Woolies forced to shut online store

High street veteran Woolworths has been forced to temporarily close its online store after customer credit card and personal details were exposed on its website.

Written by Ian Lynch

High street veteran Woolworths has been forced to temporarily close its online store after customer credit card and personal details were exposed on its website.

Two Woolworths customers will receive cash compensation from the high street retailer after their names, addresses, and phone and credit card details were published on the www.woolies.co.uk website.

Woolworths says that an unidentified glitch in the website caused the customers' personal details, along with a description of the last product they had bought online, to be published on a web page within its site. A third customer then accessed this page and raised the alarm.

A Woolworths spokesman told vnunet.com that the company has apologised profusely to those involved and has agreed a one-off payment to the two customers for the inconvenience involved in cancelling their credit cards. He said one of the customers had asked for the compensation sum not to be revealed and thus he could not supply further details.

According to the spokesman, the website was closed down as soon as Woolworths became aware of the breach and the retailer is now conducting a thorough investigation into the reasons for the breach in customer confidentiality.

He added that he does not expect this to be completed until 18 August and the website would remain offline until then.

High street bank Barclays recently suffered a breach following a system upgrade that allowed customers to view each other's bank account details online.

Woolworths confirmed that it had also recently upgraded its system but denied that this was at fault, saying such upgrades were ongoing and the cause of the problem had not yet been identified.

Woolworths is the third case of a major UK company letting down its customers over the storing of confidential information on websites.

In July, thousands of PowerGen customers had their credit card details exposed on the utility's website. Security experts said at the time that companies often failed to secure customer data, because of a variety of mistakes. These included web connections being left open at a firewall, poorly designed web applications and web servers not being patched.

Consumer groups said these breaches were weakening public confidence in ecommerce. Earlier this month, a report from the National Consumer Council, Ecommerce and Consumer Protection, found that unless problems with online security are addressed, the fear of fraud would continue to be a deterrent to online retail.

Despite the UK's support for dotcom enterprises, and the government's insistence that the UK would become the central hub in Europe for ecommerce, purchasing is still one of the least popular online activities, according to the report.

Tags:

Further reading

Still losing against an unseen enemy

This year has seen a succession of high-profile security breaches, and even the best-protected networks remain curiously vulnerable.   More...

Woolworth's back online after scare

High street retail giant Woolworth's will finally relaunch its website this week, two months after it was closed down due to security problems. But uncertainty remains over whether the site will be able to deal with predicted volumes.   More...

Net fraud goes unpunished and unreported

Nine out of 10 internet frauds in the UK still go unpunished and usually unreported, despite the recent attempts by credit card companies to crack down on online fraud.   More...

Weak security found in many web servers

One in three supposedly secure ebusiness servers are using software with known security weaknesses, and European sites are the worst offenders, according to a survey.   More...

Related articles

Sainsbury's fixes online technical glitch

Every little helps, says rival   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement