MENU
component-ddb-728x90-v1-01-desktop

Attorney: Secret Service investigates Park 'N Fly data breach

PORTLAND, Ore. -- The pre-pay parking service Park 'N Fly announced a data security breach that could impact travelers heading to Portland International Airport.

The breach is serious enough to warrant an investigation from the U.S. Secret Service, according to a law firm hired by the company.

Park 'N Fly, an Atlanta-based company that has relationships with two parking lots near PDX, announced Wednesday, Jan. 13 that the security of certain payment cards used to make reservations through its e-commerce website were at risk.

According to the announcement on the company's website, Park 'N Fly determined the data potentially at risk includes the card number, card holder's name and billing address, card expiration date and CVV code. Other loyalty customer data potentially at risk includes email addresses, Park 'N Fly passwords and telephone numbers.

The On Your Side Investigators learned Park 'N Fly hired Philadelphia-based law firm Lewis, Brisbois, Bisgaard & Smith. A lawyer there, Jim Prendergast, said the company is rigorously investigating the breach, which he said involved the U.S. Secret Service.

The Secret Service exercises broad investigative jurisdiction over a variety of financial crimes including financial institution fraud, computer and telecommunications fraud, false identification documents, access device fraud, advance fee fraud, electronic funds transfers and money laundering, to name a few.

"I don't think people should panic but I do think people should realize that this is the new norm," Ken Westin said, Tripwire senior security analyst.

He warned, if those passwords were not encrypted, that criminals could open a Pandora's Box worth of problems.

"The risk there is if people are using the same password on their Park 'N Fly account as they are with their email and social media accounts, there's a good risk that those accounts could be compromised as well," Westin said.

He continued, "There's a lot of money to be made in underground markets for stolen credit card data and personal information and that's what really driving these hackers to actually go out and actively attack websites."

KATU's On Your Side Investigators contacted Park 'N Fly for comment - both about the scope and timeline of the investigation as well as federal involvement - and received the following email statement from Park 'N Fly Senior Marketing Director Mary Gallen:

"I wanted to follow up and let you know that we are not conducting any interviews at this time. We continue to conduct an extensive investigation, with the help of outside data forensics experts, to determine specifics of the incident, including scope and timing. However, because we were able to confirm a data compromise, we put out a public announcement to make our customers aware. We plan to share additional information with our customers and the media, when our investigation is complete. Our press release provides all the information we can currently make available."

In Portland, Park 'N Fly contracts out with two parking lots: Airpark Airport Parking on N.E. 82nd Ave. and Thrifty Parking on N.E. Holman Street.

Despite the strikingly similar name, Park 'N Fly is not related to another shuttle company near the airport, Park Shuttle and Fly on N.E. 82nd Ave.

Airport shuttle cuts ties with Park 'N Fly after security breach

This breach created some confusion and concerns for shuttle company Airpark.

Airpark General Manager, Randall Connelly, said his company uses the Park 'N Fly reservation network to bring in more customers.

Since Park 'N Fly does not have its own designated parking lot near Portland International Airport, he said the company refers customers to his lot. Connelly said Park 'N Fly customers account for about one percent of his business.

"My first thought, I was a little disconcerted that I did not receive a telephone call from Park 'N Fly letting us know that they had this security breach since and now we've been pulled into this situation," Connelly said.

Once Park 'N Fly customers arrive, Connelly said they hand over the voucher to show they've already paid online. He wanted to clarify that the 99 percent of his other customers pay at his parking lot and, he insisted, Airpark's data systems had not been compromised.

After hearing about the breach, Connelly said he dropped his contract with the pre-pay e-commerce company.

"We have taken a very proactive approach today ... and we are not taking any more reservations from Park N Fly," Connelly said.

Connelly said Aipark stopped service with Park 'N Fly at an Airpark in Oakland, CA too.

INFORMATION ABOUT SECURITY BREACH FROM PARK 'N FLY WEBSITE:

Park 'N Fly AllClear Data Security Event

1. WHAT HAPPENED?

Park 'N Fly discovered suspicious activity related to our e-commerce website. An investigation into this incident was immediately initiated. Our team, including third-party forensics experts, has been working continuously to establish the scope of the incident. While we complete our investigation and remediation of our systems, we are using our reservation call center to accept reservations. Our reservation call center is available 24-hours-a-day/7-days-a-week at 1-800-325-4863. Although our investigation is ongoing, we have determined that the security of our e-commerce website has been compromised, and we have reason to believe the intruder may have stolen some data from certain payment cards that were used to make reservations through our e-commerce website. The card data potentially affected by this incident includes the card number, the card holder's name, the card's expiration date, the billing address, and CVV code. Other information potentially affected by this incident includes email addresses, telephone numbers, and Park 'N Fly passwords.

