This happened a while back but looks like it was worse then they figured. Current update:
Long story short, maybe a month or so ago their backup server got hacked followed by their main server, and it was unknown at that point if they had other backups of the forums. At that point they did not figure any CC info was stolen.
This is a scary reminder that this can happen to anyone. If someone really wants to hack a site, they'll find a way. These are people that do this all day and know more then even the top security professionals put together. Securing your server will help a lot but if someone really wants in, they'll find a way.
UPDATE: 7:14pm est 04/07/09
From what we know now, there were more records on the database server where the credit card dump was taken. If research shows that a larger number of customer's data was compromised, we will contact those individuals directly.
UPDATE: 4:34pm est 04/07/09
It has been brought to our attention that any WHT Premium memberships purchased PRIOR to 2006 would be included in the exploited credit card details.
UPDATE: 4:24pm est 04/07/09
We have contacted all major credit card companies and are awaiting their guidance. It should be noted that card holders will not be held liable for any fraudulent purchase made using their credit card.
ANNOUNCEMENT - 1:25pm est 04/07/09
This morning, the hacker who attacked WHT initiated further communication. He provided evidence that credit card information on one of our database servers was, in fact, compromised during that attack.
What data was compromised?
At this point, we know that the hacker compromised and has publicly posted credit card information from our self-service billing system currently used for sticky posts (located at http://myinet.inetinteractive.com). This system was also used for display (banner) advertising in prior to December 2007.
What about premium and corporate members? Or display advertisers?
If you've purchased a premium or corporate membership or you are a display (banner ad) advertiser from December 2007 or later, your data is safe. These products run on a newer billing platform that does not store credit card information.
What is WHT and iNET Interactive doing about it?
If we have evidence or suspicion that your credit card information was leaked, you will be receiving further communication from WHT and iNET Interactive.
Why is WHT down and when do we expect it to be back up?
We're currently doing a full security sweep of our cluster to ensure the servers are secure. The site will be back up once this security review is complete.
Long story short, maybe a month or so ago their backup server got hacked followed by their main server, and it was unknown at that point if they had other backups of the forums. At that point they did not figure any CC info was stolen.
This is a scary reminder that this can happen to anyone. If someone really wants to hack a site, they'll find a way. These are people that do this all day and know more then even the top security professionals put together. Securing your server will help a lot but if someone really wants in, they'll find a way.