CRC - Is it safe to...
 

[Closed] CRC - Is it safe to start ordering again yet?

Posts: 50
Full Member
Topic starter
 

As title, really.


 
Posted : 13/04/2011 7:39 pm
Posts: 0
Full Member
 

my mate got done last week,so no unless it's paypal mefinx.


 
Posted : 13/04/2011 7:40 pm
 Tim
Posts: 1092
Free Member
 

Ordered last week and seems fine so far...


 
Posted : 14/04/2011 10:05 pm
Posts: 0
Free Member
 

Why?


 
Posted : 14/04/2011 10:14 pm
 7hz
Posts: 0
Free Member
 

[img] [/img]


 
Posted : 14/04/2011 10:14 pm
Posts: 0
Free Member
 

Been using paypal with them of late as dont want to risk it but everything I've ordered has taken a week to arrive, which is pretty crap compared to what they used to be like. May have in part blamed royal mail but after ordering items elsewhere and still receiving them before the items I ordered from CRC I dont think thats fair.


 
Posted : 14/04/2011 10:24 pm
Posts: 41395
Free Member
 

paypal here.

ordered yesterday and today. both despatched today.


 
Posted : 14/04/2011 10:55 pm
Posts: 11606
Free Member
 

Paypal on Tuesday at midday, paid Special Delivery and although they said it was despatched that afternoon, it didn't reach the mail centre until Wednesday evening. I politely complained, got no apology just a brief explanation, and they didn't offer to refund the postage as per the website, I had to send another email to ask. Not long ago it would have been with me the following day with the free postage.

And the item is faulty anyway, not their fault but reckon they should pay special delivery both ways to replace it personally, especially if standard post is taking up to a week.


 
Posted : 14/04/2011 11:03 pm
Posts: 0
Free Member
 

No way!


 
Posted : 14/04/2011 11:09 pm
Posts: 0
Free Member
 

I ordered a funn fatboy bar last week from crc and recieved the next day. Thought or probably assumed the hack issue had been sorted... er, I'll just log onto my bank account...


 
Posted : 14/04/2011 11:19 pm
Posts: 0
Free Member
 

yep, fine so far.


 
Posted : 14/04/2011 11:23 pm
 spw3
Posts: 0
Free Member
 

I was done 12th March. Got an email from CRC saying they had found and fixed the vulnerability.

Wouldn't try CRC without PayPal though.


 
Posted : 14/04/2011 11:32 pm
 jedi
Posts: 10247
Full Member
 

lbs for the win for me.


 
Posted : 14/04/2011 11:34 pm
Posts: 0
Free Member
 

As the holder of a foreign credit card I thought (hoped) I might be resistant to the CRC fraud but I've been caught too now.
I've been away on business trip but just come back to a letter from my credit card provider telling me someone tried to make some purchases on the 6th April...

Looks like I'll be a paypal user in the future or shop elsewhere.


 
Posted : 16/04/2011 5:46 pm
Posts: 0
Free Member
 

Always used paypal and never had any problems.
Ordered some stuff from both CRC and Wiggle on Thursday of last week, standard delivery, and both parcels turned up on Saturday.


 
Posted : 16/04/2011 6:15 pm
Posts: 34452
Full Member
 

spw3 - Member

I was done 12th March. Got an email from CRC saying they had found and fixed the vulnerability

thats interesting so what was the vulnerability, poor website security or dodgy employee??


 
Posted : 16/04/2011 6:17 pm
Posts: 0
Free Member
 

Bought stuff on line on 24th March. Got a hefty clobbering of fraud that started with the 02 test around 16th April.

They have no class. Pizzahut, yuk. They've actually tried to get £1000+, successfully got about £300...


 
Posted : 22/04/2011 1:32 pm
Posts: 34452
Full Member
 

I'm really confused why anyone uses a credit card rather than paypal


 
Posted : 22/04/2011 1:54 pm
Posts: 0
Free Member
 

i am still waiting for the CRC IT bod who slagged everyone off for downloading p0rn to apologise.

I havent used CRC since being done in March. And to be honest my business has gone elsewhere now and is unlikely to go back to them.

their customer service is total shite and there are many other options out there


 
Posted : 22/04/2011 3:50 pm
Posts: 0
Free Member
 

kimbers have you ever been on the wrong side of paypal, i have and they are worse than a pitbull on heat then they try to take you to court in luxemburg?? for a £6 mess up which was their fault sorted its self out in the end but i had to do all the leg work, so happy to use the credit card my bank are far more helpful..


 
Posted : 22/04/2011 6:47 pm
Posts: 0
Free Member
 

Yes - but only with paypal - which I have done.

