As the title says, my card number was stolen after making a purchase from Wizard Labs. Last time this happened I had made the purchase on a card I use frequently, so I couldn't prove where it had been compromised. This time however the purchase was made with a card that I had not used in over a year. Sure enough a week later I get a fraudulent charge.
Anyone else have their card stolen when purchasing from Wizard Labs recently?
Adding a top level comment so it's easier to find in case this gets any bigger. This is the response I got from WL-
Hello,
Thank you for your recent order with Wizard Labs. We are sorry to hear about your experience with your credit card. However, we do not store credit card information on file. We have added a 3rd party firewall up to discover any malicious attack on our website. So far we have not found any breach of security but we are going to keep investigating. We will contact you to let you know what the investigation find. I hope this information is helpful and if you have further questions or concerns please e-mail and we will be happy to assist you.
Best Regards,
Maria
Wizard Labs
Beyond just a firewall, the JS should be inspected thoroughly. If I get some free time soon I'll test the checkout for XSS or lines that could have been added maliciously.
Update: To be honest, I'm a bit disappointed by their front-end code. It' not that it's terrible, it's just sloppy.
Onto the details.
They appear to be using Skrill to process the payments, but they used to use Authorize.net and left some of that legacy code in there. Hard to tell, but Skrill is being used currently.
Their e-commerce platform is obviously OpenCart and there is a Skrill payment extension that it comes with. They appear to be using it (code for Skrill extension can be viewed here), so the payment code probably wasn't development by WL or somebody they hired.
I submitted an order with an invalid card and there was only one network request directly to the OpenCart Skrill payment path. No funny business going on, and I can't spot anything strange in the JS offhand. It's possible that I'd need to submit a valid order for more to happen, so there's not much more I can say here and I've just ordered everything I need from another vendor.
More concerning than anything else is the total disregard for OpenCart's security by the authors. They consider CSRF vulnerabilities to be mathematical improbabilities.
One thing is for sure, OpenCart is completely blacklisted from my viable e-commerce solutions.
WizardLabs,
If you're reading this, I've ordered from you plenty of times and you're a great company. I hope you can figure out what's going on here and get this all sorted out.
Tell your web guys to do something about all the CSS/JS fragmentation. It's all over the place, optimized for sluggishness (first time I've used that term I think), and it's as if you're code-splitting without actually taking advantage of loading only what you need....? Real head scratcher. At the bare minimum, minify your files and maybe use a module loader instead of script tags in the 20's + inline JS.
This is the response I just got after emailing them and linking this post.
Wizard Labs takes the privacy of customer information very seriously; your confidence and trust are important to us. We have been notified by several of our customers that they have experienced fraudulent transactions on their payment card statements. We made it our top priority to examine our systems and began an investigation. Our third-party merchant services provider and server hosting provider conducted vulnerability scans of our system, both resulting in a clean bill of health. Further, our merchant stated that we are currently PCI compliant. Our server hosting provider performed a sweep and scan on our system and have no verified findings. They also confirmed that our SSL is up to date and functioning with AES encryption and SHA-2. As an extra security measure, we engaged a cyber security firm to perform a more in depth screening of our website. They will continue to monitor our website 24/7/365 for any malicious attacks or malware on our system. In addition, we have deployed a third-party firewall adding to Wizard Labs’ primary firewall to provide another level of protection.
It is recommended that you review your payment card account statements closely and report any unauthorized charges or suspicious activity to your card issuer immediately. Contact information is usually on the back of your payment card and included on the account statement. If you believe that your personal information has been compromised please provide any information that will help us further this investigation by contacting us at, admin@wizardlabs.us. Thank you for your letting us know of any issue you have experienced and for your patience as we continue our investigation. We will update this post as soon as we have additional information.
Sincerely, Wizard Labs Team
Yeah man... They responded with that exact same message in this thread.
Either way, it's clear it has something to do with WL. Hopefully they figure it out. I hate it because I really like WL and have spent quite a bit of money with them already. I guess extra precautions are needed going forward.
Sounds like their credit card processor has security issues. Your should email them and let them know ASAP because they may be unaware of the issue.
Highly unlikely. As somebody in this industry, they’re definitely storing cards and someone is taking them. If it was a processor it would have been known in several IT security circles I’m a part of. No credit card processor is currently hacked, I’m sure of it.
