Archived Content

The following content is from an older version of this website, and may not display correctly.

Infrastructure of Amazon-owned online shoe retailer Zappos has recently experienced a security breach that affected accounts of more than 24m of the company’s customers, the company announced to its customers and employees Sunday.

In an email to his employees, Zappos CEO Tony Hsieh wrote that a “criminal” had gained access to parts of the company’s internal network and systems through one of its servers in Kentucky.

“We are cooperating with law enforcement to undergo an exhaustive investigation,” he wrote, explaining that Zappos could not provide any specific details about the incident “because of the nature of the investigation.”

A Zappos spokeswoman said Tuesday the company could not provide any update on the investigation or any other information beyond what was included in Hsieh’s email to employees and the company’s emails to customers published online.

While the perpetrator(s) had gained access to customers’ names, email addresses, billing and shipping addresses, phone numbers, the last four digits of their credit card numbers and encrypted passwords, their “critical credit card and other payment data was not affected or accessed,” Zappos said.

The company attempted to pacify its customers by saying information that was exposed was standard information usually found on receipts. Nevertheless, Zappos had expired customers’ passwords and instructed them to create new ones.

Amazon and Zappos signed an acquisition agreement in July 2009 for a stock transaction valued at nearly US$900m.