Their public response to the whole issue was sluggish and pathetic. They never mentioned the issue on their website. They did not e mail all their recent customers. Someone who might be from their commerce solution supplier was stupidly offensive here. And Singletrack did not seem that concerned about the whole thing, which disappointed me. Even now, 2 days ago when my wife topped her phone up with O2, we got a security call from our CC.. again... They know how compromised we could be because of previous CRC purchases.

Merlin FTW, CRC only if no one else has it.

And as for their "private sale" 🙄


 
Posted : 22/04/2011 7:34 pm
 accu
Posts: 0
Full Member
 

ordered two weeks ago..using my "fraud" voucher and paypal...
everything fine..
but delivery with royal mail took too long....used to be better...


 
Posted : 23/04/2011 8:56 pm
Posts: 6252
Full Member
 

just trying to decide what to get with my voucher, now that I have 2 new CC's.
50% chance that one of them was due to paypal, 100% chance that the other was CRC.
as for royal mail... well my last order took *weeks* to arrive. that eats right into Paypal 45day dispute window. Give me a CC and consumer credit act protection any day.


 
Posted : 23/04/2011 9:18 pm
Posts: 0
Free Member
 

So has anyone used their cc for a crc purchase in the last few weeks? I don't Paypal, and crc have some wheels that would do me nicely! I did consider paying the extra hundred quid my lbs will charge me, but the usual totally disinterested manner just ment I couldn't bring myself to do it.


 
Posted : 23/04/2011 9:51 pm
Posts: 0
Free Member
 

I used my cc the other day and no probs yet.


 
Posted : 23/04/2011 10:00 pm
Posts: 0
Free Member
 

I'd say no. i had my card stopped as a precaution by HSBC last week. this is the third time on two different cards since christmas,coincidence?

wont use CRC now unless it would be really cutting my nose off to spite my face. they are shite.


 
Posted : 23/04/2011 10:43 pm
Posts: 0
Free Member
 

Made 3 prchases with CC (From here in Egypt) in the last 2 weeks. I didn't know that there was a problem until reading this.

All orders arived within 2 days and no problems.

Should I be concerned? What is the best thing to do to prevent any issues?


 
Posted : 24/04/2011 6:56 am
Posts: 1
Free Member
 

CRC clearly know they have a problem so you'd think they'd shut the credit card payment section down and only accept Paypal until they resolve it all.

I think its pretty crap of them to keep accepting credit card numbers knowing that they may be nicked by the thieves who seem to have attacked their web site / credit card payment provider.


 
Posted : 24/04/2011 7:43 am
Posts: 0
Free Member
 

I won't be using my card with them until there is a statement from CRC that something has been fixed.

Used my card on 12th March with CRC and it was stopped last week after over £3k of suspicious activity was declined. The bank hinted the CRC transaction could be to blame so there's a decent time lag from details getting compromised until fraud attempts.

Very inconvenient. I've seen a few mentions of fraud vouchers - how were these issued? Did you have to alert CRC that you were a victim of card fraud, possibly through their siteq?


 
Posted : 24/04/2011 9:14 am
Posts: 0
Free Member
 

Received an update from CRC the other day:

"The independent forensic investigation has shown that our infrastructure was the target of a sophisticated attack which resulted in the theft of card details relating to a number of our customers. Details were being stolen 'real time' and only a small proportion of recent CRC customers were affected.

The access point of the theft has been identified and permanently closed off so we are confident that we have fully addressed any weakness in our infrastructure."


 
Posted : 24/04/2011 9:50 am
 jonb
Posts: 0
Free Member
 

Just been onto the credit card company after they stopped my card. I use it a bit online but when I mentioned CRC they were aware of the problem.

Could have had my details for a while. Made a few orders since the start of March.

I'd still go down the paypal route and keep an eye on statements.


 
Posted : 29/04/2011 1:12 pm
Posts: 74
Free Member
 

Phone call to day from the bank fraud office 🙁
attempts to purchase £15 of O2 vouchers and then £112 else where..
I last used chain reactions in December, looks like the theives are
still working their way thought the list they obtained.


 
Posted : 06/05/2011 6:20 pm
Posts: 0
Free Member
 

Like others I used paypal last time. Next day delivery (which they still claimed when I ordered) seems to be a thing of the past - they actually managed to dispatch same day, but sent PF48, so not really much hope of next day delivery!


 
Posted : 06/05/2011 6:25 pm
Posts: 0
Free Member
 

Had over £130 debited from my account and 36 attempts by someone to send faxes by MyFax.com.

Lloyds TSB have now said that all CRC payments are being treated as high risk.

Think this may be a big blow to the future of CRC....appreciate their staff maybe getting frustrated with all the calls from us complaining but they are the cause of the problem due to their lax security.

I certainly will not be using Chain Reaction Cycles again....especially after the poor quality of service and replies from the staff.

