post this at del.icio.uspost this at Diggpost this at Technoratipost this at Newsvinepost this at Ma.gnoliapost this at Furlpost this at Blinklistpost this at Spurlpost this at Wistspost this at Redditpost this at Farkpost this at Blogmarkspost this at Yahoo! my webpost this at Blinkbitspost this at Connoteapost this at de.lirio.uspost this at feedmelinkspost this at LinkaGoGopost this at Netvouzpost this at RagSugarpost this at Scuttlepost this at Shadowspost this at TailRankpost this at Smarkingpost this at Kinjapost this at Winkpost this at Mr. Wongpost this at Netscapepost this at Windows Livepost this at StumbleUponpost this at Google Bookmarkspost this to Twitter


Cingular Retailer Knowingly Puts Thousands of Customers at Risk for Identity Theft

Between November of 2005 and July of 2006 I was employed by a local Cingular Authorized Retailer that does business by the name of “Wireless Depot“ here in the Portland, OR area. While employed for this company I discovered a potentially serious security flaw in their POS (Point of Sales) system that leaves hundreds, if not thousands, of customers’ and employees’ personal information out in the open for anyone to grab. Shocked and amazed that such a flaw would exist, I did what anybody should do in a position such as this: I immediately contacted my District Manager, Reuben Arcaya, and my Operations Manager, Cassie Smith, and notified them of the flaw and educated them on how devastating and dangerous something like this would be if our databases fell into the hands of the wrong person… or anyone else for that matter!

Of course, neither of them took me seriously and brushed off my sense of urgency as a paranoid delusion. Instead of taking action and fixing the problem, which would have been as easy as clicking a mouse a few times, they told me to just leave it as it was. Upset and frustrated, I emailed one of the head IT professionals in their corporate offices and informed him of the security risk. Once again, I received no response so I decided to just climb the ladder and informed my Regional manager, Mike Greene, about the problem. Luckily for every Cingular customer for whom we ever activated a phone for, this individual actually understood the importance of tackling this problem as soon as possible. Unfortunately, shortly after contacting him about the issue, the company decided that it was time he and they part ways, once again leaving me back at stage one where I started.

A couple weeks went by and we received a new Regional Manager by the name of Edmund Chun. A couple days after Edmund was promoted into his current position he took a trip to our store to introduce himself to all of the employees from our market. During this visit I once again touched base on this security flaw and expressed, in great detail, the dire urgency of getting this flaw taken care of. Once again though, no one appeared to be listening. While every person I talked to promised to help take care of the problem, no one was in a great deal of a hurry to actually fix it.

Eventually, Edmund decided to visit us again and on this one particular visit he was accompanied by the owner of the company, Shaun Yeh. During this visit I managed to sneak Shaun away for a second to explain this seriously dangerous flaw in our POS system to him. If anyone would have understood my sense of urgency to get this problem taken care of you would have guessed it was the actual owner of the company, right? Unfortunately my pleas for action once again fell on deaf ears! It was as if the louder I screamed the more everyone pretended to not hear me.

Frustrated beyond belief I made one more attempt to get the problem resolved. I begged and I pleaded, but in the end our loveable Edmund finally sat down with me and explained why this problem was not fixed, “No one knows about this problem and it will be too expensive to fix at the moment. The chances of someone stumbling upon this problem are slim. As long as you stop talking about it I’m sure no one will discover it!”

The tone in his voice let me know exactly where he stood. I could sit back, and keep my mouth shut, or I could find a new job. According to Edmund, as long as I didn’t tell anyone details about the flaw, it would never be discovered. What was the actual flaw in question? An unsecured wireless access point from our DSL provider, and a shared folder that contained our “password protected” Microsoft Access Database, which houses the personal information of every employee and customer who has ever stepped foot through our store’s doors. By personal information I mean names, addresses, phone numbers, IMEI numbers, SIM card numbers, social security numbers, driver license numbers, checking account numbers, routing account numbers, credit card numbers and a lot more. Trust me, something of that nature was most likely compromised a thousand times over. Luckily the databases in question only held the information for that store and that store alone, but when you have over 50 stores throughout the country those numbers add up really fast. For those of my readers who purchased phones from me in the Portland area, fear not. The second I discovered the flaw I addressed it by turning off our WiFi access point. Since we never used them there was never a reason to have them on. Unfortunately after calling around to several other stores, in many different states, it appears that the issue is still not taken care of.

Eventually, I decided that it was time for me to pursue other business ventures and Wireless Depot and I parted ways shortly there after. After leaving I was left with a decision I had to make. Do I “out” this company publicly and risk the consequences of angering the beast, or do I pretend this never happened and live with the fact that thousands of individuals are at risk of having their lives ruined because I was too afraid to take a stand. Everyone who is reading this article obviously sees which decision I thought was the right one. Sometimes the hardest thing for anyone to do is to speak up against those that do wrong.

At what point do we start holding million dollar corporations responsible for their carelessness? At what point do we take a stand to fight for what we believe in? Today is that day for me. Below is a complete list of all the stores under this company’s umbrella that are, and have been, at risk for lord knows how many years. If you purchased a phone from any of these locations I seriously suggest you go out and get your credit report and if possible set up some kind of credit protection on your social security number.

