Remember when Microsoft Store India was hacked, user data leaked, and passwords had been stored in plain text? Microsoft called the breach a "limited compromise" and assured customers that "databases storing credit card details and payment information were not affected." Try not to get whiplash as Microsoft now admits that financial data - credit card information - may have been compromised. Do you recall when the Microsoft Store in India was hacked by a group of Chinese hackers dubbed Evil Shadow? It was more embarrassing than a defacement since the hackers breached the database and then leaked usernames and passwords which had been stored in plain text.The website was taken down and replaced with a holding page that stated, “The Microsoft Store India is currently unavailable. Microsoft is working to restore access as quickly as possible.” The Microsoft Store India site is still down; it was managed by third-party service provider Quasar Media.In a statement, Microsoft called the breach a “limited compromise” of the company’s online store in India. “The store customers have already been sent guidance on the issue and suggested immediate actions.” Microsoft assured customers that “databases storing credit card details and payment information were not affected during this compromise.”Two weeks later . . . well apparently the big M fibbed. At the time of the hack, Evil Shadow claimed, “The data is very important. Any security enthusiasts are interested in the data.” The hacking group added, “Even Microsoft-owned stores will also use clear text passwords.”Now blogger and India Microsoft customer Amit Agarwal reported: If you ever used your credit card to shop at the Microsoft Online Store in India, it may be a good idea to stop everything you’re doing and call your bank to get your credit card blocked. That’s because your credit card number, your address and everything else that a fraud needs to use your credit card online, could later become available in the underground market.Agarwal further speculated that Quasar Media “was probably storing customers confidential data in plain text inside a Microsoft Access database that hackers got hold of.” He received a second email from Microsoft [PDF], but this one admits, “Further detailed investigation and review of data provided by the website operator revealed that financial information may have been exposed for some Microsoft Store India customers.” Furthermore, customers were advised to contact their credit card provider and closely monitor their credit card account.Microsoft has set up a helpline and a team of specialists for concerned customers because “Microsoft is committed to protecting customer privacy and takes this situation very seriously.”Like this? Here’s more posts:Smile for the drone: Coming to police stations near you soon25 More Ridiculous FBI Lists: You Might Be A Terrorist If . . .Firesheep moment for SCADA: Hacking critical infrastructure systems now as easy as pushing a button?Photo, fingerprints, eye color, height required: Your crime? Selling used video gamesPrivacy Advocates Sue DHS for Big Bro Fake ‘Friends’ Monitoring Social MediaMass Surveillance and No Privacy Bill is ‘For the Children’Gov’t: You have no right to anonymous speech on TwitterDARPA’s Spy Telescope Will Stream Real-Time Video from Any Spot on EarthBusted! DOJ says you might be a felon if you clicked a link or opened emailSecurity Researchers: ‘Did Google Pull a Fast One on Firefox and Safari Users?’Social Media Monitoring on Gov’t Steroids: Anything might come back to bite youWoz on smartphones: Wishes his iPhone could do all his Android canData Privacy Day: Social media ‘private’ data is fair game for e-discovery in courtDo you give up a reasonable expectation of privacy by carrying a cell phone? Follow me on Twitter @PrivacyFanatic Related content news Dow Jones watchlist of high-risk businesses, people found on unsecured database A Dow Jones watchlist of 2.4 million at-risk businesses, politicians, and individuals was left unprotected on public cloud server. By Ms. Smith Feb 28, 2019 4 mins Data Breach Hacking Security news Ransomware attacks hit Florida ISP, Australian cardiology group Ransomware attacks might be on the decline, but that doesn't mean we don't have new victims. A Florida ISP and an Australian cardiology group were hit recently. By Ms. Smith Feb 27, 2019 4 mins Ransomware Security news Bare-metal cloud servers vulnerable to Cloudborne flaw Researchers warn that firmware backdoors planted on bare-metal cloud servers could later be exploited to brick a different customer’s server, to steal their data, or for ransomware attacks. By Ms. Smith Feb 26, 2019 3 mins Cloud Computing Security news Meet the man-in-the-room attack: Hackers can invisibly eavesdrop on Bigscreen VR users Flaws in Bigscreen could allow 'invisible Peeping Tom' hackers to eavesdrop on Bigscreen VR users, to discreetly deliver malware payloads, to completely control victims' computers and even to start a worm infection spreading through VR By Ms. Smith Feb 21, 2019 4 mins Hacking Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe