Threadless.com - Best t-shirts in the world
Type Tees - Amazing tees created from submitted slogans!
The Select Series - Artist edition limited invite only tee shirt designs
Threadless Kids - Designer kids & baby clothing
Threadless news, your #1 source for Threadless news!
For news about Threadless, what better place to look than the official Threadless news section??

  Aug 14 '09 by Threadless        30 Comments        Watch this      Share:  Share on facebook    Share on delicious    Share on digg    Share on MySpace    Tweet this    Stumble this    Share this on Kaboodle   
To those of you who may have been affected by the hacking of our mass-email services provider late last weekend, the following information is everything that we are currently up to speed on:

Our mass-email services provider,
Campaign Monitor had their had a large portion of their database hacked into last weekend (which continued through the middle of this week) and many of their clients email lists were compromised, including Threadless. As a result, an number (still unknown exactly how many as of this post) of our community members and newsletter subscribers email addresses were compromised and as a result those addresses have been hit with spam.

We can assure you that we always take your privacy very seriously and we sincerely apologize for any inconvenience this unfortunate incident may have caused. This is a vendor that we are no longer utilizing and we hope that we don't incur problems like this in the future.

This is a post from earlier this week with some details, we'll provide the update shortly thereafter:

Hey everyone - I wanted to clear up a few points before some rumors and speculation start becoming confused with what is actually happening.

Why does this vendor even have an email list to begin with?

Because this vendor provided mass-email messaging services for us (namely sending out newsletters, upcoming sale info, etc.) When we send out our weekly newsletter, keep in mind it goes to hundreds of thousands of subscribers - the process isn't as simple as typing in "to: everyone" then clicking send. As our community grew, it became very difficult to send out our newsletters and updates in house, thus the need for a third-party vendor to provide these services.

So why do they still have the list if you haven't used them in 6 months?

Because when you walk away from a vendor that provides these services, it's not just a clean break. These vendors are required to keep these lists for some time because of opt-out lists - Community members opt-out/unsubscribe from old emails all the time - emails that were sent through the old vendor. This is really common practice and above all, it keeps us compliant with the spam laws regarding the ability of recipients to opt out of our communications (i.e. CAN-SPAM Act of 2003).

So what really happened?

The vendor in question, (I am purposely not giving their name at this point because their site is still under attack as of this message) is being aggressively attacked by some evil hackers who not only gained access to our mailing list, but gained access to at least a few other of their clients email databases as well.

We are currently working with this vendor to assess the damage and find out how many email addresses were actually obtained, once we have this information we will be contacting those people who were affected by this unfortunate incident.

One last point I want to make is that we do take our privacy policy very seriously - so much so that we had our website, our privacy policy and related practices certified by a leading third party watchdog (www.truste.org). Having the trust of our community is of the utmost importance to us and we strive to maintain this level of trust every single day.





squatterjohn
squatterjohn on Aug 14 '09 at 1:26pm
Thank you!
bcrider
bcrider on Aug 14 '09 at 1:26pm
You guys rock. :)
squintygirl
squintygirl on Aug 14 '09 at 1:28pm
Thanks for the update, much appreciated.
nikolina100
nikolina100 on Aug 14 '09 at 1:28pm
Threadless is made of goodness!
tracerbullet
   tracerbullet on Aug 14 '09 at 1:29pm
we'll get you next time, spammers! next tiiiiiiiime!
the other festa
the other festa on Aug 14 '09 at 1:31pm
UPDATE:

Here is an update from Campaign Monitor

At this time we are still working with CM to assess the full extent of how many email addresses were compromised.

We can confirm that the only personally identifiable information that was compromised were the email addresses. No other PII, order history or credit card data was compromised in this attack.
tracerbullet
   tracerbullet on Aug 14 '09 at 1:34pm
luckily i didn't get any spam that i'm aware of. although gmail catches all my spam anyway, so who knows.
tracerbullet
   tracerbullet on Aug 14 '09 at 1:41pm
ah, i was wrong. i did get spam. but gmail caught it.
Torakamikaze
   Torakamikaze on Aug 14 '09 at 1:43pm
how embarassing
squatterjohn
squatterjohn on Aug 14 '09 at 1:43pm
I got the PDF thing that the guy in the other blog alerted us to, but it also went to my Spam folder. Still, there's probably more on the way. Damn hackers!
tracerbullet
   tracerbullet on Aug 14 '09 at 1:48pm
i blame brett favre. everything is his fault.
rbthatcher
rbthatcher on Aug 14 '09 at 1:52pm
I'd blame it on cssss
professorE
professorE on Aug 14 '09 at 1:59pm
dsssssssss's blog took literally hundreds of times more of my actual time than the one solitary nugget of spam did.

Hell, typing this comment has it beat tenfold.
SuperRyan
SuperRyan on Aug 14 '09 at 2:01pm
No probs.
gumbolimbo
   gumbolimbo on Aug 14 '09 at 2:07pm
sorry to see that happen. It sucks, but if it's any consolation Threadless isn't the only one.
Recently I found emptees is quite leaky, and I found another apparel sellers mailing list appears to be hacked too. (I use unique email adresses for everything I sign up to, so it's easily traced back when something is leaking)
skeev
skeev on Aug 14 '09 at 2:09pm
We can confirm that the only personally identifiable information that was compromised were the email addresses. No other PII, order history or credit card data was compromised in this attack.

I would hope that this statement doesn't imply that a vendor responsible for your mass emailings would even have access to my credit card data...or this vendor also responsible for processing your orders too?

In the end I'm glad that more vital information was not breached I am curious as to who else you have to share credit card data with, if anyone.
individual8
individual8 on Aug 14 '09 at 2:13pm
What 'vendor' are you talking about, if not Campaign Monitor?
Jackanapes mk.II
Jackanapes mk.II on Aug 14 '09 at 2:16pm
Ugh.
the other festa
the other festa on Aug 14 '09 at 2:29pm
@skeev - Just wanted to make that clear in case of any doubt - I didn't mean to imply that they had this info to begin with as they definitely did not have any other info besides the email list. Sorry for any confusion!
the other festa
the other festa on Aug 14 '09 at 2:30pm
@individual8 - Campaign Monitor = 'vendor'
skeev
skeev on Aug 14 '09 at 2:38pm
Ah, no problem.
FRICKINAWESOME
   FRICKINAWESOME on Aug 14 '09 at 2:55pm
I didn't receive any spam. Why don't the hackers love me?



ps- no prob Threadless. It happens to the best of us. We're still cool like dat yo.
dssss
dssss on Aug 14 '09 at 6:04pm
So why do they still have the list if you haven't used them in 6 months?

Because when you walk away from a vendor that provides these services, it's not just a clean break. These vendors are required to keep these lists for some time because of opt-out lists - Community members opt-out/unsubscribe from old emails all the time - emails that were sent through the old vendor. This is really common practice and above all, it keeps us compliant with the spam laws regarding the ability of recipients to opt out of our communications (i.e. CAN-SPAM Act of 2003).


Could you possibly explain to me in what way a "vendor" / mass email service provider that hasn't been used in 6 months can, in any way whatsoever, allow a customer to opt-out. Especially, when the opt-out link has been directed at a sub-domain of Threadless for, at least, the whole of 2009, and presumably the new "vendor" would be required to know whom had opted out. (Unless you are saying that the old "vendor" periodically informed the new "vendor" of who had unsubscribed, rather than merely letting the new "vendor" control it, lol).
BlueDanGroup
BlueDanGroup on Aug 15 '09 at 2:18am
No spam here, but thanks to Threadless for being open about this, most companies would try to sweep things like this under the carpet.
kooky love
   kooky love on Aug 15 '09 at 2:47am
I've got two spam this week, 1. they ask me to restore my facebook account by html that they attached in the email
2. they ask me to do the same thing but for my paypal account
I dunno is these spam connect with this matter or not? But thanks a lot threadless.
Don't worry threadless. We support you and good luck!
Yay! white


kooky love
   kooky love on Aug 15 '09 at 2:51am
Bill gates has the same problem. Not only you :)
yaywhite
Andreas Mohacsy
   Andreas Mohacsy on Aug 15 '09 at 3:00am
go gettem TL
OneRedRocket
OneRedRocket on Aug 17 '09 at 2:40am
No Spam here thanks for the quick work
Miss Mayhem
Miss Mayhem on Aug 17 '09 at 8:28pm
So that's why this week's newsletter (for me anyway) got stuck in my spam folder. Thanks for clearing this up. :]
9 days later
Mya Jamila
Mya Jamila on Aug 27 '09 at 5:23pm
I haven't told you I love you recently.

I love you Threadless.

You're an amazing company.
Thank you for everything.
You must be logged in to leave a comment.

News tools

Meet the staff
Profiles of Threadless staff members
skawshimalaJeFshondimimiarzie13kahleanspeedyjvwxleration00I AM H2CharlesFestabeanie-odhenderlkatiefordibipsekovachHellpandaBNannashello.kristeninaudiblewearecarefulspigumusscottvdetour1999LauraCatgferg55Rachel Ray Guncsteph01ADD LTD.donelladthe other festabschaefwebcitedarktaxfutureprimitivejcassarlyashmoneyatkinsDYRbabyknucksmagicalthinkletaycachagoingonsixkingawesomenessjcurleeThe TomMattJordanpolarizemeFree BeerohmymamaginaEdward GobboalesaurusrexFatManCantKeepAWifexthednixmeghan.g.alabamergencymargauxteeSheyOliverchicagoredwilsonfongbiggitybamXavier Alexander