News

Music Web Site: Breach Exposed Accounts

Credit card data on Bananas.com music and gear Web site compromised, with several victims coming forward.

(San Francisco) A musical instrument and sound gear Web site that advertises its relationship with artists such as Dave Matthews, Carlos Santana and Mary J. Blige notified some customers that their credit card information may have been stolen.

The warning, which came more than a month after someone broke into Bananas.com, was delivered Wednesday after The Associated Press inquired about the breach. The San Rafael-based company said none of its celebrity clients was among the 274 people notified.

Web site operators still are trying to determine how the intruder gained access. Following the discovery, administrators changed passwords and added other safeguards to restrict unauthorized access to the system, Bananas.com owner J.D. Sharp said.

The breach was discovered after an individual identified only by the screen name SmookeR advertised in an Internet chat room the sale of compromised credit card information. In late February, SmookeR released the names, addresses, phone numbers and credit card numbers of at least 31 people who had recently placed orders at the company.

"I'm a little stunned I'm the victim of something you read about a lot but don't expect to have happen to me," said Patrick Klein, 42, a musician living in Queens, N.Y. He said he received a call from the bank that issued his credit card asking if he authorized charges that originated in France.

Dan Clements, chief executive of CardCops, a company that helps shield consumers from identity theft, said he e-mailed evidence of the intrusion to an employee at Bananas.com on March 1 but never got a response.

The employee was on vacation and never got the messages, Sharp said.

Featured

  • Microsoft Dismantles RedVDS Cybercrime Marketplace Linked to $40M in Phishing Fraud

    In a coordinated action spanning the United States and the United Kingdom, Microsoft’s Digital Crimes Unit (DCU) and international law enforcement collaborators have taken down RedVDS, a subscription based cybercrime platform tied to an estimated $40 million in fraud losses in the U.S. since March 2025.

  • Sound Wave Illustration

    CrowdStrike's Acquisition of SGNL Aims to Strengthen Identity Security

    CrowdStrike signs definitive agreement to purchase SGNL, an identity security specialist, in a deal valued at about $740 million.

  • Microsoft Acquires Osmos, Automating Data Engineering inside Fabric

    In a strategic move to reduce time-consuming manual data preparation, Microsoft has acquired Seattle-based startup Osmos, specializing in agentic AI for data engineering.

  • Linux Foundation Unites Major Tech Firms to Launch Agentic AI Foundation

    The Linux Foundation today announced the creation of a new collaborative initiative — the Agentic AI Foundation (AAIF) — bringing together major AI and cloud players such as Microsoft, OpenAI, Anthropic and other major tech companies.