Security Problems


Website Feedback


I've been unable to contact Customer Service via email about this problem or they are unwilling to respond or act. I think anyone who uses this site should be very concerned.

Two weeks ago I discovered that I could access account information about a person with the same name as myself. I could see what he had ordered and whats worse is I could place an order using his credit card information. It is likely that he could do the same to me.

I wrote customer service immediately and have received no reply even after writing them again. I can't believe Paizo is so lax about credit card security and personal information.


Obviously, we take any potential security problem extremely seriously and are looking into this matter with great urgency.

Preliminary investigation suggests that the problem is not system-wide, but rather peculiar to Timothy's account, where two accounts may have been erroneously merged due to human error.

To clarify for everyone's benefit, sharing a name with someone has no bearing on your ability to access their information. Data is tied to the user account. Each user account has an email address, which must be unique, and a password. No one without both of those things can access an account on paizo.com.


Timothy Williams wrote:
I've been unable to contact Customer Service via email about this problem or they are unwilling to respond or act.

With very rare exceptions, email received at customer.service@paizo.com is responded to within 2 business days, usually one day.

We have checked the account and found no email matching your information.

This could indicate a problem on either the sending or receiving end. We'll continue to look into whether customer.service is receiving all the mail properly sent to it.


Robert Head wrote:
Timothy Williams wrote:
I've been unable to contact Customer Service via email about this problem or they are unwilling to respond or act.

With very rare exceptions, email received at customer.service@paizo.com is responded to within 2 business days, usually one day.

We have checked the account and found no email matching your information.

This could indicate a problem on either the sending or receiving end. We'll continue to look into whether customer.service is receiving all the mail properly sent to it.

Unfortunately my email provider changed hands and the outgoing mail will no longer look like it came from the account in question but I did include the account email in the text. I will change it but didn't want to until this is cleared up. I did get the email you sent just fine.

The messages were sent on 11/16/2004 at 11:16 AM MST and again on 11/19/2004 at 9:31 AM MST.

My mail always seems to get through to other sites without a problem. I've seen other posters complain about no response from customer.service. It would seem that you have a flaky server or an overzealous spam filter (human or computer) somewhere in your pipe.

As much as I hate getting computer generated responses at least that way you know that the message made it through.

Community / Forums / Paizo / Website Feedback / Security Problems All Messageboards

Want to post a reply? Sign in.
Recent threads in Website Feedback