2. WHAT IS PARK 'N FLY DOING IN RESPONSE TO THIS INCIDENT?

We have initiated a comprehensive response to investigate thoroughly and respond to the incident, review and improve our data security, and support our customers. The data compromise has been contained. We also are working with law enforcement and credit card brands. As our investigation continues and out of an abundance of caution for our customers, Park 'N Fly has engaged AllClear ID to offer identity monitoring and identity protection services to potentially affected customers, free of charge for the next 12 months.

3. THE PARK 'N FLY WEBSITE IS DOWN, HOW CAN I MAKE RESERVATIONS NOW?

Call our reservation desk at 1-800-325-4863 and an agent will be happy to help you book a reservation. Our reservation call center is available to serve you 24-hours-a-day/7-days-a-week.

4. WHEN WILL THE RESERVATIONS SITE GO BACK UP?

Security enhancements are underway and we hope to have our ecommerce website back on-line in the coming weeks, but will not do so until we are confident that all issues are rectified. In the meantime, please call our reservation desk at 1-800-325-4863 and an agent will be happy to help you book a reservation.

5. I USED THE PARK 'N FLY SITE EARLIER THIS YEAR TO BOOK A RESERVATION, AM I AFFECTED? SHOULD I BE CONCERNED?

Park 'N Fly's investigation into this incident is ongoing. Our team, including third-party forensics experts, has been working continuously to establish the nature and scope of the incident. Security updates relating to our investigation will be available on this website.

6. WHAT DO I DO IF I SEE SUSPICIOUS ACTIVITY IN MY BANK ACCOUNT/CREDIT FILE?

If you detect suspicious activity in your bank account or credit file, you should contact your bank to report any suspicious activity, change online passwords and check your credit reports. Instances of suspected fraud should also be reported to local law enforcement.

7. I HAVE USED MY CREDIT CARD ON PARK 'N FLY'S E-COMMERCE WEBSITE AND THINK I MAY BE THE VICTIM OF FRAUD. WHAT SHOULD I DO?

If you believe you have been the victim of fraud, Park 'N Fly encourages you to contact law enforcement and your card company or the financial institution which issued the card. We also encourage you to take advantage of the identity monitoring and identity protection services that we are making available through AllClear ID to any potentially affected customer, free of charge for the next 12 months.

8. I HAVE A FREQUENT PARKING REWARDS ACCOUNT. DO I NEED TO CHANGE MY PASSWORD OR TAKE ANY ACTION?

If you have an frequent parker online profile with Park N' Fly, as an extra precaution, we recommend that you change your password when full website access is restored.

9. WHAT STEPS CAN I TAKE TO PROTECT MYSELF FROM IDENTITY THEFT OR FRAUD?

Specific steps you can take to protect against the possibility of identity theft include closely monitoring your financial statements and explanation of benefits forms for any unusual activity, changing your online passwords and monitoring your credit report. Under U.S. law, you are entitled to one free credit report annually from each of the three major credit bureaus. To order your free credit report, visit www.annualcreditreport.com or call toll-free (877) 322-8228. You can obtain a free credit report from any one or more of the three national consumer reporting agencies (listed below). At no charge, you can also have these credit bureaus place a "fraud alert" on your file that alerts creditors to take additional steps to verify your identity prior to granting credit in your name. This service can make it more difficult for someone to get credit in your name. Please note, however, that because it tells creditors to follow certain procedures to protect you, it may also delay your ability to obtain credit while the agency verifies your identity. As soon as one credit bureau confirms your fraud alert, the others are notified to place fraud alerts on your file. Should you wish to place a fraud alert, or should you have any questions regarding your credit report, please contact any one of these agencies.

Equifax P.O. Box 105069 Atlanta, GA 30348 800-525-6285 www.equifax.com {<}http://www.equifax.com{>} Experian P.O. Box 2002 Allen, TX 75013 888-397-3742 www.experian.com {<}http://www.experian.com{>} TransUnion P.O. Box 2000 Chester, PA 19022-2000 800-680-7289 www.transunion.com {<}http://www.transunion.com{>}

The Federal Trade Commission has also compiled helpful information on steps you can take to avoid or detect identity theft. Visit their website at www.ftc.gov/idtheft {<}http://www.ftc.gov/idtheft{>} or call their hotline at 1-877-ID-THEFT (438-4338). Your state Attorney General may also have useful information on how to protect against identity theft or fraud.

