Pharmacy giant Walgreens had to swallow some bitter medicine on Friday when it told customers that a computer criminal had stolen its e-mail marketing list. The criminal used the list to send out realistic-looking spam that asked recipients to enter their personal information into a Web page controlled by hackers.
"We are sorry this has taken place and for any inconvenience to you," the e-mail said.
No prescription information or other health information was stolen, the company said — the criminal only managed to pilfer customer e-mail addresses.
But even customers who had opted out of receiving marketing materials via e-mail from Walgreens had their addresses stolen in the heist. That means the firm stores customers' e-mail addresses even after they ask not to participate in e-mail marketing.
"We realize you previously unsubscribed from promotional emails from Walgreens, and that will continue," the e-mail to customers said.
Walgreens spokesman Michael Polzin said criminals so far have not attempted to imitate Walgreens corporate logo in the phishing e-mail they sent to consumers.
"The e-mails said they were from another company and asked (users) to update some information," he said. Walgreens would never ask consumers to e-mail personal information like credit card numbers or Social Security numbers, he said.
The company "became aware" of the heist within the past week, he said. He refused to disclose the number of customers impacted by it.
"We are in the process of contacting those customers," he said. "We are not going to get into specifics."
Walgreens, which has $60 billion in annual sales, is expanding at an astonishing pace. In November, it added 50 stores to its ranks of 8,000 retail outlets across the country.



I wish I had nothing better to do with my time than figure out how to screw people out of their money and wreck their computers. But alas I actually have to work for a living...
It's time for American consumers to demand the same privacy rights that Canadians and Europeans enjoy. No company can store your private information, sell it, or use it to advertise to you without your explicit permission.
Here, it's all about maximizing corporate profits and minimizing consumer rights.
It's time for everyone of us sucked into the Ticky Tacky Techy Toys of today to say NO. Privacy is a personal responsibility and sitting in front of our computers whining about any company "storing" information about us should figure out how data mining works.
We supply the miners by turning the Internet into what was called Diaries in archaic times... you know, the times when we used handwriting and didn't share our outpourings with anyone.
Tough, huh.
The obvious motto for any of us should be: "I don't Twitter, Tweet, Slog the Blog, or Face the Book. I don't get sucked into iPhones, WiiTones, UTubes, or MeTubes."
The insanity of cell phones, especially given to each of our kids, and with each kid owning a laptop during the impressionable and irresponsible ages is turning the era in which we live into the Age of Robots. Chicanery rules.
Think we will survive it? It’s our choice ... and so I have my doubts.
So you say, Mr. Hindsight, as you use a diary tool to post your rant! Don't play it off by saying you have an untraceable email account or some such nonsense - you are at the amusement park, eating the popcorn, eating the cotton candy, riding the rides, and you have the gall to point at everyone else and scream "This amusement park is an eyesore!"
Set an example for us and delete all your User IDs, toss your laptop and cell phone, take yourself back 200 years and communicate by traveling and posted mail, no electronics!
Let's see... Walgreen's security was so lax, they got hacked.
Then they admit they stored email addresses, even after being asked to delete them.
And what do they say to their custmers.... "Sorry for the inconvenience."
Is this a joke - or what?
To apologize, they're going to send a coupon for a free 64-ounce bottle of alcoholic Red Bull, while supplies last.
Seems to me this is a good reason for not doing business with Walgreens.
It's like the USA's Homeland Security. So lax the information gets stolen and leaked. Only difference is the government doesn't ever apologize.
@Jacques - It is rare to delete customer emails that are opted-out. The general practice in an email opt-out policy is to record the person's email, with an indicator that they have opted out. Also it is normal to track the date of the opt-out as well as the person's IP address. It is practical for auding purposes. Just like any retention model of information.
The author should not imply that Walgreen's has done anything wrong in regards to email opt-out policies as there are viable compliance reasons to maintain such data. In regards to network security - Walgreens, WTF! Who leaves their databases accessible to the outside world.
Every company store every customer's information, e-mail or otherwise. How many bills do you pay online where they remember your cc # or checking account? Everything can be stolen, it's just the matter of how the theives do it, hacking online or stealing the check from a mailbox, it makes no difference. Everyone pushes for the next advance in technology to make their lives easier. But while it makes you life easier, it makes you life easier to steal.
having managed a company's privacy policies, opt-out info, and do-not-call lists, i really should clarify the misconception that the article gave about storing email addresses. opting out of emails does not mean that the company has to delete your email, quite the opposite, in fact. a company needs to keep a record of your info to prove they have you marked for nonsolicitation. otherwise, if somebody claims to be receiving emails from you and you don't have their info at all, what would you do?
but how do they know this was an outside job? perhaps it was an employee's last revenge before being let go?