Just like a lot of online stores, WizardLabs doesn't store card numbers so that PCI compliance isn't an issue.
There are a lot of credit card processors and I would never make the statement you just made. As a person in the tech industry, especially security, you know that's one of the first rules.
I'm not saying WL isn't at fault. There very well could be some malicously injected lines of code somewhere.
And I'm saying if a credit card processor was hacked, it wouldn't just be Wizard Labs, it would be all that processor's clients.
Master Card, Visa, Discover and American Express would have already tracked down the offending processor and it would already be temporarily suspended from doing business.
More to the point though, Wizard Labs seems to be using OpenCart, as detected from here: https://builtwith.com/?https%3a%2f%2fwizardlabs.us
When we take a look here: https://www.opencart.com/index.php?route=cms/feature
I don't see too many tokenized payment gateways in that list. So it's most likely or the odds are in the favor of at least storing the credit cards on the server.
Frankly, Wizard has put no effort into procuring a proper storefront software. I'm not saying open source is bad, but having a solid performer standing behind your store is a good thing. There comes a time when customer security should be more important than convenience, tossing https://sucuri.net/ over top of your site isn't going to stop folks from stealing card data.
It's even likely that a Wizard employee is stealing the cards him/herself. Most shit like this happens from the inside, not the outside.
I did, it was literally the only online order I had done with that card, two or three days later bam, fraudulent charges from about 5 states away, contacted the merchant and they refunded me immediately, but still. Cancelled the card, got a replacement, and will be only using virtual cards from now on and deleting them after the order processes
Tell me more about these virtual cards...
You can make virtual cards with http://www.privacy.com also. Connects with your bank account then you can generate multiple regular or 1-time "burner" cards. Not all services accept the cards but 9/10 have no problem. Each card is locked to 1 merchant so even if the card number is stolen it can't be used anywhere else.
The card I use (PayPal prepaid mastercard) let's me generate a unique card number that I can then use for as long as I want and delete when I'm done with it. In this case it gives it its own expiration date and security code too. That way if the card number is compromised before I delete it it can be canceled instead of my main account card. Also if they get the number and try to use it it will decline if I've deleted it. Super handy I just didn't think about it from wizard labs, I've ordered from there before with no problems
Citi offers VANs, at least on their doublecash cards, I use them for all online purchases. Basically creates a new card number linked to your actual card. They come in two varieties, a single use number with $ limits or a number with $ limits and time limits. Either way that number can only be used at the vendor it was used at initially and only for online of phone transactions.
Wizard Labs takes the privacy of customer information very seriously; your confidence and trust are important to us.
We have been notified by several of our customers that they have experienced fraudulent transactions on their payment card statements. We made it our top priority to examine our systems and began an investigation. Our third-party merchant services provider and server hosting provider conducted vulnerability scans of our system, both resulting in a clean bill of health. Further, our merchant stated that we are currently PCI compliant. Our server hosting provider performed a sweep and scan on our system and have no verified findings. They also confirmed that our SSL is up to date and functioning with AES encryption and SHA-2. As an extra security measure, we engaged a cyber security firm to perform a more in depth screening of our website. They will continue to monitor our website 24/7/365 for any malicious attacks or malware on our system. In addition, we have deployed a third-party firewall adding to Wizard Labs’ primary firewall to provide another level of protection.
It is recommended that you review your payment card account statements closely and report any unauthorized charges or suspicious activity to your card issuer immediately. Contact information is usually on the back of your payment card and included on the account statement. If you believe that your personal information has been compromised please provide any information that will help us further this investigation by contacting us at, admin@wizardlabs.us. Thank you for your letting us know of any issue you have experienced and for your patience as we continue our investigation. We will update this post as soon as we have additional information.
This happened to me also! I was wondering if it might have been wizard labs. I've never purchased from them before until the other day then I noticed some odd charges on my card. Now I'm sure it was the wizard labs purchase! I'm sure it's just a lapse in their privacy/security and not that wizard labs themselves are out to get us.
