Question

In: Operations Management

Eric received an email from Amazon Customer Service that said "Thank you for contacting us." But...

Eric received an email from Amazon Customer Service that said "Thank you for contacting us." But Eric did not contact them. Instead, an attacker had contacted them and pretended to be Eric. When Amazon Customer Service asked the attacker to identify himself all he had to do was give Eric’s name, email address, and mailing address—which the attacker got from Whois, which contains Eric’s registration information for his website. However, Eric knew to protect his actual mailing address so the registration information on Whois was actually a hotel close to Eric’s house. Because the information matched what was on file, Customer Service told the attacker the mailing address of Eric’s order, which was his real home address. Eric contacted Amazon, found out these details, and told them not to release any of his information to anyone who contacted Customer Service, to which Amazon agreed. Fast forward two months. Eric again received another "Thank you for contacting us" email. After contacting Amazon again, he found that this time the attacker had tried to get the last four digits of Eric’s credit card number on file through more social engineering tricks.

Fortunately, this time Amazon did not surrender that specific piece of information (although they had ignored his previous instruction not to give out any information). Had they provided the credit card number the attacker would have had enough information to pass the "I’m-the-real- Eric" test on almost any of Eric’s online accounts (using his name, email address, mailing address, and last four digits of his credit card) and trick their Customer Service into resetting Eric’s password. This would then allow the attacker to get into Eric’s online accounts and purchase a virtually unlimited number of items charged to Eric’s credit card. What went wrong? Should the first Amazon Customer Service representative have been reprimanded? What policies should Amazon have had in place to prevent this? What technologies should there be in place to prevent this? As a customer, what should you do to protect your online accounts?

Write a one-page paper on your analysis.

Solutions

Expert Solution

The customer identity verification process at Amazon was not comprehensive and strong. An attacker had posed to be Eric and had obtained his mailing address. The verification process just asked the attacker to confirm name, email address and mailing address. These are the basic information which is accessible to all. Hence the attacker could easily pose to be Eric and get information from the customer service center at Amazon.

When the first attacker call had happened and Eric had contacted the customer service at Amazon, informed about the imposter and had asked them not to disclose his information to anyone. Amazon did not take any other step apart from this. However, the customer service got another call from the imposter, 2 months forward, and they again failed to identify the hoax. The customer identity verification procedure at Amazon customer service center was not adequate. Anyone can pose to be any customer and can get vital information. This is clearly data theft and can be considered a type of cyber crime.

The first customer care representative did not do much to report about the imposters to the higher authorities. This was a matter of concern for the company and a loop hole in the customer identity verification system. This could have led to major data leakage and could have been foundation of a cyber crime. The first customer care representative needs to be counselled by the management.

The policies and technologies which could have prevented this situation are as follows:

· A comprehensive customer identity verification process asking some difficult questions from the customers could have been a better way

· The customer data must be stored in various layers of protection

· The customer data must be encrypted to save it from any cyber attack and data leakage

As a customer, I would have ensured the following to keep my data safe online:

· Having updated firewalls on my system

· Not giving all information on any random site that I visit

· Having complex passwords and security questions for online accounts


Related Solutions

Email from Suresh Batik I received the following email from a former student. I hope you...
Email from Suresh Batik I received the following email from a former student. I hope you are doing well. I took your Managerial Accounting class ten years ago and have a question on how to do costing in a service-based business. Currently, I am working for a firm that manufactures various products used in pipelines (torque wrenches, flange pullers, bolts and flanges, grinding machines, etc.). Five years ago we began servicing pipelines in refineries, offshore/onshore platforms, nuclear plants, etc. Our...
1) If a customer provides us an email address, does this automatically mean that we have...
1) If a customer provides us an email address, does this automatically mean that we have the right to use it in our marketing materials? Why or why not? What can we do to help alleviate any misunderstandings that may occur if we misread our customers intent when the customer gave us their email address? 2) What information other than the basic customer contact information like name and address do you believe is the most important to collect for marketing...
You received a letter of recommendation from a teacher. Write a thank-you note.
You received a letter of recommendation from a teacher. Write a thank-you note.
Spoofing email is a common occurrence these days. Have you received a spoofed email? Briefly, describe...
Spoofing email is a common occurrence these days. Have you received a spoofed email? Briefly, describe the email and how did you notice it was not legit? Anything else that was odd concerning the spoofed email?
One of the major challenges companies face is providing customer service information via email. Think of...
One of the major challenges companies face is providing customer service information via email. Think of companies you do business with. Do you email them? How long does it normally take for them to respond? Explain some of the shortcomings of using email for customer service.
Why would a customer buy a product or service from you? Pick a product or service...
Why would a customer buy a product or service from you? Pick a product or service that you currently offer, or would like to offer, and use this worksheet to brainstorm about aspects of your company, product, or service that would motivate a customer to choose you rather than a competitor." Awareness: Features and benefits: Price: Brand: Convenience: Word-of-mouth: Affiliation: Other:
If Amazon launchs their own delivery service, What customer need, wants and demands are being met....
If Amazon launchs their own delivery service, What customer need, wants and demands are being met. (Please answer it as a maketing manager.-This is marketing class.)
300 words(minimum).... One of the major challenges companies face is providing customer service information via email....
300 words(minimum).... One of the major challenges companies face is providing customer service information via email. Think of companies you do business with. Do you email them? How long does it normally take for them to respond? Explain some of the shortcomings of using email for customer service.
A company received payment of $10,000 from a customer that had previously received services performed on...
A company received payment of $10,000 from a customer that had previously received services performed on account. What would the effect of this transaction on the company’s current month accounting equation? Select one: A. No effect on Assets; No effect on Liabilities; No effect on Stockholders’ Equity B. $10,000 increase in Assets; $10,000 increase in Liabilities; No effect on Stockholders’ Equity C. No effect on Assets; $10,000 increase in Liabilities; $10,000 decrease in Stockholders’ Equity D. $10,000 increase in Assets;...
2a). The customer service department of H&R Block received a total of 235 telephone requests for...
2a). The customer service department of H&R Block received a total of 235 telephone requests for a tip-sheet on personal tax or corporate tax. The following table summarizes callers' primary area of interest, and how they first heard about the tip-sheet. Topic of most interest to caller How the caller first heard about the report Radio Newspaper Television Internet Personal tax 34 20 26 20 Corporate tax 36 70 14 15 What is the probability a caller is interested in...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT