Forum: MarketPlace Customers


Subject: Low security at Renderosity?

l.croft opened this issue on Apr 11, 2017 ยท 83 posts


nujazz posted Wed, 26 April 2017 at 6:36 PM

henrikmk posted at 6:11PM Wed, 26 April 2017 - #4303113

I'll just chime in that my card has been hacked 4 months ago with no email warnings received from Renderosity, even after checking the spam folder. Then again just two weeks ago, the new card was blocked by the bank for no apparent reason, but I have been shopping here a few times with that card in 2017, before it was blocked. Still heard nothing from Renderosity. Then I actively search and find this thread.

I'm not sure what else to say, other than if you think there are problems, it's best to send out emails unconditionally to all users as a safety measure along with changing all passwords.

Hello henrikmk,

A few other users reported compromised cards around 4 months ago. That incident doesn't appear to have originated at Renderosity.

As for two weeks ago...
Your bank can block your card for any number of reasons. Have you contacted your bank to find out why they blocked your card?
If your bank says they detected fraudulent purchases then I can investigate your account. If your card was blocked for something other than fraud, I wish you the best of luck in resolving the issue.

We sent emails to all users who may have been at risk, but our emails often have trouble getting to everyone's inboxes. (Sneak peek: We're planning some big changes to our email system to address this.) We only sent the messages to at risk users to avoid causing unnecessary concern among users who definitely were not affected. There was a specific window of time when purchases were at risk. That's how we know who was at risk. Member passwords were not compromised in this attack, just payment information that was entered during that window. It might be challenging to imagine how that's possible, but we're absolutely certain of it. I was personally involved in the forensics. While the attack was clever, it wasn't all-powerful.

Again please verify whether your bank detected fraud on your account. If they did, I can investigate your account.