FYI - FabFitFun recently experienced a security issue. You may be prompted to reset your password when you sign in. More from FabFitFun:
Hi Community,
I wanted to make you all aware that our technical team recently discovered that an unauthorized third party gained access to portions of our website that may have enabled them to capture certain information in connection with recent customer sign-ups.
Based on our forensic investigation, this incident concerns the new member sign up pages of our website during the period between April 26, 2020, and May 14, 2020, and between May 22, 2020, and August 3, 2020. Although we believe that only a subset of members who signed up during this period was affected, we are sending notices today to everyone that purchased a subscription or redeemed a Starter Box during this timeframe as a precaution.
We take the security of personal information very seriously, and sincerely regret any concern or inconvenience this may cause. We took steps to address and contain this incident promptly after it was discovered. As soon as our technical team identified the issue, we removed the malicious code and took steps to secure our website with the help of forensic cybersecurity experts engaged to assist with our investigation. We have also reported the matter to law enforcement and are cooperating with the investigation.
Please note that all affected members will receive an email today, and will also receive an official notice via mail explaining the incident. If you did not receive a notice from us directly, this means that we do not have reason to believe that your information was affected.
While we are continuing to review and enhance our security measures, we are confident that the issue has been resolved and will no longer affect transactions on our website. As a further precaution, and as you are now aware, we have initiated a password reset for all FabFitFun members with enhanced complexity and length requirements.
We are here for you if you have any questions, and remain committed to our goal of creating the most valuable membership for you, especially during a period when we need self-care the most.
Take care and stay safe,
Chris
SVP Technology
For your reference, our team has prepared some FAQs:
Q: Can you tell me if I am affected?
A: This incident concerns the new member sign up pages of our website during the period between April 26, 2020 and May 14, 2020, and between May 22, 2020 and August 3, 2020. Notification letters and email communication are being sent to potentially affected individuals. If you did not receive a specific email and letter notification about the incident from us (which is different from the password reset email), this means that we do not have reason to believe that your information was affected.
Q: How are you preventing similar incidents in the future? How do I know shopping on your site is safe?
A: We don’t take this lightly. Your trust is the most important thing to us and our goal is to be proactive and forthcoming with our member communication on these topics. We took steps to address and contain this incident promptly after it was discovered. As soon as our technical team identified the issue, we removed the malicious code and took steps to secure our website with the help of forensic cybersecurity experts engaged to assist with our investigation. We have also reported the matter to law enforcement and are cooperating with the investigation. While we are continuing to review and enhance our security measures, we are confident that the issue has been resolved and will no longer affect transactions on our website.
Additionally, as part of our ongoing security efforts and out of an abundance of caution, we are requiring a password reset for all FabFitFun members with enhanced password length and complexity requirements. Working closely with leading security experts, we will take steps to enhance the security of our site on an ongoing basis and as part of an overall strategy to mitigate the risk of future incidents.
Q: What are you doing to protect the identity of members whose information was potentially compromised?
A: Members who may have been potentially impacted by the incident will be offered complimentary identity protection services from a leading identity monitoring services company. We are deeply appreciative that our members have chosen to be part of the FabFitFun community, and as a token of our appreciation, we will be offering members who were impacted a $25 credit that can be used in with the Winter Add-Ons or Winter Edit sale. Instructions on how to redeem the credit will be included in the individual emails that are sent to those members.
FabFitFun is a quarterly subscription box from FabFitFun.com. Each season they send you a box of $200+ worth items in categories like beauty, fashion, and fitness. It’s our readers’ top pick for the Best Fitness Subscription Boxes of 2020!
Check out our FabFitFun reviews to see what you can expect from this subscription.
Please do not enter your email address in the Name field or in the comment content. Your email address will not be published. Required fields are marked *. Remember to post with kindness and respect. Comments with offensive language, cruelness to others, etc will not be approved. See our full comment policy here.