UPDATE: THEY FIXED IT - Pentair Data Mismanagement (probably many people here affected)

Goostav

Member
May 6, 2020
12
Los Angeles, CA
Hola,

TLDR; Like me, If you have submitted a rebate request to Pentair, your info might be (probably is) unencrypted and readily accessible online. What should we do?

Not really sure where to post this so I guessed that here is as good as any. I happened to come across a SUPER weak spot in how Pentair manages the data in their rebate program, for at least their pumps.

I'm not exactly sure what to do but I'd love to get my unencrypted name/address/telephone number and last 4 digits of my credit card offline asap. The info that is available goes back at least 1 year, probably more. Without any real technical know-how they've made it ridiculously easy to access the info of a boatload of people that have submitted rebate requests.

They have put literally ZERO security protocols in place. If a near computer-illiterate person like me stupidly stumbled upon this I'd hate to think what a capable, less scrupled person could do. One could, theoretically, write a super simple script, scrape their website, run it through an OCR and within minutes/hours have a working database for thousands of instances of personal info: name, address, phone numbers, home and billing address, potentially some cc info and gps data if taken with a phone that records that info to the file.

Edit by Jim R.

I have been hesitant to even post here because it's really, really easy to access the info and somebody with malicious intent would be happy to know about it. Or if somebody from Pentair read this and quickly/sloppily buried the problem without any real correction.

Have you gotten a Pentair rebate in the last year or so and care about weirdos or nefarious types getting your personal info? What do you guys think?

Thanks
 
Last edited by a moderator:
  • Sad
Reactions: MyAZPool
Have you tried to notify anyone at Pentair of the data exposure?


I have been pwned so many times that any privacy is long gone. Name, address, phone numbers, are on many public information web sites. My CC numbers are my banks fraud departments problem.

Yes, I agree it is dumb of Pentair to expose customer data. Based on what we have seen with their automation software Pentair is challenged with its internal IT abilities.


 
Last edited:
PM @MyAZPool He has contacts at Pentair and can get the data breach information to an executive.
 
PM @MyAZPool He has contacts at Pentair and can get the data breach information to an executive.
Allen,
Well, this is concerning. I'll shoot some of the excerpts of the information that Goostav has provided over to the the IntelliCenter Product Manager. I guess the best we can hope for there, is that I assume that he at least might know who to directly forward it.
My guess, is this is a customer service issue.
I suggest that anyone who might be concerned, maybe attempt to utilize the following contact.

Customer Service
8 AM to 8 PM — Eastern and Pacific Times
Phone: (800) 831-7133
Fax: (800) 284-4151

"Based on what we have seen with their automation software Pentair is challenged with its internal IT abilities". Yup, that's for sure. sheesh, why am I not surprised.. 😞

r.



 
Since you are from CA, I would kindly remind them of the California Consumer Privacy Act. That can make data breaches very costly in terms of fines and the payout to impacted consumers. Its much cheaper for them to pay for consultants/extra workers to actually fix the problem.
 
  • Like
Reactions: guinness
If they refuse to fix it post it on the bug web site give them 30 days first if you found it chances are it’s already known. I use to do it as a hobby “google dorks” I have seen pictures of credit cards front and back birth certificates drivers license telephone numbers all just with google. It’s pretty sad companies well keep everything unencrypted or worse a church that had scanned all documents and put it online all emails all the churches info including how much they were required to collect and send to the main church and a whole bunch of information on the people that went to the church including all their information. I always informed the people running site some would fix it other just left it. Now companies get sued for such stuff so.
 
ALCON,
Recommend that anyone who may be concerned with this issue, immediately send all pertinent information (do not send "sensitive info") to: [email protected]
I am advised that they are the responsible department for this issue..
r.

EDIT: Also send to: [email protected]
 
Last edited by a moderator:

Enjoying this content?

Support TFP with a donation.

Give Support
Quick update: Pentair fixed it!
I sent them an email last night explaining the issue and got an email at 2 pm today from somebody at Pentair thanking me for informing them and letting me know that they had corrected the problem. I signed onto my pentair account and tried to duplicate the problem to no avail. So they fixed it really quickly and to the best of my knowledge have patched up that leak.
Thanks for your advice!
 
Thread Status
Hello , This thread has been inactive for over 60 days. New postings here are unlikely to be seen or responded to by other members. For better visibility, consider Starting A New Thread.