10. WHERE SHOULD I GO FOR UPDATES?

Our investigation into this incident is ongoing. Security updates relating to our investigation will be available on this website. When we have more details available, we plan to send a notice with additional information directly to all customers for whom we have current mailing address information. That same information will be posted on our website and available through this call center.

11. WHEN DID THIS HAPPEN?

Park 'N Fly's investigation into this incident is ongoing. . Our team, including third-party forensics experts, has been working continuously to establish the nature and scope of the incident and associated timelines. Security updates relating to our investigation will be available on this website.

12. WHY WAS THIS INCIDENT NOT DETECTED EARLIER?/WHAT TOOK SO LONG TO DISCOVER THE INCIDENT?

Park 'N Fly takes the security of our customer's personal information very seriously. Despite any company's best efforts, intrusions such as these can occur and can take time to discover. Once we were alerted to a potential security compromise, an investigation into this incident was immediately initiated. Our team, including third-party forensics experts, has been working continuously to establish the nature and scope of the incident. This investigation is ongoing. The security compromise has been contained.

13. WHAT IS PARK 'N FLY DOING TO PREVENT THIS FROM HAPPENING AGAIN?

Park 'N Fly takes the security of personal information very seriously. Upon discovering that our systems were potentially affected, we immediately launched an investigation to determine the nature and scope of this incident. We engaged independent third-party forensic experts to assist with our investigation of, and response to, this incident. We have been working with these security experts to identify and resolve possible issues, and to enhance our IT security. In addition, we are working with law enforcement and payment card brands. Our investigation is ongoing. While our investigation is ongoing, we have suspended our online reservations systems, pending remediation.

14. WHAT PROTECTION IS PARK 'N FLY OFFERING AFFECTED CUSTOMERS?

Park 'N Fly is taking steps to protect you and your information. You are automatically protected with AllClear Secure for the next 12 months - there is no action required on your part to receive this service. If a problem arises, simply call (855) 683-1165 and a dedicated investigator will assist you in restoring your identity to its accurate state. For additional protection, you may also enroll, free of charge, in AllClear PLUS at any time during your coverage period. AllClear PLUS includes identity theft monitoring and a $1 million identity theft insurance policy. To use the PLUS service, you will need to provide your personal information to AllClear ID. You can visit pnf.allclearid.com to gain access to your redemption code. A link to enrollment information is also available on the Park 'N Fly website. Please note that additional steps may be required by you in order to activate your phone alerts.

15. I AM A FREQUENT PARKER MEMBER AND WOULD LIKE TO KNOW WHEN I WILL RECEIVE MY FREE DAYS FROM LAST YEAR/ WHAT DOES THE 2015 FREQUENT MEMBER PROGRAM INCLUDE?

Park 'N Fly is about to wrap up our 2014 Frequent Parker Program and transition to our new 2015 program. This includes:

If you have earned Free Days based on your parking in 2014, these days will actually be in your Frequent Parker Program account by the end of January. Good News! They will be deposited in your Frequent Parker Program account, rather than mailed to you and you can redeem them for reservations online OR print them to use for drive-up parking.
If your tier has changed, you will receive a new Membership Card.
Park 'N Fly's new, improved program from 2015 will be launched in the next few weeks (although you are already earning credit for 2015 parking). Park 'N Fly thinks you'll be very happy when you see the improvements which include the additional benefits of last year's programs AND the ease of use and value from our old program, which many of you had asked for.
Park 'N Fly's 2015 program includes:
Park 7 Times and earn a free day;
Preferred Parking & Discounts for Gold & Platinum members continues;
Earned Days are posted to your account and can be redeemed online for reservations or printed for drive up use.

We planned to have your days posted and the 2015 program in place by now; however, due to a data security compromise relating to Park 'N Fly's online reservation system containing payment card data we have temporarily suspended our online booking system and the ability to edit your profile until we are confident that all issues are rectified and that you can book with complete confidence. In the meantime, please call our reservation desk 24/7 at 1-800-325-4863 and an agent will be happy to help you book a reservation directly. Any customer who believes unauthorized charges may have been made to their payment card should contact their respective financial institution.

Trending