Lets hope that Wiggle, Merlin etc take note beef up their security and enjoy all the new customers at CRC expense.


 
Posted : 06/05/2011 6:36 pm
Posts: 0
Free Member
 

I had £1400 ish taken over easter bank holiday, i told them i had used crc and they seemed aware of them. They are still investigating, me i expect!


 
Posted : 06/05/2011 6:44 pm
Posts: 0
Free Member
 

Oh god, I just ordered some parts from them!


 
Posted : 06/05/2011 7:18 pm
Posts: 0
Free Member
 

Just had a call from my CC provider as it may have been compromised. Card stopped, new one issued. Haven't used CRC since November last year.
It might not be CRC that is the problem - could be any manner of other transactions, but interesting nevertheless having missed the previous thread about it.


 
Posted : 06/05/2011 7:19 pm
Posts: 17
Free Member
 

Called them this morning as I got done as well. Was told it's safe now, but will be using paypal from now on.


 
Posted : 06/05/2011 7:24 pm
 Taff
Posts: 4
Free Member
 

Been using them quite a bit but been using paypal to pay for things. Add and extra day or two on to usual arrival times etc but it's safer.


 
Posted : 06/05/2011 7:43 pm
Posts: 0
Free Member
 

Add and extra day or two on to usual arrival times etc but it's safer

Because of using paypal? It shouldn't, as it's just as instant a form of payment as CC - people on ebay seem capable of getting stuff to me next day when I pay that way. What you're actually seeing is that CRC don't normally do next day delivery any more.


 
Posted : 06/05/2011 9:09 pm
Posts: 682
Full Member
 

LBS for me too! Cheaper than CRC a lot of the time too... i buy all my stuff there so they value my biz. They also build great wheels too and are always happy to help if they ever need a quick "tweek"...A big up for good old Marshalls Cycles in Herts. I first went there cos of all the support they had given local racing. On line stuff might be easier in terms of delivery etc but if it goes wrong like some of those guys have, its a nightmare!!


 
Posted : 06/05/2011 9:37 pm
 empy
Posts: 0
Free Member
 

CRC - Is it safe to start ordering again yet?

That's what I asked CRC after >£1000 attempted fraud on my card over easter. They haven't responded yet so I haven't used them again yet.


 
Posted : 06/05/2011 9:50 pm
Posts: 0
Free Member
 

Ah - that explains why my bank cancelled my credit card a couple of weeks ago! No amount of pushing would get them to reveal the reason - but now I'm confident it was CRC that was the leak! Lucky my most recent order went to Wiggle instead...


 
Posted : 07/05/2011 10:55 am
Posts: 173
Full Member
 

what I can't figure out is that if the extent of the fraud is really this bad (which it appears to be) then CRC's merchant acquirers will be looking to CRC to refund the fraud loss. It usually works that way - the banks always look back to the merchant - especially in this case where CRC's total lack of control and non-compliance with PCI-DSS has been admitted.

I reckon:
1. prices will go up at CRC to cover a few extra %age points on txn fees
2, or CRC's insurers will be hit hard for the fraud loss - resulting in higher charges
3, or CRC will go bust when the banks try to recover the fraud loss amount.


 
Posted : 07/05/2011 11:01 pm
Posts: 0
Free Member
 

Paypal here
had a load of hassle with debit card
never again 🙁


 
Posted : 08/05/2011 11:59 am
Posts: 0
Free Member
 

DO NOT USE CRC!!!

I just used them on Saturday last week. It was a debit card i had never used before and the next day £400 was taken and then £250 on the monday. Cleaned out my current account.

It had to have been CRC because the fraud was in sterling and I havent purchased anything else that would have been in sterling. All my other transactions are in Euro.

Be careful. Paypal only in future.


 
Posted : 13/05/2011 10:24 pm
 rs
Posts: 28
Free Member
 

Arrrrggghhh, I figured it must be fine now, I just placed an order earlier with my CC, I will keep an eye on my statement and will see what happens!


 
Posted : 13/05/2011 10:37 pm
Posts: 0
Free Member
 

ohhhhhhhhhhhhhh. that explains it. not been on here for ages so not seen anything about crc probs. It would explain the attempted £3k on my card just after I bought some stuff a few weeks ago. Thank you for the unintentional help!


 
Posted : 13/05/2011 11:29 pm
Posts: 0
Free Member
 

what are you finding bez? and how did you find someones password? thats scary.


 
Posted : 14/05/2011 1:22 am
 Taff
Posts: 4
Free Member
 

Had my card done again but this tome it wasn't CRC as been using paypal.


 
Posted : 14/05/2011 7:41 am
 PJay
Posts: 4955
Free Member
 

Have you let them know what you've found? Personally I think that trading whilst knowingly putting your customers at risk is a kind of fraud in itself.


