{"id":3633,"date":"2012-01-17T09:49:24","date_gmt":"2012-01-17T08:49:24","guid":{"rendered":"http:\/\/blog.intego.com\/?p=3633"},"modified":"2012-12-12T13:55:40","modified_gmt":"2012-12-12T21:55:40","slug":"credentials-for-24-million-zappos-customers-hacked","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/","title":{"rendered":"Credentials for 24 Million Zappos Customers Hacked"},"content":{"rendered":"<p>The online shoe and apparel company Zappos, a subsidiary of Amazon.com, was recently hacked, and <a href=\"http:\/\/www.pcworld.com\/businesscenter\/article\/248244\/zappos_hacked_what_you_need_to_know.html\">credentials for 24 million users were stolen<\/a>. In an e-mail to the company&#8217;s employees, CEO Tony Hsieh said, &#8220;We were recently the victim of a cyber attack by a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky.&#8221; The company told customers:<\/p>\n<blockquote><p>\nWe are writing to let you know that there may have been illegal and unauthorized access to some of your customer account information on Zappos.com, including one or more of the following: your name, e-mail address, billing and shipping addresses, phone number, the last four digits of your credit card number (the standard information you find on receipts), and\/or your cryptographically scrambled password (but not your actual password).\n<\/p><\/blockquote>\n<p>What is important to understand here is that the actual password was not recovered, but rather a &#8220;hash,&#8221; or, as Zappos says, a &#8220;cryptographically scrambled password.&#8221; Nevertheless, Zappos has reset its passwords for all of its customers, and they will see a request to create a new password the next time they try to log into the Zappos website. Also, the hackers did not obtain full credit card numbers. Nevertheless, the hackers did obtain e-mail addresses, which could be used for spamming or phishing campaign. <\/p>\n<p>While passwords were not recovered in this hack (at least according to Zappos), they are sometimes obtained in this type of data breach. It&#8217;s worth pointing to <a href=\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/\">an older blog post about choosing secure passwords<\/a> to remind you not to use the same password on multiple sites, and how to come up with unbreakable passwords. Data breaches like this one are common; it&#8217;s a good idea to make sure your passwords are all secure, so if passwords are obtained in a data breach, hackers can&#8217;t use yours on other sites and see if it&#8217;s the same.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.<\/p>\n","protected":false},"author":3,"featured_media":3480,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13],"tags":[106],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Credentials for 24 Million Zappos Customers Hacked  - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2012-01-17T08:49:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2012-12-12T21:55:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png\" \/>\n\t<meta property=\"og:image:width\" content=\"128\" \/>\n\t<meta property=\"og:image:height\" content=\"128\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png\",\"width\":\"128\",\"height\":\"128\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/\",\"name\":\"Credentials for 24 Million Zappos Customers Hacked - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#primaryimage\"},\"datePublished\":\"2012-01-17T08:49:24+00:00\",\"dateModified\":\"2012-12-12T21:55:40+00:00\",\"description\":\"Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Credentials for 24 Million Zappos Customers Hacked\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Credentials for 24 Million Zappos Customers Hacked\",\"datePublished\":\"2012-01-17T08:49:24+00:00\",\"dateModified\":\"2012-12-12T21:55:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#webpage\"},\"wordCount\":324,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png\",\"keywords\":[\"Privacy\"],\"articleSection\":[\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/","og_locale":"en_US","og_type":"article","og_title":"Credentials for 24 Million Zappos Customers Hacked  - The Mac Security Blog","og_description":"Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/","og_site_name":"The Mac Security Blog","article_published_time":"2012-01-17T08:49:24+00:00","article_modified_time":"2012-12-12T21:55:40+00:00","og_image":[{"width":"128","height":"128","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png","width":"128","height":"128"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/","name":"Credentials for 24 Million Zappos Customers Hacked - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#primaryimage"},"datePublished":"2012-01-17T08:49:24+00:00","dateModified":"2012-12-12T21:55:40+00:00","description":"Credentials for 24 million customers of Zappos were stolen by hackers. No passwords or credit card numbers were obtained.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Credentials for 24 Million Zappos Customers Hacked"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Credentials for 24 Million Zappos Customers Hacked","datePublished":"2012-01-17T08:49:24+00:00","dateModified":"2012-12-12T21:55:40+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#webpage"},"wordCount":324,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png","keywords":["Privacy"],"articleSection":["Security &amp; Privacy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/credentials-for-24-million-zappos-customers-hacked\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2011\/11\/Alert.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-WB","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3633"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=3633"}],"version-history":[{"count":0,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/3633\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/3480"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=3633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=3633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=3633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}