Jump to content

NCIX Data breach 2018

SirRemog
Message added by vanished

This is the thread on this news story.  If you see other threads popping up about it, please report them and ask for them to be merged in here.  Don't bother commenting on them.

1 hour ago, rcmaehl said:

Stolen from chat. Product Drop Tester Predicts Data Breach (2018, Colorized)
 

 

image0.jpg

 

Well Shiiiiiiiiiieeeeet...

Gotta cancel my credit card then, and update my pre-authorized monthly bill payments...

F#$kin' NCIX's founder, Steven Wu....ya goof'd Bic Tyme Bic Boi

Intel Z390 Rig ( *NEW* Primary )

Intel X99 Rig (Officially Decommissioned, Dead CPU returned to Intel)

  • i7-8086K @ 5.1 GHz
  • Gigabyte Z390 Aorus Master
  • Sapphire NITRO+ RX 6800 XT S.E + EKwb Quantum Vector Full Cover Waterblock
  • 32GB G.Skill TridentZ DDR4-3000 CL14 @ DDR-3400 custom CL15 timings
  • SanDisk 480 GB SSD + 1TB Samsung 860 EVO +  500GB Samsung 980 + 1TB WD SN750
  • EVGA SuperNOVA 850W P2 + Red/White CableMod Cables
  • Lian-Li O11 Dynamic EVO XL
  • Ekwb Custom loop + 2x EKwb Quantum Surface P360M Radiators
  • Logitech G502 Proteus Spectrum + Corsair K70 (Red LED, anodized black, Cheery MX Browns)

AMD Ryzen Rig

  • AMD R7-5800X
  • Gigabyte B550 Aorus Pro AC
  • 32GB (16GB X 2) Crucial Ballistix RGB DDR4-3600
  • Gigabyte Vision RTX 3060 Ti OC
  • EKwb D-RGB 360mm AIO
  • Intel 660p NVMe 1TB + Crucial MX500 1TB + WD Black 1TB HDD
  • EVGA P2 850W + White CableMod cables
  • Lian-Li LanCool II Mesh - White

Intel Z97 Rig (Decomissioned)

  • Intel i5-4690K 4.8 GHz
  • ASUS ROG Maximus VII Hero Z97
  • Sapphire Vapor-X HD 7950 EVGA GTX 1070 SC Black Edition ACX 3.0
  • 20 GB (8GB X 2 + 4GB X 1) Corsair Vengeance DDR3 1600 MHz
  • Corsair A50 air cooler  NZXT X61
  • Crucial MX500 1TB SSD + SanDisk Ultra II 240GB SSD + WD Caviar Black 1TB HDD + Kingston V300 120GB SSD [non-gimped version]
  • Antec New TruePower 550W EVGA G2 650W + White CableMod cables
  • Cooler Master HAF 912 White NZXT S340 Elite w/ white LED stips

AMD 990FX Rig (Decommissioned)

  • FX-8350 @ 4.8 / 4.9 GHz (given up on the 5.0 / 5.1 GHz attempt)
  • ASUS ROG Crosshair V Formula 990FX
  • 12 GB (4 GB X 3) G.Skill RipJawsX DDR3 @ 1866 MHz
  • Sapphire Vapor-X HD 7970 + Sapphire Dual-X HD 7970 in Crossfire  Sapphire NITRO R9-Fury in Crossfire *NONE*
  • Thermaltake Frio w/ Cooler Master JetFlo's in push-pull
  • Samsung 850 EVO 500GB SSD + Kingston V300 120GB SSD + WD Caviar Black 1TB HDD
  • Corsair TX850 (ver.1)
  • Cooler Master HAF 932

 

<> Electrical Engineer , B.Eng <>

<> Electronics & Computer Engineering Technologist (Diploma + Advanced Diploma) <>

<> Electronics Engineering Technician for the Canadian Department of National Defence <>

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, -rascal- said:

NCIX's founder, Steven Wu....ya goof'd Bic Tyme Bic Boi

Not his fault, everything was taken away from him when he went bankrupt.

 

I assume (someone correct me if I'm wrong) the blame lies with the company responsible for liquidating the assets.

System specs:

4790k

GTX 1050

16GB DDR3

Samsung evo SSD

a few HDD's

Link to comment
Share on other sites

Link to post
Share on other sites

Quote

 mounted one image belonging to Steve Wu the founder of NCIX. Inside I found data going back 13 years, financial documents, employment letters containing SIN numbers, and data from Mr. Wu’s home computer which featured personal documents and images of his family mixed in with numerous private photos of high end escorts from mainland china.

my favorite part of the article. now I know where my restocking fees went

i7-8700k @ 4.8Ghz | EVGA CLC 280mm | Aorus Z370 Gaming 5 | 16GB G-Skill DDR4-3000 C15 | EVGA RTX 2080 | Corsair RM650x | NZXT S340 Elite | Zowie XL2730 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, AntiTrust said:

my favorite part of the article. now I know where my restocking fees went

Ya boy Steve Wu knew what was up

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

well I called my credit card company and said I was worried about a data breach at an online store I used to use and the guy was super helpful. Card blocked and new card with new number coming in a few days.

 

fuck you NCIX!!!

i7-8700k @ 4.8Ghz | EVGA CLC 280mm | Aorus Z370 Gaming 5 | 16GB G-Skill DDR4-3000 C15 | EVGA RTX 2080 | Corsair RM650x | NZXT S340 Elite | Zowie XL2730 

Link to comment
Share on other sites

Link to post
Share on other sites

I used to work there. Apparently our SIN numbers are on there so what can we do about that?

