Caravan and Motorhome Club's website down! (4 Viewers)

Affiliate links here may earn MHF compensation

GerTee

LIFE MEMBER
May 9, 2016
468
4,347
Near Fareham
Funster No
42,992
MH
Burstner iXeo
Exp
Since 2016 - UK & Europe
CAMC have changed their holding page which now says "We would also like to thank and recognise our partners and external teams of specialists who are working around the clock to help bring our systems back online."

Hacked or ransomware methinks.
 

Gellyneck

LIFE MEMBER
Jun 5, 2014
10,223
20,954
Scotland
Funster No
31,836
MH
C Class
Exp
More than toes wet now!
2nd hand but understand the Club has sent a text (from where?) to all members who are insured with them advising a dedicated phone number to make a claim. I thought this was managed by a 3rd party but are they impacted as well?:unsure:

What about those with breakdown cover? Are they stuffed, as well?:unsure:
 

Gellyneck

LIFE MEMBER
Jun 5, 2014
10,223
20,954
Scotland
Funster No
31,836
MH
C Class
Exp
More than toes wet now!
C&MC response from another website
+++++
Unfortunately we are experiencing technical issues which are affecting our systems and our IS team are working hard to get everything back up and running. Our technical teams are still investigating the source of the issue and we have been advised there is no evidence that member data was compromised. Please rest assured we are working hard to get everything back up and running as quickly as possible, so do keep an eye on the website for any further updates
+++++

Subscribers  do not see these advertisements

 

BillandHelen

LIFE MEMBER
Nov 17, 2013
959
2,910
Edinburgh United Kingdom
Funster No
29,056
MH
Wildax Elara
Exp
since 2004
2nd hand but understand the Club has sent a text (from where?) to all members who are insured with them advising a dedicated phone number to make a claim.
Just renewed my Motorhome insurance with them this afternoon, usual phone number and they had full system access, think it’s Devitt system not CAMC.
No text received re claims.
Also just booked into Melrose for a couple of nights later this week, phoned site direct, booked no problem.
Warden said it’s mayhem at HQ as they try and get the systems back up, as an ex bank COO they have my sympathies, though why their backup system didn’t work will be another question.
 
Feb 27, 2011
15,208
80,468
UK
Funster No
15,452
MH
Self Build
Exp
Since 2005
though why their backup system didn’t work will be another question.
Their backup system might be working. I just had to restore a clients site 3 or 4 days ago due to a hardware failure.
He had 104TB of data to restore. It took 10 hours for the data to be transferred from the backup system to the new system.
Then it took another 8 hours for the database data to be imported. All told he was down for a little over 36 hours.
The initial response was, what has gone wrong, took a while for onsite techs to realise the hardware was defunct.
They (the hosting company) then didn't have the necessary spares in stock.
So he was told he would either have to wait for new parts to arrive OR he could have a new server and some credit.
He took the new server.

He is now considering having redundant database servers up and running on separate hardware. I suspect at CAMC scale they already do this.
however, if their database got corrupted and this corruption was propagated to the redundant hardware then a full restore may have been necessary.
Just hope they had transaction logging/journalling turned on.

To be honest. CAMC contract may not have weekend covered for their IT staff for a major incident. So start from Monday, if this a major failure.
Then restoring a full big system like theirs may not be a simple 1 or 2 day process.

The above are just guesses based on my experience of running a disaster recovery service for my clients. Mine is extremely small scale and does not have all the latest bells and whistles and we do not host it on the same network or even the same provider.
CAMC should have 2 levels of backup. A local one for fast recovery. A full offsite, offline isolated backup hosted by a different company which would always take l long time to restore from but could survive anything short of a nuclear war.
 
Last edited:

Gellyneck

LIFE MEMBER
Jun 5, 2014
10,223
20,954
Scotland
Funster No
31,836
MH
C Class
Exp
More than toes wet now!
Just renewed my Motorhome insurance with them this afternoon, usual phone number and they had full system access, think it’s Devitt system not CAMC.
No text received re claims.
That's what was confusing me as I knew it was a 3rd party (we've previously been insured with them).
Also just booked into Melrose for a couple of nights later this week, phoned site direct, booked no problem.
Warden said it’s mayhem at HQ as they try and get the systems back up, as an ex bank COO they have my sympathies, though why their backup system didn’t work will be another question.
Yip Judith at Melrose has been tearing her hair out!

Subscribers  do not see these advertisements

 
Oct 7, 2013
6,128
38,479
South Wales
Funster No
28,463
MH
Swift Escape Compact
Exp
Since 1988
I have been trying to contact them by ’phone,e-Mail and via their website as £150 of vouchers for my daughter’s birthday have gone astray somewhere.

No way to contact them at present.
 
Feb 27, 2011
15,208
80,468
UK
Funster No
15,452
MH
Self Build
Exp
Since 2005
It’s a bit of a concern if there is any security breach as they now hold card details for automatic balance payments the day of arrival.
They won't hold card details. The PCI/DSS requirements have ramped up to stupid levels in recent years. Very few companies will even risk holding client card details unless they are suicidal and don't want business insurance.
I thought it was WorldPay that held it on their behalf, even so it's still worrying 🙄.
I don't know the company they use, but you are correct it will be someone like WorldPay that does it for them

BUT, This is not what is causing the issues. If it was a payment issue you would still be able to book just not pay.