California

Arcadia Store
1230 S. Goldenwest Ave., #A
Arcadia, CA 91007

Baldwin Park Store
14510 Towne Center Dr Suite 1-A
Baldwin Park, CA 91706 626-338-8129


Diamond Bar Store
1257 S. Diamond Bar Blvd
Diamond Bar, CA 91765
909-861-7888


Duarte Store
1169 Huntington Dr
Duarte, CA 91010
626-301-0899


El Monte Kiosk
10845 Valley Mall
El Monte, CA 91731
626-258-0600


El Monte Store
4780 N. Peck Road
El Monte, CA 91732
626-454-3333


Monterey Park Store
2215 S. Atlantic blvd
Monterey Park, CA 91754
323-415-0088


Rowland Heights Store
1015 S. Nogales #122
Rowland Heights, CA 9748
626-820-0692


Santa Ana Kiosk
318 E. 4th St
Santa Ana, CA 92706
714-647-1220


Santa Ana Store
1702 N. Bristol ST. #C
Santa Ana, CA 92706
714-480-0555


Sunland Store
10509-D Sunland Blvd.
Sunland, CA 91040
818-951-6499


Upland Store
110 S. Mountain Ave #E
Upland, CA 91786
909-985-3700


Mission Gorge Store
6171 Mission Gorge Rd. #108
San Diego, CA 92120
619-521-8000


Oceanside Store
175 Old Grove Road #2
Oceanside, CA 92057
760-433-5717


Sports Arena Store
3681 Sports Arena Blvd
San Diego, CA 92110
619-221-8111


Hawaii

Aiea Store
98-1025 Moanalua Rd
Aiea, HI 96701


Kapahulu Store
909 Kapahulu Avenue Unit 7
Honolulu, HI 96816
808-734-8282


Pearlridge Store
Pearlridge Shopping Center
Pearl City, HI


Idaho

Coeur D’Alene Store
202 W. Ironwood Dr., #F
Coeur D’Alene, ID 83814
208-664-9363

Kellogg Store
120 W. Cameron Ave #7
Kellogg, ID 83837
208-783-2520


Lewiston Store
1702 21st St. Suite 101
Lewiston, ID 83501
208-798-8855


Nevada

Boulder Store
110 N. Boulder Hwy Ste 100
Henderson, NV. 89015
702-438-6888

Decatur Store
284 S. Decatur Blvd
Las Vegas, NV 89102
702-877-3000


Desert Inn Store
2833 E. Desert Inn Rd Suite A2
Las Vegas, NV 89121
702-212-0807


Flamingo Store
4850 W Flamingo Rd.
Las Vegas, NV 89103
702-248-9700


Nellis Store
420 N. Nellis Blvd Suite A2
Las Vegas, NV 89110
702-459-7791


Rancho Store
751 N. Rancho Dr.
Las Vegas, NV 89106
702-898-5588


Russell Store
5725 S Pecos Rd Suite D2
Las Vegas, NV 89121
(702)456-2888


Sloan Store
5891 E. Charleston Blvd Suite 140
Las Vegas NV 89142
702-207-1035


Stephanie Store
180 S. Stephanie Suite 120
Henderson, NV 89014
702-822-5888


Tenaya Store
3250 N. Tenaya Way Suite 112
Las Vegas, NV 89103
702-645-4279


Tropicana Store
2470 E. Tropicana Ave Suite B
Las Vegas, NV 89142
702-450-3691


Oregon

Fubonn Plaza
2850 S.E. 82nd Ave #110
Portland, OR. 97266

Lake Oswego
101 State St Suite 140G
Lake Oswego, OR 97034


North Portland
1440 North Lombard Street #B
Portland, OR 97217


Pearl District
900 NW Lovejoy St
Portland, OR 97209


Washington

Edmonds Store
22511 Hwy 99, #109
Edmonds, WA 98026
425-776-6601


Factoria Store
3615 Factoria Blvd #A
Bellevue, WA 98006
425-641-8080


Great Wall Store
18230 E. Valley Hwy #181
Kent, WA 98032
425-656-0655


Jackson Square Store
1200 S. Jackson St. #5
Seattle, WA 98144
206-709-1010


Kennewick Store
350 Columbia Center
Kennewick, WA 99336
509-737-8102


Overlake Store
Overland Shopping Ctr
15617 NE 24th St. Redmond,
WA 98052
425-562-1011


Pike Place Store
2003 Western Ave. #109
Seattle, WA 98121
206-728-9119


Spokane Store
9331 N Newport Hwy
Spokane, WA 99218
509-482-6006


Uwajimaya Store
600 5th Ave
Seattle, WA. 98104
206-709-1010


Westgate Store
2621 N Pearl
Tacoma, WA 98407
253-759-5759


Yakima
1300 N. 40th Ave. #113
Yakima, WA 98908
509-469-6111

EDITORS NOTE: Wireless Depot operates under several other names in the many different states where it does business. Some of those names are JustPCS, Wireless Depot, B-Per Electronics, Digital PCS and The Net Wireless. The parent company, The Net Wireless (http://www.thenetwireless.com) is based out City of Industry, CA.