---
title: 'Bulletproof' Website? Apparently Not
description: A company called Bulletproof discovered malicious code that potentially exposed customer credit information for months.
---

[SecureWorld News ](https://www.secureworld.io/industry-news)

# ['Bulletproof' Website? Apparently Not](https://www.secureworld.io/industry-news/bulletproof-breach-notice)

 Written by [SecureWorld News Team](https://www.secureworld.io/industry-news/author/secureworld-news-team) | Wed | Sep 20, 2017 | 6:30 PM Z

A company with a self-proclaimed "Biohacker" for a founder and CEO has, itself, been hacked.

[Bulletproof](https://blog.bulletproof.com/bulletproof-for-beginners/) has an e-commerce website that may not have lived up to its name.

The hack started last year and allowed access to customer financial information during check-out from the site, which sells supplements and food. 

The company says it determined that someone inserted code into the software that operates the checkout page.

Anna Collins, Chief Operating Officer, says this in [Bulletproof's breach notification letter](https://justice.oregon.gov/consumer/DataBreach/Home/GetBreach/905485622) to customers: "Bulletproof determined that the unauthorized code may have been capable of capturing information entered during the checkout process. The information compromised by the incidents may have included your name, payment card number, expiration date, and CVV number from payment cards used for online transactions on Bulletproof’s e-commerce website from October 26, 2016 to May 30, 2017, and August 28, 2017 through September 5, 2017."

Do the math on this one, and we're talking more than seven months during which customers potentially had their payment information stolen.

The company says it is making changes: "To help prevent a similar incident from occurring in the future, Bulletproof has implemented enhanced security measures, including installing a new website security platform, implementing a security information and event management system (SIEM), and implementing enhanced logging."

Hopefully, whoever is responsible is not a part of the "more than 1 million biohackers who follow Bulletproof for leading-edge information on how to supercharge your body, upgrade your brain, and become Bulletproof."

Because the last thing InfoSec experts need is a bulletproof hacker.

[View full post](https://www.secureworld.io/industry-news/bulletproof-breach-notice)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SecureWorld News Team"
  },
  "dateModified" : "2017-09-27T01:28:23.287Z",
  "datePublished" : "2017-09-20T18:30:00Z",
  "headline" : "'Bulletproof' Website? Apparently Not",
  "image" : {
    "@type" : "ImageObject",
    "height" : 853,
    "url" : "https://cdn2.hubspot.net/hubfs/2221756/blog-image-uploads/hacking-2300793_1280.jpg",
    "width" : 1280
  },
  "mainEntityOfPage" : "https://www.secureworld.io/industry-news/bulletproof-breach-notice",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2221756/Logos/SWE/SWE_logo_full-long_forWHITEbackgrounds.jpg",
      "width" : 304.46954
    },
    "name" : "SecureWorld News"
  }
}
```