Urgent Notice to Rudder Users [email]
The following message showed up in my inbox this afternoon. Because I’ve written about Rudder in the past, I figured that it was best that I also share this email. I think it is very respectable that they were so quick to admit the wrongdoing and show their plans for preventing it from happening again. What do you think?
Today, 732 Rudder users were sent alerts via e-mail, which could have potentially included
information like account balances, transactions and bills of different users. This issue was not
the result of a data breach, but due to a software issue in our program that generates emails. It is
important to know that Rudder has “read only†access to your account balances and transactions
and we do not store account credentials like user names, passwords, or your personal
information like name, address or social security number.
If you have questions or wish to speak to a Rudder representative please call our hotline at
1 (877) 730-4914 extension 0.
What happened?
On May 18th, 2009 we made a change to our program that generates custom email updates for
each individual user. On May 19th, 2009, due to a software bug, the email program sent out
multiple emails to multiple users, which could have provided access to information that related to
a different Rudder user. The issue was detected early and subsequently all email
communications were stopped. However, incorrect emails were sent to users whose email
addresses started with either a number or the letters “a†or “bâ€. In total, emails were sent out to
732 users (less than 2% of Rudder’s user base). We’d like to reiterate that Rudder has “read onlyâ€
access to your account balances and transactions. We do not store account credentials like user
names, passwords, or your personal information like name, address or social security number.
What are we doing about it?
First, the email alert system has been completely turned off, and the links that log you into your
Rudder account have been disabled.
Second, we are offering affected users a complimentary subscription to an Identity Theft
protection service. The details of this offer will be made available later this week.
Third, we will engage an independent security specialist to review our processes and provide
recommendations on controls to prevent anything like this from happening again in the future.
To be clear this incident was not the result of a security breach, nor was any third-party hacker
involved.
Users who wish to completely cancel and delete their accounts may do so by clicking here and
logging in. https://www.rudder.com/settings/
What data has been exposed?
The e-mails that went out today included access to the following information:
* Â Â Â E-mail address of the Rudder account holder
* Â Â Â Account balances of the Rudder account holder
* Â Â Â Recent transactions of the Rudder account holder
* Â Â Â Bills of the Rudder account holder
What data was not exposed?
Rudder does NOT have access to the following information. Even in the event of a full security
breach, it is impossible for anyone to retrieve:
* Â Â Â Full (given) name (unless your name is in the email address)
* Â Â Â Social Security Number
* Â Â Â Account number(s)
* Â Â Â Bank/Credit Card website user names or passwords
Why it will never happen again.
In addition to the security audit, our alert server and distribution system will be rebuilt from the
ground up. We will keep you up-to-date on this process, every step of the way. We are launching
a Rudder Security Update tumble log here http://rudderupdate.tumblr.com/ to provide these communications. We will also be communicating with users by e-mail and phone, if necessary.
We greatly appreciate the generosity that the Rudder user community has shown us thus far, and
for those of you who choose to continue managing your finances with us, we will go above and
beyond the call of duty in every aspect of our business in order to regain your confidence.
Again, anyone who wishes to cancel their account and delete all associated data may do so here
https://www.rudder.com/settings/.
The online banking industry itself (including companies large and small) has been grappling very
publicly with issues of security and privacy for many years. We sincerely regret that Rudder let
down our users with this breach.
More than anything, we hope that users do not let this incident discourage them from pursuing
the benefits of managing their finances online, regardless of which provider they may use.
Improving Americans’ financial health has been our mission since day one, and we continue to
believe that this new generation of personal finance management applications, including Rudder,
have the potential to change the world for the better.
Sincerely,
The Rudder Team