pull down to refresh

A vulnerability in one of our systems was exploited, affecting exactly 6 user accounts — no more. Using this opening, they were able to compromise a small number of user accounts and place fraudulent gift card orders that cost them virtually nothing but resulted in real financial loss on our end. Because digital gift cards are fulfilled instantly and cannot be revoked, the attacker was able to extract value before we could detect and stop the abuse. The total financial impact was in the tens of thousands of dollars. We’ve been able to recover a small portion of this only, so the real-world loss hurts.