They say they were hacked - probably an inside job and/or disgruntled employee. Oppression is alive and well in America.
Actually it is perfectly acceptable to maintain email that was previously provided. The consumer did not ask to have them deleted, they asked not to be marketed using them. There is a difference. A very real world example may be a credit card or online store you use where they have an email as part of the account. You use it to log in, they use it to submit order confirmations, etc. but they mark a place ensuring you don't receive extra marketing from it. It's simple.
Oppression by Walgreens?
HAHAH, who ever shop at walgreen should get hacked, hahahahah.
Cheapy!!!
What can you do with email anyways, just thrown them in the junk boxes.
get real people, be vigilant, if you dont know what youre doing on a computer maybe you should not have one. PERIOD!!
@Sloppyjoes - you are an idiot. What happened? Did you get screwed over by Walgreens?
Looks like you don't need a computer either since you apparently do not know how to spell!!!
Walgreens is an ok store.
I go there all the time. Much better than the trailer trash Walmart that you probably go to.
@ Karen: I agree with you. Walgreens is a convenient place to shop occasionally. Walmart, on the other hand, is a big, bloated example of the worst in corporate greed. It goes hand-in-hand with the philosophy of Teabaggers.
lol, you're showing your ignorance. Best just keep your trap shut unless you don't mind being seen as a fool.
Walgreens is no better than any other money-grubbing corporation.
After working for them for 9 years, my wife was fired for getting hurt on the job doing work beyond her physical capacity. I'm sure the settlement for the lawsuit won't be extremely large, either. But only the most beggardly, miserable companies treat their rank-and-file so poorly. Bankruptcy is too good a fate for these slave drivers.
Whoa whoa whoa. In the article is stated that Walgreens opened 50 more stores nationwide. I can honestly say I have seen countless more Walmarts than Walgreens. I'm not saying that Walgreens is a bad store - my town FINALLY got one, but Walmart has been here since I can remember (yeah, I'm young..17).
But seriously people where is your sense of respect? Just because people go to Walmart doesn't mean they are trailer trash or "Teabaggers." I guess if I go to Walmart I am trailer trash? Really? Is that why my family is an honest middle-class working family? Is that why my aunt served my country as a military doctor and my grandpa works until his knuckles bleed nearly every day on his farm to feed this nation? Yep. That's some quality trailer trash.
Jaime13 makes a great point and I hope he learned something as well. There are many whiners out there ready to blame anyone but the person they see in the mirror for their lifes woes. They believe any success, be it a middle class life, a farm life, or a big corporation is based soley on greed and is undeserved for those who worked hard to achieve. It's a lesson I hope Jaime remembers always. Obviously, at 17 you see things better than many "adults".
SloppyJoes: I think you're thinking of Wal-Mart....Walgreen's is a pretty good drug store and beats CVS and Rite Aid by a MILE!!!
What Jaime13 fails to mention is what s/he has done for this country themselves. Just because your family has history with the country doesnt mean you're clear and free from being trailer trash. You can be trailer trash, even if you have a huge family history behind you. It's how you act and what you do with your life that makes you who you are, not your family.
If you shop at any of these big international corps you are putting nails in the coffin of your own economy and standard of living. Dont think so? Just go to some other nations where Walmart is about the only big business, and everyone is working like slaves for slave wages.. Yeah they really worked hard for all that wealth.. NOT. Their success has been on the backs of their poorly-paid, mostly part-time, no-benefit employees, and using child labor in 3rd world country's to make their crap products. Combined with using their wealth to kill off competition. They are the epitome of a monopoly..
I wouldn't shop at either of these atrocities, if my life depended on it.
Comment to HankE 3.2 If it wasn't for the "teabagger" watching over you children, America would really be screwed. I suppose you want the Dream Act to go through? I bet you have never contacted a Senator or House of Rep.I personally called 11 Senators today and ask to please vote against the Dream Act. What have you done?
Back to topic. Anytime you subscribe to anything on line, there is a chance it can be hacked, even with firewalls.
Petunia, I do not want you or anyone else watching over my children, anymore than you want me watching yours. Mind your own business.
BTW I fully support the dream act. Im not a bigot, and I don't have anything against legal immigrants coming in. If your problem is that this will benefit some that are here illegally, the blame lies in the broken immigration system. Besides, the dream act will effect immigrants far beyond the present situation regarding immigration.
When your family immigrated here, there were just as many bigots trying to road block back then as there are today. I guess you're glad they didn't succeed back then huh... Hypocrites...
Me thinks ya'll whine too much.
I'm pretty grateful for Walgreens and Walmart.
Anybody who really wants your information is going to get it from somewhere whether it's your bank or Walgreens.
@jaimie, just because your family is all-American and shops there, doesn't mean Walmart and Walgreens are honest companies. They are greedy scum. I'm so sorry you have to shop there.
those of you who protested against me have Noooooooooooo idea.
