Every day a new attack comes to light . This time, the victim is the popular site Bodybuilding.com.
The site itself announced last week that a group of hackers managed to gain access to system .
The site is used by many people, fitness and bodybuilding enthusiasts, as it contains articles about fitness, gives advice on exercises and training, and other related topics.
The company said there is currently no evidence that hackers gained access to any personal customer information. However, it is notifying all customers about the incident.
In a statement , it says that Bodybuilding.com experienced a data security issue and that some customer information may have been affected
The statement also said: “A data security incident was identified in February 2019, involving unauthorized access to our systems. We engaged a leading data security firm to conduct a thorough investigation.” The investigators discovered that it all started with a phishing email the company received in July 2018. The investigation was completed on April 12, 2019. It is not certain whether customer information was accessed.
Bodybuilding.com reported the incident to the appropriate authorities and is working with the security firm to address the vulnerabilities that the hackers used to breach its systems. The company's IT staff has already implemented additional security measures. It has even proceeded with the process of resetting customers' passwords.
The data that was possibly leaked is data that the company keeps on file, such as customer names, username and password on Bodybuilding.com, email address, addresses that customers had provided for shipping products, phone number, order history, communications with Bodybuilding.com, date of birth.
The good news is that the company does not store bank or credit card numbers, so such information was not at risk. Usually only the last four digits of the card are stored, but never the full number.
Of course, Bodybuilding.com customers will be forced to change their password for any other accounts where they use the same credentials.
The company, following the incident, suggests customers do the following:
- Change passwords on accounts that use the same credentials as the Bodybuilding.com account.
- Do not give out personal information over the phone or on websites they are not familiar with.
- Check their accounts for suspicious activity.
- Do not open links or download attachments if they do not know the sender of the email or if they see something strange.
