According to the alert e-mail sent to CoverItLive customers, the company noticed that “certain proprietary data files were accessed without authorization” beginning last Saturday. While they say they’re currently unsure as to what exactly was accessed (though they claim that payment details were definitely not), they urge their users to change their passwords be it they use the same (possibly exposed) password anywhere else. While they say that all user passwords are encrypted, they do not say what sort of encryption (and thus what level of security) was used.
The full text of the e-mail follows:
CoveritLive recently discovered that certain proprietary data files were accessed without authorization starting on or about January 7, 2012. We have not yet determined if, or to what extent, CoveritLive account information (i.e., user names, email addresses and/or passwords) was accessed. We do know, however, that no financial account information has been compromised.
Our investigation is ongoing, and, as a precautionary measure, we will implement required password resets for all active CoveritLive accounts. We plan for this process to begin Saturday January 14, 2012 at 12 AM EDT (5 AM GMT). The next time you log in after the process has begun, you will be asked to change your password before you will be allowed into your account. NOTE: we do not anticipate that you will experience a disruption in your event if you are using CoveritLive while the change is invoked.
Your password and all account passwords are encrypted as a standard CoveritLive information security practice, and we have no evidence that an unauthorized individual has actually retrieved, or is using such data. However, out of an abundance of caution we recommend that if you registered for CoveritLive using an email address and password combination that you use for other online accounts, you should immediately create unique passwords or new login credentials for those other sites and accounts.
We take this matter very seriously and will continue to work to ensure that all appropriate measures are taken to protect your personal information from unauthorized access. We also would like to take this moment to remind you of a couple of tips that should always be followed:
Do not open emails from senders you do not know. Be especially cautious of “phishing” emails, where the sender tries to trick the recipient into disclosing confidential or personal information.
Do not share personal or sensitive information via email. Legitimate companies will not attempt to collect personal information outside of a secure website.
We regret any inconvenience that this password change process may cause you. Please do not hesitate to contact us at email@example.com if you have any questions.