Acer settles online breach probe for $115k: Difference between revisions

fixed archived date
added archive link with archive date
Line 27: Line 27:
==Consumer response==
==Consumer response==


Consumers expressed frustration, distrust, and tangible harm following Acer’s data breach. On HardForum, several posters reported that they never received a notification from Acer despite being affected, and some discovered fraudulent charges on their credit cards after purchasing through Acer’s online store.<ref>{{Cite web |author=HardOCP News |date=2016-06-20 |title=Acer Admits Hackers Stole Up To 34,000 Customer Credit Cards |url=https://hardforum.com/threads/acer-admits-hackers-stole-up-to-34-000-customer-credit-cards.1902876/ |url-status=live |access-date=2025-08-18 |website=[H]ardForum}}</ref> Others criticized Acer for mishandling sensitive payment data, particularly for storing CVV codes, which violates standard payment card security rules. The overall tone was one of anger at both the breach and Acer’s poor communication.
Consumers expressed frustration, distrust, and tangible harm following Acer’s data breach. On HardForum, several posters reported that they never received a notification from Acer despite being affected, and some discovered fraudulent charges on their credit cards after purchasing through Acer’s online store.<ref>{{Cite web |author=HardOCP News |date=2016-06-20 |title=Acer Admits Hackers Stole Up To 34,000 Customer Credit Cards |url=https://hardforum.com/threads/acer-admits-hackers-stole-up-to-34-000-customer-credit-cards.1902876/ |url-status=live |archive-url= |archive-date= |access-date=2025-08-18 |website=[H]ardForum}}</ref> Others criticized Acer for mishandling sensitive payment data, particularly for storing CVV codes, which violates standard payment card security rules. The overall tone was one of anger at both the breach and Acer’s poor communication.


On The Register’s forum, reactions were similarly skeptical and critical.<ref>{{Cite web |last=Nichols |first=Shaun |date=2016-06-17 |title=You Acer holes! PC maker leaks payment cards in e-store hack |url=https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |access-date=2025-08-18 |website=The Register}}</ref> Commenters condemned Acer for failing to follow PCI DSS compliance standards and for allowing card verification codes to be compromised.<ref>{{Cite web |last=Pasher |first=Justin |date=2016-06-17 |title=Re: Storing CC security verification codes |url=https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |access-date=2025-08-18 |website=Forum on 'The Register'}}</ref> Some users confirmed they did receive breach notification letters, though experiences varied widely. Many expressed concern that Acer’s negligence would push costs and risks onto consumers through fraudulent charges and credit monitoring needs.
On The Register’s forum, reactions were similarly skeptical and critical.<ref>{{Cite web |last=Nichols |first=Shaun |date=2016-06-17 |title=You Acer holes! PC maker leaks payment cards in e-store hack |url=https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |archive-url=https://web.archive.org/web/20260104042936/https://www.theregister.com/2016/06/17/what_a_pain_in_the_acer/ |archive-date=2026-01-04 |access-date=2025-08-18 |website=The Register}}</ref> Commenters condemned Acer for failing to follow PCI DSS compliance standards and for allowing card verification codes to be compromised.<ref>{{Cite web |last=Pasher |first=Justin |date=2016-06-17 |title=Re: Storing CC security verification codes |url=https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |url-status=live |archive-url=https://web.archive.org/web/20260104043419/https://forums.theregister.com/forum/all/2016/06/17/what_a_pain_in_the_acer/ |archive-date=2026-01-04 |access-date=2025-08-18 |website=Forum on 'The Register'}}</ref> Some users confirmed they did receive breach notification letters, though experiences varied widely. Many expressed concern that Acer’s negligence would push costs and risks onto consumers through fraudulent charges and credit monitoring needs.


Consumers faced heightened risks of identity theft and financial fraud due to the exposure of full credit card details, login credentials, and personal addresses. The fact that sensitive data was stored unencrypted in plain text worsened concerns about Acer’s handling of private information. While the settlement imposed stronger protections going forward, many customers were left to deal with potential fraudulent charges, credit monitoring, and long-term distrust in Acer’s ability to safeguard their personal information. Public statements from the Attorney General emphasized consumer expectations for companies to uphold basic data security standards, reflecting broader frustration with corporate negligence in protecting private data.<ref name=":0" />
Consumers faced heightened risks of identity theft and financial fraud due to the exposure of full credit card details, login credentials, and personal addresses. The fact that sensitive data was stored unencrypted in plain text worsened concerns about Acer’s handling of private information. While the settlement imposed stronger protections going forward, many customers were left to deal with potential fraudulent charges, credit monitoring, and long-term distrust in Acer’s ability to safeguard their personal information. Public statements from the Attorney General emphasized consumer expectations for companies to uphold basic data security standards, reflecting broader frustration with corporate negligence in protecting private data.<ref name=":0" />