 
Posted : 14/05/2011 8:55 am
Posts: 0
Free Member
 

Hi bez

Can you drop me an email to Michael@chainreactioncycles.com

With the regards to forgotten password feature, regardless of any on screen messge, the website will only email the password to the email address associated to that password. Therefore you can only use this feature to retrieve a password if you also have access to the email

Drop me a mail anyway and we can discuss further.

Thanks

Michael


 
Posted : 14/05/2011 9:49 am
 DT78
Posts: 10066
Free Member
 

Sounds worrying if Bez is right....

I hoped it was ok by now so used my card with them last week, will be keeping an eye out.... I had the 2x£15 O2 voucher fraud on my debit card a few months ago, can't be sure it was CRC. Real pita but bank sorted it with minimal fuss.


 
Posted : 14/05/2011 10:30 am
Posts: 2277
Free Member
 

Bez, it can only be foolish posting such stuff on an open forum.

First, you may be wrong.

Second, you should be contacting CRC first instead of publicizing an exploitable weakness to everyone (if you are right, and I have my doubts).

I'd suggest the mods should take this thread down in case Bez is right and is publicizing an exploit.


 
Posted : 14/05/2011 10:37 am
 Bez
Posts: 7439
Full Member
 

As I said, the instructions are on CRC's own site. I've said nothing that fills in any blanks.


 
Posted : 14/05/2011 10:46 am
Posts: 0
Free Member
 

I would add my concern to CRC. Great company, great price, GREAT GAFF ! I got contacted by my bank about unusual activity. My money was save by the bank (god knows why I should praise those crooks !) and the fact that the card details taken did not get by the sounds of it the last 3 digits on the back. Again these details are store with CRC and recent purchases point to CRC. The bank stop the card. But I must admit I need to check now what other details CRC have !


 
Posted : 14/05/2011 10:47 am
 Taff
Posts: 4
Free Member
 

DO NOT USE CRC!!!

Be careful. Paypal only in future.

Bit contradictory there?

I've used CRC for years with only this little hicup - with the exception of the hacking their shop and staff have always been good and much better than most LBS' in my area. Granted I've not been scammed for large quantities yet but I've now changed the way I online shop


 
Posted : 14/05/2011 10:56 am
Posts: 0
Free Member
 

I used paypal fortunately, since they haven't yet dispatched my order of 31 March and then tried to ask for more money to do so. My suggestions that they were in breach of distance selling regulations by hanging onto my cash and my goods were just ignored, they gave me a revised date that has come and gone and they didn't bother replying to my last posting on the paypal dispute.

So we've moved to a claim....


 
Posted : 14/05/2011 12:05 pm
 Bez
Posts: 7439
Full Member
 

I've received a reply from Michael at CRC and they are on the case. Indeed I've checked back on the website and the specific vulnerability I tested has now been removed.

I'll remind everyone else of one important thing in Internet security. [b]Do not reuse login pairs of username/password or email address/password.[/b] Ideally do not reuse passwords at all, especially for important logins such as your email accounts or anything financial.

I should perhaps add that I have been a regular customer with CRC for a number of years and have had no significant issues with their service in that time, in fact on occasions it has been excellent.


 
Posted : 14/05/2011 12:22 pm
Posts: 0
Free Member
 

I had the 2x£15 O2 voucher fraud on my debit card a few months ago

It may be a coincidence but my bank highlighted O2 top ups as one of the declined items as well.


 
Posted : 14/05/2011 12:25 pm
 DT78
Posts: 10066
Free Member
 

Sounds like some free consultancy there Bez, surely worth some CRC vouchers 🙂

The O2 thing is very common, loads of threads on it. I believe it is how they test they have a valid card number, before they try a major fraud


 
Posted : 14/05/2011 12:26 pm
Posts: 1
Free Member
 

So is it now safe to use CRC? I've been avoiding them for a while, but need to get some tyres.


 
Posted : 17/05/2011 8:31 am
Posts: 0
Free Member
 

Wish i looked on STW before i ordered from crc last night- bank just called to say that someone has cloned my card and now the account is frozen.
So no- its not safe....


 
Posted : 29/05/2011 10:57 am
 7hz
Posts: 0
Free Member
 

Wow that is a nightmare.

This has been going on for what, 3 months now?

I haven't bought anything else from Chain Reaction since this incident (took me three changes of credit card!)


 
Posted : 29/05/2011 11:04 am
Posts: 0
Free Member
 

on the contrary, i ordered on monday [b]via paypal[/b] and my account hasnt been drained. item hasnt turned up yet either, but thats another matter 🙂


 
Posted : 29/05/2011 11:05 am
Posts: 0
Full Member
 

Ordered from Chain Reaction 23/5, unusual card activity started 3/6. Bother.


 
Posted : 14/06/2011 11:17 am