Wiggle hacked

in Road general
Just spotted on another forum and cyber security site that wiggle are investigating a cyber attack. It's reported people have lost money for goods supposedly ordered by them and delivered elsewhere. Currently being investigated.
Too many bikes according to Mrs O.
0
Posts
the thieves use automated tools to try lists of stolen credentials against other sites, in bulk, enough people re-use passwords to make it viable
wiggle's not to blame for illicit access where a customer has re-used the same login details that they used on oops.com
but if it's allowing stored payment details to be used for delivery to a new address without re-verification, that's really unacceptable
just speculation, we'll have to wait and see
btw always a good idea to check email addresses you use...
https://haveibeenpwned.com/
...and of course, avoid re-using passwords, and use two-factor whenever available
I got an email from Wiggle the other day to 'complete my order' which is a standard email you get after you add something to your basket but don't end up buying it. This raised alarm bells as I hadn't been on the site but I didn't follow it through.
After reading this I've just logged into my Wiggle account to see that my address has changed to this.
Nikita Yakymenko
Ukraine, Shostka, 41100
Shostka
Sumy oblast
41000
Ukraine
+380686565203
I don't store payment details on sites to prevent issues like this so luckily nothing could be purchased. Sungod mentioned https://haveibeenpwned.com/ - it's a great site to let you know if your email has been part of any breached data. My email has been part of several data breaches.
All of these email addresses will resolve to the same inbox (note, this is a new address I set up purely for this example):
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
Other services may be able to do similar things, but I'm only really familiar with Gmail's options.
Edit: If you have a decent password manager (I use Dashlane), you can store which of your infinite email addresses you've used for each site.
Specialising in Git Daaahns and Cafs. Norvern Munkey/Transplanted Laaandoner.
Chrome also alerts you if you've entered a username/password combo that's on a list of stolen details which is handy.
The other advice I have taken on board for important passwords which you need to remember is to use a (long) phrase from a book you know well. One guy I know uses an entire sentence.