Security Incident Notice
On September 21, Coincards identified unauthorized access to our frontend web server through a WordPress-specific vulnerability.
The attacker was able to gain access to the web server and take a copy of the frontend website files.
*These files do not contain user or order information.*
Our production database is hosted separately behind private networking, and we have found no evidence that the attacker directly accessed or downloaded our production database containing user information.
During our investigation, we did confirm that a small number of customers had their data downloaded through an export tool we use. The export contained a handful of customer account records, including email addresses, account usernames/IDs, and password hashes.
Passwords are not stored or exposed in plaintext. The file contained one-way cryptographic password hashes, which cannot be used directly to log into an account. As a precaution, the affected customers will be contacted directly today with additional information and recommended steps.
We have contained the incident and completed several security measures, including removing the vulnerable software and malicious files, invalidating all existing WordPress login sessions, changing administrator passwords, rotating database and application/API credentials, and adding additional server-level protections to prevent the exploit from being run again.
We also conducted an extensive review for signs of continued access or persistence.
At this time, we have found no evidence of unauthorized administrator accounts, new SSH keys, new system users, persistent malicious processes, keyloggers, or other ongoing access to the server.
The handful of affected customers will be contacted directly today.
We will continue monitoring the environment and reviewing the incident, and we will provide additional information if anything materially changes what we currently know.
We believe transparency is important when a security incident occurs, and we wanted to communicate what happened, what information was affected, and the steps we have taken in response.