers at all. This attack worked by tampering with the payment page and placing a similar input form that closely resembled the original credit card input form, so that when the payment button was pressed, the entered information was forwarded to the attacker’s site.
Q) What does it mean that there is a possibility of credit card information leakage? Does that mean it may not have leaked?
A) We were not able to confirm that information was actually forwarded to the attacker’s site, and we are proceeding with the process for all cards used while the attack file was present on the server as "possibly" affected. Therefore, customers who paid during this period may in fact not have had their information leaked. After analyzing the purchase dates of customers whose cards were actually used fraudulently, the cases are concentrated among customers who made purchases on 12/2, 12/3, 12/4, 12/8, and 12/9. During other periods, the fake form may have been removed (※ this was also actually confirmed by us).
Q) If fraudulent use occurred, how will reimbursement be handled? Also, will there be any fees for card replacement?
A) All expenses incurred in connection with this incident will not be borne by the customer. As stated in the main text of the report, please be sure to check your credit card statement and contact your credit card company if you find any unauthorized use.
Q) Will ApparelX continue to provide services going forward?
A) We take this matter very seriously and have implemented all necessary measures to improve security as instructed by the third-party investigation agency. We will continue to work to improve security and do our utmost to restore our customers' trust.
Q) I would like to withdraw from ApparelX and delete all information. Can you do that?
A) Please delete your account information from Account Deletion in My Account. All information stored on our website will be deleted.
Q) When will credit card payment acceptance resume?
A) We are currently consulting with our payment processor. When service resumes, we will announce it on the website. (Added on 4/28) After approval from each card company, we resumed credit card payments on 2021/4/28.