Ive worked on many computers and people are stupid enough to open email from strangers they dont know, if you didnt subscribe to that particular store, then why are you opening the email, see?? Stupidity at work here when you open an email from a stranger, you get maleware and viruses. So who is the stupid ones, just throw it in the Junk box.
You people sure dont like using your heads, you just want an easy solution for everything, this isnt a split second thinking process either.
wallgreen and walmart are the worst stores to shop in, if you look at the product they go stale very fast or the cheapest on the market.
yeah its a convience to have around yeah yeah, but still for cheapies, which is okay, you get what you pay for.
Karen the spelling police who cares, i just didnt want to hit the spell check, obviously youre so narrow minded you cannot figure out what i typed, you have to be a school teacher correcting every little mistake you see, when the mistake is you.
"That means the firm stores customers' e-mail addresses even after they ask not to participate in e-mail marketing."
It's not at all unusual for a company to save email addresses from people who have unsubscribed. How else would they keep track of the people who don't want their emails?
They could "track" them by NOT having them in their database!! If they're gone completely then no one can steal them.
John,
Just because a customer opts out of receiving advertisements, doesn't mean they don't use it for other notifications such as your prescription is ready or if you use there online ordering or downloading store coupons.
Anything that is on the web that seems to be protected is game for hackers. No one can claim that they have secured list/files, no one. Now that we are progressively moving more and more from computer programs/applications from the desktop to the internet (e.g., "cloud") control is being lost. Unfortunately we have to live with it and it will get worse and worse.
I was unaware the usual clientele of Walgreens knows how to use the email.
Excuse me, I get my prescriptions filled at Walgreens because A) They take my insurance and B) There is a Walgreens about 5 minutes from my home which is convenient for me because of being disabled. That does not mean I deserved to have my e-mail address stolen by some hacker. Instead of being a pompous ass, you might take the time to consider that other drug stores do not always accept all insurance and there is also the issue of convenience for many people including the disabled and the elderly. That also goes for your equally pompous and moronic friend Sloppyjoes as well.
Camoron Ford
You really don't deserve a reply as your parents named you well CaMORON.
There are more Walgreens in my city than Walmarts. They are convenient and reasonably priced. You can also shop online for products they don't carry in their stores.
You are probably unaware of many things, Cameron, but apparently you feel qualified to make obnoxious comments which you probably think are very clever on subjects of which you clearly have no knowledge. I shop at Walgreens occasionally and have been using e-mail for nearly 20 years.
Yes, we do Cameron.
Idiots.. This is my point. NEVER GIVE ANY INFORMATION OUT.
But didn't YOU have to give MSNBC your email address in order to register here? Same thing. We're trusting MSNBC not to release or lose our email addresses.
Thank you.
IT'S NOT ME. JD
I FULLY EXPECT THEM TO LOSE IT AND HAVE MADE PROVISIONS AHEAD OF TIME TO PREVENT DAMAGE.
THINKING AHEAD.......................
Good Luck Bud.
Your bank hands out your information on a regular basis unless a disgruntled employee gets to it first.
I fully agree, Im.
Tea is NOT my real name!
I can see where this is all going...
Seems like "digital terrorism" is the new enemy.
Enjoy the internet while it lasts, folks.
Great, one more thing to worry about...I rely on their emails to know my RX's are ready so I don't have to call....you would think a pharmacy that holds such private costumer information would have a better security system!! ;(
Health information is held in a separate, restricted access database from email addresses and other contact information. But that isn't to say that it is invulnerable.
State of Virginia had their pharmacy systems held hostage by a disgruntled consultant about two years ago.
Frankly, I have to wonder if the FBI officers who captured him, beat his #$ for stealing their prescription information.
Another company that forgot to budget for computer security.
how do you know that? this isn't like not having an antivirus program on your PC, anybody, even the most secure systems in the world, can be subject to hacking, and since hackers by nature are pushing the limits of technology, it can't always be prevented.
Ok, this is getting old. Time to make it a huge penalty for these cyber crimes. Make it a felony if it isn't already.
One to Twenty under Title 18 for Computer Fraud.
booyah!
Even the most "secure" computer or server can be hacked into if a hacker tries hard enough. That is how they've gotten into government and banking files.
It's too bad that this powerful tool we all enjoy can be misused in so many ways by criminals. I'd like to see some high profile prosecutions. which can be difficult when the perps are so often overseas, plus better security on the part of everyone who has our data. I'm sure the people doing it think they're clever and above the level of street muggers, but word might get around if a few went to prison for a good long time.
