AIM Surplus Security Breach

The #1 community for Gun Owners in Indiana

Member Benefits:

  • Fewer Ads!
  • Discuss all aspects of firearm ownership
  • Discuss anti-gun legislation
  • Buy, sell, and trade in the classified section
  • Chat with Local gun shops, ranges, trainers & other businesses
  • Discover free outdoor shooting areas
  • View up to date on firearm-related events
  • Share photos & video with other members
  • ...and so much more!
  • BugI02

    Grandmaster
    Rating - 0%
    0   0   0
    Jul 4, 2013
    32,555
    149
    Columbus, OH
    Dear online retailers

    #1 Stop archiving information on your customer base for any longer than necessary, by which I mean longer than the chargeback window of the associated credit card.

    #2 Put some ****ing security on the information you do keep. Encrypt your database, with modern computers the overhead in cost and latency is minimal

    Sadly, until retailers are themselves financially responsible for the harm caused by low security data (which will feed the class action sharks, unfortunately) there is no 'evolutionary' pressure to change the way they do business.

    IIRC in an early and infamous breach of a debit and credit card database, the TJX breach (T J Max, Marshall's etc), the company had data on its customers accounts going back at least five years. WTF are they doing keeping this much data. If you bought one thing in one affiliated store ever you were as much at risk as anybody else. Multiply that by the number of companies you do business with via credit card.

    The OPM breach was even worse. If you had a background check they know everything about you needed to steal your identity. If you have a clearance like I do they have that information on your family and even possibly some of your friends.

    I have my data stored on my desktop Mac with far greater security than almost every entity I do business with uses. You can personally follow best practices and be savvy and cautious in how and with whom you do business and one careless operator can undo it all

    :ranton:
     

    Thor

    Grandmaster
    Site Supporter
    Rating - 100%
    2   0   0
    Jan 18, 2014
    10,753
    113
    Could be anywhere
    I was a part of the OPM breach...they've probably got my DNA and retinal scans...

    They did also offer some of the free ID protection....all you have to do is log in with the same people who lost your information in the first place and give them everything else...:rolleyes:

    So, let met get this straight OPM, you lost all my personal information through incompetence and shoddy management and now you want me to give you all my banks account information too? No thanks.
     

    singlesix

    Grandmaster
    Industry Partner
    Rating - 100%
    1   0   0
    May 13, 2008
    7,340
    47
    Indianapolis, In
    Why do people refuse to send their drivers license copy or block out the number when sending them to an FFL? They need that info for their books.

    If if I get someone who refuses to give me that info with a gun guess what? Your **** is coming back cod.

    AIM Customer Service told me to do it this way when I called them about my concerns and questions about security. I only bought Ammo from them.
     

    halfmileharry

    Grandmaster
    Rating - 100%
    65   0   0
    Dec 2, 2010
    11,450
    99
    South of Indy
    It could be the Government is just using another means to track certain groups or people.
    Snowden just might have been on to something.
    Many motives for this type of thing.
    I use only pre paid plastic for any online purchases. Our info is accessible to people with the know how.
     

    SmileDocHill

    Grandmaster
    Rating - 100%
    61   0   0
    Mar 26, 2009
    6,237
    113
    Westfield
    wow, I've bought my share of ammo and "stuff" from them as recent as a year ago. I haven't gotten a letter though???? Was it a physical letter (like they used to do in the mail :) ) or an email? If it was a letter it likely got thrown away as junk mail.
     

    Expat

    Pdub
    Site Supporter
    Rating - 100%
    23   0   0
    Feb 27, 2010
    114,011
    113
    Michiana
    wow, I've bought my share of ammo and "stuff" from them as recent as a year ago. I haven't gotten a letter though???? Was it a physical letter (like they used to do in the mail :) ) or an email? If it was a letter it likely got thrown away as junk mail.
    Physical, paper, letter...
     

    scottka

    Master
    Rating - 100%
    6   0   0
    Jun 28, 2009
    2,111
    38
    SW IN
    Hmmm... Just made my first "ID required" purchase from AIM about a couple weeks ago. I bought an LE trade-in Glock 17 from them. From the letter, it looks like this occurred earlier in the month so maybe my info hasn't been compromised since it was after the system got hacked. I haven't been down to check the mail yet, but we'll see if I have a letter.
     

    Spear Dane

    Grandmaster
    Rating - 100%
    3   0   0
    Sep 4, 2015
    5,119
    113
    Kokomo area
    WTF are they doing keeping this much data.



    :ranton:

    Very easy to answer. Customer data is absolute GOLD to many businesses, especially retailers. There is an entire sub specialty of computer science called database mining. When Bernie grasps reality and gives up, his donor database will fetch BIG bucks as it is considered the most quality donor list out there this cycle. Last year when Radio Shack went belly up their customer database sold for $15 million IIRC.
     

    rhino

    Grandmaster
    Rating - 100%
    24   0   0
    Mar 18, 2008
    30,906
    113
    Indiana
    These places that require that much person info need to purge it immediately after it's no longer needed the specific purchase. I'd rather them do that and upload my info each time than have it sit like bait.
     

    JollyMon

    Shooter
    Rating - 100%
    2   0   0
    Sep 27, 2012
    3,547
    63
    Westfield, IN
    Got the letter. Never doing business with them again - nor anyone else that requires such information.

    Do you stop doing business with all companies that have data breaches? Guess you dont shop or use Home depot, JC pennys, Target, Sony, Anthem, ebay, JP Morgan Chase, Tricare, etc.
     

    ljk

    Master
    Rating - 100%
    30   0   0
    May 21, 2013
    2,771
    149
    Never bought ammo from them, probably never will.

    They told me I wasn't part of the data leak, looks like the perps went straight after the I.D. and C&R pictures.
     
    Top Bottom