I ordered from them on Saturday June 24th. They charged my card on Tuesday June 27th. The next day a $.01 charge was made against my card (I guess to see if the card still worked) and then several charges to Adidas and Forever 21 were made. Sadly my bank was slow to notify me until my account was wiped out. I called Wizard Labs after talking to my bank and they took my phone number and said they would call me in two to three days, when they find something out. I have not heard anything from them yet. I have no doubt that my card info was stolen after my Wizard Labs purchase.
I ordered from them 6/21, fraudulent adidas.com charges showed up 6/25. I've ordered from them a couple times before (been several months now, typically use ECX) and not had an issue. It's odd that someone else on this thread also had charges from adidas.com.
Hey so funny story... I had the same thing happen with Adidas and such. Today I had a Point of Sale return show up on my statement from Adidas in Portland. My thoughts are they ordered online and were trying to take either back for cash but they couldn't do that so they refunded my card. :) Might check your statement.
I've had my card number stolen four times in the past year. All of the purchases I'd made online with it during that time period were at Bull City, ECX, Nic River, Heartland, and CTX (no Wizard Labs) -- I wasn't able to pinpoint which one was to blame. I think a bunch of people had their stuff stolen due to a security breach when buying directly from FW recently. So WL isn't the only one who has had problems with their credit card processing. This probably won't be happening to me again, since I've learned that my bank offers an authentication service, but it would be nice to see these merchants better job for people who don't have that option.
I am definite that Wizard Labs had somehow something to do with getting my cc number stolen to, especially after reading all these posts. I placed an order in 6/23 and on 7/3 there was an unauthorized charge for $.01 from a FRIENDS PHOENIX PUBLIC in Phoenix AZ, just like what happened to some of the other posters on here. That's a real shame because I love their products and three day shipping. And I was just getting ready to place my second order with them. I absolutely will NOT be buying from them again. Sounds like their trying to dodge the problem too. I haven't called or contacted them, but sounds like other members here have and either got a canned response or nothing back from them at all. That's not good. I would expect them to be all over the problem. Because it sounds like maybe an internal issue.
I just checked and now there is an unauthorized purchase too a Forever21.com. Lucky I didn't have more than 5 bucks on the card. What a bummer and I'm kind of pissed. I've never had credit card number get stolen before.
Anyone who had their card stolen after shopping at Wizard Labs, what type of purchases were made and where? I had 2 different numbers stolen and another person on E-Liquid-recipes.com who had their number stolen, all had similar purchases to some mentioned here. All three card numbers that I know of the purchases made were used at Neiman Marcus (one purchase there was for Chanel perfume), both of mine were also used at stores such Sephora, Forever 21, Beauty box, H&M, and I am having trouble remembering the others. But there were all mostly female clothing, perfume, makeup. I also had ancestry.com as someone else mentioned.
Basically, all three cards and now 2 mentioned here were used for the same types of purchases. Female things (besides ancestry, but again, that is a developing trend on these stolen cards). Because it has happened to so many of us, maybe Wizard Labs or their credit processor can help catch who it can be based on the similarities in purchases. The more we can connect them, the better chance there is of catching this asshole! I am guessing it is a woman or transsexual MtF from the purchases made. It is possibly a former or current employee at Wizard Labs or their credit processor. There has still been more stolen card charges happening, so continue watching your cards!
IF YOUR CARD WAS STOLEN, PLEASE LET ME KNOW WHERE IT WAS USED. I am trying to keep a list of trends with the charges. I don't know if it will help, but, I just feel like trying anything to get the person responsible caught!
Wow man! The exact same thing happened to me exactly placed a wizard labs order on 6/30 and 2 days later got a call from my banks fraud department, card was only used on wizard labs. I love wizard labs and always have used them, but they definitely have an issue and need to stop with the copy pasted response.
Thank you for the heads up. Just got off the phone from cancelling my card since various gift card and online purchases I never made had begun to post to my account.
Anyone that's made a purchase over the last couple of months should check their statements sooner rather than later to make sure they're not compromised.
I was just about to place an order with Wizard today. Thinking twice now. I had this happen to me with myfreedomsmokes last month. Shucksters made off with $600 out of my account.
Ouch shit that's a lot of money. Might figure out how to do the one time charge like /u/D34THSPAWN is talking about. I just posted a discount offer in the holiday thread if you do decide to place one. I'm sure it's nothing malicious on WL's part. Just bad security. (Which is definitely still a problem and hopefully they'll handle it.)
