Announcement

Collapse
No announcement yet.

Security Breach

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Security Breach

    November 22, 2000 Olympic Sports Security Alert - For Immediate Release -
    16:20 EST

    We at Olympic Sports regret to say that we have experienced a security breach
    on our systems. The attack occurred between the days of November 10, 2000 and
    November 13, 2000 . Using a combination of a Microsoft IIS 4.0 security flaw
    and inside password information, the hacker was able to access our server and
    retrieve personal information such as credit card numbers and customer
    information.

    Olympic Sports has taken immediate proactive action from the moment of
    detection. We immediately gathered the necessary information to identify the
    hacker, as well as copies of all logged activity performed against our
    servers. This information was used to determine exactly HOW the hacker
    compromised our web servers as well what insider information he had used to
    access our database servers. A recent security bulletin posted by Microsoft
    announced the security vulnerability used on IIS 4.0 servers and the patch
    was applied to our servers to prevent any further violation.

    Using our logged information, our software provider has determined the
    identify of the hacker to be located at servers owned by Crown Internet; a
    Sportsbook operating in the Dominican Republic (recently moved from Costa
    Rica, who just happens to use the same software). Employees of this book set
    up a website at http://www.winnersbook.com and used this server to launch
    their attacks against our system. The software provider is completing a patch
    to prevent insider password information from ever being used again by another
    book operating the same software.

    A few of our customers have reported that their credit cards have been
    charged without authorization from a processing company called "NetPro". We
    have worked with these customers to find out what merchant is charging these
    transactions, and have found that they are coming from winnersbook.com
    Therefore, our recommendation for our customers who have processed credit
    cards with us in the past six months is this:

    · Call the company that issued your credit card on file with us immediately
    and see if you have any unauthorized charges from NETPRO.

    · If you DO have charges from NETPRO, we advise canceling the card
    immediately.

    · NETPRO has ALREADY been made aware of the situation and has issued CREDITS
    against ALL accounts that were charged from winnersbook.com


    It is important to note that the Microsoft bug allowed access to our server,
    however it was INSIDE password information that allowed access to our
    customer database. Therefore, this hacking job was premeditated and executed
    by someone using inside information only known to approximately a dozen
    people that use the same software. It was this hackers intent to defraud our
    customers as well as our reputation. We are fully committed to working with
    the credit card authorities to take action against the hacker(s) and bring
    justice about quickly. Olympic Sports appreciates your business and it
    saddens us that we have been a victim of malicious intent. We apologize for
    the inconvenience some of you may face and want to wholeheartedly work with
    you to remedy this situation as soon as possible. A special email has been
    set up to field questions or concerns about the security breach.
    Email [email protected]


    Please do not hesitate to contact us. Phone:1-800-274-7384 Ask for Spiro

    Sincerely,
    Olympic Sports www.thegreek.com


  • #2
    Olympic is a class act as always for informing everyone, instead of trying to keep it quiet.

    Comment


    • #3
      People have trusted me with their money nad their info. And even though this was something I had no control over, I feel like I've let them down.

      I'm sorry.

      Spiro

      Comment


      • #4
        i spoke to spiros yesterday about this terrible breach of security. his sincerity in this matter was very evident. he/olympic will continue to stay at the forefront of this industry despite this setback. this will be a transparent event.

        brian

        Comment


        • #5
          ONE OF THE REASONS OLYMPIC SPORTS IS THE #1 OFF-SHORE BOOK.

          SPIRO,YOU TRULY ARE ONE OF A KIND.

          NOW I KNOW WHAT YOU WERE TALKING ABOUT THE OTHER NIGHT.

          ANYTHING I CAN FOR YOU JUST GIVE ME A CALL.

          SU AMIGO,

          REALITY

          Comment


          • #6
            I feel I should keep this topic alive. There are still people that have fallen victim to these crooks and are not aware of what has happened.

            Spiro

            Comment


            • #7



              [This message has been edited by natty (edited 12-01-2000).]

              Comment


              • #8
                My card got hit and yes, NETPRO did credit my card back before I could even call them. I hope we can nail these a**holes.

                natty
                PS. Thanks Spiro for letting us know.


                [This message has been edited by natty (edited 12-01-2000).]

                [This message has been edited by natty (edited 12-01-2000).]

                Comment


                • #9
                  I would suggest that it is advisable for everyone who has an active account with Olympic to at least change their passwords.

                  Comment


                  • #10
                    I signed up with Olympic in September using a credit card. Now I want a payout for my original stake to my credit card for no cost as their site says but Olympic tells me since the security breach they have no record of my card and I must pay for a western union or Fed Ex. Is this fair? In my opnion it is not.

                    Comment


                    • #11
                      jayhawk - Your situation has nothing to do with the security breach. There was a problem with one of the credit card processors and Olympic has switched processors. Thus there is no way for them to credit your card back since they are no longer using that company. I'm sure if you call, you'll probably come to an agreement where you pay half the charges and they cover the other half and everybody's happy...

                      May all your bets be winners
                      May all your bets be winners
                      www.footballstart.com

                      Comment


                      • #12
                        I spoke with Spiro and he mentioned that these A**holes didn't get anyone's password.
                        I would suggest to anyone who used a CreditCard with Olympic to just call your bank and cancel your card(I think they just block it) and have your bank issue you a new # just to be safe. It cant hurt at all.- The jerks got name,address and probally phone #.
                        To all of the new people out there looking for a book. Let me say after being a member with Olympic for 2 years, they are top notch!
                        This situation had nothing to do with Olympic.Spiro assured me they took every measure to prevent this from happening again.
                        I have never had a problem with Olympic as they are still top notch in my book.
                        Nuff Said,

                        Natty

                        Comment


                        • #13
                          Jayhawk,

                          You should not have to pay for the unfortunate problem I had with my Credit Card processor a couple of months back. Email me ([email protected]) with your info and I will make sure you get that money back.

                          Spiro

                          Comment


                          • #14
                            Come to think of it I got a cold call from some tout service just a couple of weeks ago. Maybe it's totally unrelated, but maybe not. It's pretty unusual, since my phone number is unlisted. Did anyone else get a call from "New World Sports" or something like that?

                            Maybe it's a long shot, but I couldn't help but wonder if it had anything to do with the list.

                            Comment


                            • #15
                              Top

                              ( I noticed some people just finding out about it now so I wanted to bring it back up to the top.)



                              [This message has been edited by natty (edited 12-17-2000).]

                              Comment

                              Working...
                              X