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, _Zer0_ said:

I used to work there. Apparently our SIN numbers are on there so what can we do about that?

Contact the Government (Service Canada) immediately. 

 

And probably consider legal options. Maybe a class action is something that could happen in the future? Though IANAL so YMMV

Link to comment
Share on other sites

Link to post
Share on other sites

i seen this more the once with laptop... so many laptops........ you be surprise how many times i had to clear out stuff like this,.,,

MSI x399 sli plus  | AMD theardripper 2990wx all core 3ghz lock |Thermaltake flo ring 360 | EVGA 2080, Zotac 2080 |Gskill Ripjaws 128GB 3000 MHz | Corsair RM1200i |150tb | Asus tuff gaming mid tower| 10gb NIC

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Terryv said:

I assume (someone correct me if I'm wrong) the blame lies with the company responsible for liquidating the assets.

Basic PCI compliance: ENCRYPT YO' SHIT

Link to comment
Share on other sites

Link to post
Share on other sites

So.. What do we do? Is there a way to check to see if we were affected? Anything?? What are the steps we should take?

Moist

Link to comment
Share on other sites

Link to post
Share on other sites

I'm wondering if some Linus' old work data is also on there.  He may need to worry about his own PII data being out there due to NCIX's negligence.

Link to comment
Share on other sites

Link to post
Share on other sites

Best way to prevent something like this is to allow the IT staff to take all drives to a local gravel pit with a sledgehammer or shotgun and let them have an Office Space moment prior to the closing.

Link to comment
Share on other sites

Link to post
Share on other sites

Linus should investigate if his PII data is protected due to NCIX's negligence.

Link to comment
Share on other sites

Link to post
Share on other sites

Now I'm wondering if there are any Government regulations regarding the handling of customer data in the case of bankruptcy. Yes, NCIX should've encrypted their drives, but that's the tip of the iceberg when you consider how many companies still have boxes and boxes of paper records as Linus showed in his videos. And clearly it seemed like the people running these auctions don't give a crap and just leave them on the show room floor. I wouldn't even be surprised if they sold them. They're solely there to recoup money and since customer information has more value than ever these days, it's a no-brainer in their perspective. NCIX just happened to be the one who should've known better. But I can bet you there are thousands of small businesses that don't encrypt their drives that could face a similar fate and have company and customer data sold or leaked. To even think this data wasn't ceased upon filing for bankruptcy with the courts, and having auctioneers just sell these unformatted drives boggles my mind. 

 

TL;DR It's not just a failure on NCIX's part, it's a failure on all parties involved with the filing of this bankruptcy. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

I haven't seen the other reports, but I did read this article, including information like "This even featured personal documents and images of Mr. Wu’s family mixed in with numerous private photos of high end escorts from mainland china." [sic]

 

Let me know if anyone finds information about a class action lawsuit against whomever is responsible for this...

Link to comment
Share on other sites

Link to post
Share on other sites

I'd like to take a moment to thank NCIX for always having exorbitant shipping fees for anything I thought about buying from them. Sure a case may have been $10 cheaper than Amazon there but when it cost $30 to ship it to me I picked Amazon every time. So thanks for disuadding me back then so I'm not getting fucked over by you now xD

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, imreloadin said:

I'd like to take a moment to thank NCIX for always having exorbitant shipping fees for anything I thought about buying from them. Sure a case may have been $10 cheaper than Amazon there but when it cost $30 to ship it to me I picked Amazon every time. So thanks for disuadding me back then so I'm not getting fucked over by you now xD

I guess this was a plus for living in the same city as their headquarters. Just place an order online and pick up at one of their 3 stores or warehouse in Richmond later in the day. I've practically bought all of my parts from them prior to their bankruptcy. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

>Not having customer data encrypted

 

How?!

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

NCIX was a major seller to various BC Government and Government of Canada, IT Departments. If this is true, I expect to see some fairly spectacular fireworks.

I say "if" because at current we only have one source of this information.

Link to comment
Share on other sites

Link to post
Share on other sites

People need to remember, data breaches/leaks like this do not only occur just from businesses shutting down or going bankrupt, but also routine upgrades and hardware refreshes.

 

As someone who regularly purchases Enterprise-class IT hardware from Canadian Government auctions, there's been a number of occasions where sensitive/damaging data hasn't been wiped from drives or flash memory of networking gear has not been cleared. 

Link to comment
Share on other sites

Link to post
Share on other sites

To be honest, the best way to protect your data is not to give it out.

Restrict how much you give out, don't count on other people to protect your data. Don't rely on Cloud based solutions to protect your information. As soon as your information is out of your hands, you have lost control of it.

This isn't 100% fool proof by any means, but its the best place to start. By reducing your data footprint. The more you shrink your data foot print, the less likely you will be hit.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Tannah said:

To be honest, the best way to protect your data is not to give it out.

Is this meant to be helpful in some way? This wasn't some fan forum; it was a commercial retail outlet. You can't not give personal information for online transactions, especially if you didn't live in a city with an NCIX pickup location, as they have to mail it somewhere.

 

29 minutes ago, cchhrriiss11 said:

As someone who regularly purchases Enterprise-class IT hardware from Canadian Government auctions, there's been a number of occasions where sensitive/damaging data hasn't been wiped

I sincerely hope you've reported this to the Privacy Commissioner. If not, here you go: https://www.priv.gc.ca/en/report-a-concern/

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×