But your bank took care of it right?
I have made several orders with WL lately during their 12 hr flash sales. I also placed orders in the previous months and my card was hit this weekend. My bank shut it down and a new one is on the way in 7-10 days. It usually takes awhile for charges to appear most people say. However in this case it looks like Wizard Labs may be the common denominator. Hard to say as I have used Element Vape, Ecig.com, Nic River etc. but this may be a breach at Wizard labs. I signed up for Privacy.com yesterday and plan to use it for all my online purchases from here on out.
Hey, the same thing happened to me a few days after I placed an order on Wizard Labs about 4 weeks back (the only other recent purchase I'd made with this particular card was with Nicotine River). Fraudulent purchase made was for a Roku subscription.
Handled through my CC company, I did not contact Wizard Labs.
I'm glad I found this thread. I couldn't figure out how my card number had gotten stolen. Not knowing how worried me more than it getting stolen.
The only online purchasing I've done outside PayPal are Amazon, WL, and Bull City. Since I didn't suspect any of them, I was at a loss to explain it.
I called wizard labs yesterday to ask what the status was because i emailed and called and was told i would get a call in 2-3 days. they told me that they had posted on Reddit that they were hacked, so that comment on this thread is how theyre stating theyre compliant. I filed a complaint with IC3.org because this is ridiculous, no transparency at all, i called over a week ago and wasn't allowed to talk to anyone other than the customer service associate who picked up because 'other people had already called and reported their cards being used for fraudulent purchases'. They switched to the third party(from the manager said yesterday) since the hack.
they should have took down their site the moment a hack was reported and sorted it out instead of allowing more people to order and get stung like this.
When was your card compromised? }
ive never had any problems and ordered from them 06/05/17 but that's anecdotal
For me, I ordered on 6/20 and the fraudulent charges happened on 6/26.
How did they show up on you statement? (for others)
I'm pretty vigilant of my accounts. I'll update if anything happens. Sorry to hear that.
>Anyone else have their card stolen when purchasing from Wizard Labs recently?
purchase made 4/19, one person drained my bank account 6/07 for some sims DLC on origin. it was only 12$ but it meant i rode a bike to work for that week. there's also been many attempts to log in to my various accounts since then. paypal, origin, steam, gmail, discord (but why though?). most have been outside of the US.
My card was compromised yesterday with a $.01 transaction to that same trophy shop and then 2 purchases to adidas online store, 1 for $130 and 1 for $170. $300.01 total out of my account. I contacted my card company and adidas online store as well as soon as i seen it before it cleared my account. Adidas online store said that they would be reporting it to the police. I order from WL a lot. I hope they can bounce back from this and keep their business as usual
Bringing back a old post but I just got this.
Please read this email in its entirety.
Wizard Labs is committed to maintaining our customers’ privacy and confidential information. We recently became concerned that an unauthorized person may have accessed our systems in an attempt to acquire confidential information. These systems process customer orders and include such information as names, addresses, payment account numbers, and/or email addresses.
While we have no evidence that any of your personal information was accessed or misused in any manner, we are taking appropriate precautionary measures to ensure your financial security and help alleviate concerns you may have.
What are we doing to address this situation?
We have long employed a wide range of security measures to ensure the confidentiality of everyone’s personal information. Since becoming aware of the attempt, on July 7, 2017, we retained the services of a computer forensics company to investigate potential unauthorized access and advise us on additional precautions we may implement. We believe if any information had been accessed, it would have been during the period of May 25, 2017, through June 26, 2017. Please rest assured that we are taking this matter very seriously and are continuing to actively investigate this incident. We have notified law enforcement and will continue taking steps to prevent such an incident from occurring in the future. We have already implemented new security measures to ensure the confidentiality of the personal information of those we serve and continue providing the level of service you expect from us.
In addition, Wizard Labs is providing you with access to Credit Monitoring* services at no charge. These services provide you with alerts for twelve months from the date of enrollment when changes occur to your credit files. This notification is sent to you the same day that the change or update takes place with the bureau. These services will be provided by CyberScout, a company that specializes in identity theft education and resolution.
It was followed with a link and a code to get the free monitoring.
Chances are it happened somewhere else. I know you said you haven't used it in over a year, but when cards get compromised, it initially happens a good while before they try to use it.