The computer and the resulting internet there upon has been abused from day 1 when it went to personal use computers. One of the greatest inventions of mankind to enhance our intelligence and bring people together worldwide has been utilized to replace our intelligence and be used as the medium for people to be devisive and hateful in ways they would never dare to in person, eye to eye. It has bestowed upon societies around the world not only a vast wealth of knowledge but insidious reams of propaganda and memetic abuses. It has also lent itself to some of the worst crimes and given them international reaches ... in theft, prostitution, child abuse, drugs, etc.
People used to be able to go to the store and know exactly how much change was due them ... they need a caculator now.
People used to meet friends "eye to eye" and develop their social skills through the friendships they cultivated ... now some stranger they will never meet is their "best friend" because they message each other online daily.
People honed their mathematical skills balancing their check books each month, now too many need a computer program to do so or feel helplessly lost. Computers are superb when processing hundreds or thousands of checks per month or a payroll for workers in a company ... a total waste when balancing 5 to 12 checks per month or managing 5 or 6 bills that need paying each month.
The internet and computer uses today attempt to replace rather than enhance our intelligence and social abilities ... it is being utilized the same as using a sledge hammer to kill a fly on your living room window.
Instead of serving its purpose of enhancing mankind, it is adding to the "dumbing down" of society world wide
Give the government unlimited rights to go after hackers. When found, fine them to the point they don't have a dime left.
Recycled Hope,
One of the truest comments I've ever seen written about computers and the Internet.
Outstanding post.
thank you Idaho Dragon
You just have to accept that there will always be thieves in the system whether they are Ukrainian hackers or disgruntled employees with an axe to grind.
Keep harassing the Legislatures (both State and National) for better laws and protections.
It did not say that customers asked for their emails to be deleted. Customers asked to be unsubscribed from marketing lists. It is normal for marketers to retain email addresses to filter out communications to those who have requested not to receive them. for example, I tell Walgreens not to email me but I buy from their site again, my email address is on a "do not email" list internally so they can scrub my name off their list before broadcasting. If they deleted my email address, I might get emailed again even though I asked them not to.
Well i hope they put a lot of effort to catch these folks like they do for Wikileaks..haha
Next will be McDonalds, Burger King and Taco Bell. Wow, there's no end to this fun.
The only way to keep something private is keep it in your mind. Tell no one and do not write it down anywhere. Otherwise, someone could hack your computer or smart phone or break in and take the notebook or daytimer you have it stored in. That is why I never write my secret PIN down or have my SSN on my driver's license any more. The less people know about me, the better off I am.
i don't pay much aout the spams or wal-greens.Besides they don't carry out money orders.
I wonder if they're like Dollar General?
These hackers need to be stopped and that entails some new tough penalties. 25 years 1st offense, 50 years second. Or better yet just take then out and blow their effing heads off!
Money grubbing corporations. This is the biggest load of BS I've ever heard. A corporation is a business. What is a business there to do? Make money. As for Walgreens itself, they have a very long standing of providing excellent customer service. Like any other large company, they have had a few mistakes. But saying that they need better security is just plain silly. All computer systems are designed to be accessed by someone. Wherever there's an access point, there is a vulnerability. User names and passwords can be hacked. Most software engineers also have a "back door" they use during development. Most end users never remove it. Some don't know it's there and most do not have the know-how to do it anyway.
so, tell everyone how to remove that "back door". i await that info with bated breath!
@ blunt talker-Well as an IT professional just to let you know a little about back doors, they are only accessible after breaking lines and lines of code and one would have to be very experianced in networking a router to break through security firewalls that are in place. Some of the end user engineers dont even know that they are there ........Don't be scared to be a little more optimistic
I agree with you Cubfan. For everyone else that's bad mouthing Walgreen's, please tell me which drug stores you shop at, and how would you fix this problem? A lot of Monday morning quarterbacks out there, but not a shred of how things should be fixed. Just remember Abe Lincolns quote, "It's better to remain silent and be thought a fool, then open your mouth and remove all doubt." (Paraphrasing)
Patch your computer blunt.
$%iT #u&@!
Now everyone's gonna know about my type 2 adult onset Tourette Syndrome brought on by my 8 year olds clear indications of Alzheimers Disease!
oh get over it people, get a life! Its going to happen to the best, deal with it!
If they did this to e-mail lists,how do those of us who have our prescriptions in Walgreen's computers know that that info is safe, along with insurance & other personal info???
I believe that if the hacker that did this was NOT good enough to get that info, or he/she would have. Therefore it would not be any kind of issue for people that shop at Walgreens to be worried about. Just while your online simply DO NOT GIVE YOUR PERSONAL INFORMATION OUT OVER THE INTERNET. You will be better off.
And my kids think I'm old school for paying cash for what I can whenever I can. Anybody can get any and all info they want if they know enough about computers. I do buy on the internet sometimes, but I never sign up for e-mail notifications.