The level of CAMC IT expertise is seriously lacking, demonstrated after the recent new website launch. I hoped it’s not been hacked, but wouldn’t be surprised. In which case if there’s been a data breach they need to make an official statement and report themselves to the relevant authorities ASAP.
They do not need IT expertise. They need campsite expertise. These days no company of their size or smaller should be doing their own IT. The security and stability requirements just too high for such a non core activity.
I suspect they have an "IT" contract and something has gone wrong and they are being pushed from pillar to post. I suspect the new site was developed and hosted under a single contract and they are unwilling at this stage to throw the contractor under the bus until they are sorted. But I suspect at contract renewal time the current company will not be in the running.
 
Sep 7, 2017
886
2,844
Funster No
50,394
I would say the user interface part of their IT is only average but can see its a matter of opinion. The back end seems fine.

Regardless, their communication is often poor. It would not be difficult to put an explanation on the holding page we currently see with either a warning customer data may be compromised, or reassurance that it is not. Equally they could get a message to this site and the Motorhome magazine sites with similar information. That would either allow people to stop worrying or change passwords elsewhere which they may have unwisely replicated. Let’s face it most people do this.

Finally some sort of holding message is in their own best interests, it would help to damp down some of the wilder speculation.
 
Last edited:
Oct 12, 2009
11,496
25,453
SW London, Poland and all Europe
Funster No
8,876
MH
A Class N+B Arto 69GL
Exp
Since 2009
I would say the user interface part of their IT is only average but can see its a matter of opinion. The back end seems fine.

Regardless, their communication is often poor. It would not be difficult to put an explanation on the holding page we currently see with either a warning customer data may be compromised, or reassurance that it is not. Equally they could get a message to this site and the Motorhome magazine sites with similar information. That would either allow people to stop worrying or change passwords elsewhere which they may have unwisely replicated. Let’s face it most people do this.

Finally some sort of holding message is in their own best interests, it would help to damp down some of the wilder speculation.

What? Treat the Members as Members of a mutual club? What next?

Subscribers  do not see these advertisements

 
Apr 24, 2023
420
752
Funster No
95,493
MH
Herald 400RL
Regardless, their communication is often poor. It would not be difficult to put an explanation on the holding page we currently see with either a warning customer data may be compromised, or reassurance that it is not. Equally they could get a message to this site and the Motorhome magazine sites with similar information.

Likely they do not know the impact yet and so can't say either way. If we had a ransomware incident it would be weeks until we were sure. We would need to comb logs of all the different systems and tools we have to see if we had suffered a simple cryptographic ransomware attack or if they had also exfiltrated data and this would cause bigger issues.
But yes, some indication of what's going on wouldn't go amiss.
 
Sep 10, 2020
347
855
Lancashire
Funster No
75,713
MH
Autograph 69-2
Exp
Moved over to the Dark Side after 16 yrs tugging.
I doubt whether the CMHC has even asked them selves the question, ^What do we do if were subject to a ransomware attack. Do we have a plan in place?^
I suspect that the answer is no in both cases.
 
Oct 9, 2019
5,087
17,928
Todmorden
Funster No
65,104
MH
Van conversion
Exp
FUNSTER in a PVC
I doubt whether the CMHC has even asked them selves the question, ^What do we do if were subject to a ransomware attack. Do we have a plan in place?^
I suspect that the answer is no in both cases.
Their accountants will have asked them but the CAMC are so arrogant and dismissive that their reply would likely be ‘We are fine we are invincible’ 😝😝😝😝😝😝
 

Jim

Ringleader
Jul 19, 2007
37,294
137,278
Sutton on Sea, UK
Funster No
1
MH
Adria Panel Van.
Exp
Since 1988
At last some communication from CAMC on X. Not many kind wishes in the responses though :D

1706088461895.png

Subscribers  do not see these advertisements

 
Feb 16, 2013
20,583
56,090
uttoxeter
Funster No
24,713
MH
ambulance conversion
Exp
50 years
Why don't you all just cancel your direct debit or whatever you use to pay them, and get out and find other places with less hassle and money.
Just ask yourselves what you need them for.
 
Oct 18, 2022
1,511
6,322
South West
Funster No
91,961
MH
Adria Twin
Exp
Since 1992
I’m not sure how many CAMC ‘Club Together’ forum members post here any more, but those that do will know it’s suffered with IT problems for (literally) years. As regular as clockwork members were complaining and reporting problems in the vain hope that somebody in CAMC might listen and fix it. Usually there was no response let alone solution. The current problems will all be part of the same arrogant and dismissive approach to members.
 
May 16, 2023
1,245
3,005
Funster No
95,993
MH
Bailey Alliance 66-2
Their backup system might be working. I just had to restore a clients site 3 or 4 days ago due to a hardware failure.
My part of the IT world for consulting is IT security -> and I can say having ran a few Incident Responses on a major hack investigation, this also could look exactly like the symptoms CAMC are suffering.

Priority one is to find out "How they got in", then "What they got access to", "fix the problem and any similar problems in the codebase", recover database from tape (happens in parallel to previous step) and finally recover access to customers.
If it was a SQL injection type attack (still as common as in 2001) stopping access to the website allows the entry point to be discovered. Reason I mention this Gromett is becuase a SQL injection type attack could also wipe all data -> sometimes attackers use a join in SQL that can delete data in extreme circumstances.

This then adds a recovery stage to stage 3 to enable the actual corrupt data (all columns become true, false, 1 or 0 typically in many cases these days) to be recovered from their offsite backups, which I agree with gromett takes an age on a several Tb system (mostly becuase index's have to be recomputed to enable the website to perform).

But this pretty much matches the timeline and IR plan on one I was involved with by a (namelesss) UK based insurer client 10 ish years ago. SQL injection is still very very common and attackers methods to leverage them are entire books of content these days, as you usually also have to bypass a web-application firewall or similar out of app defence now.
 
Jan 11, 2010
2,828
10,053
Chester
Funster No
9,901
MH
Auto-trail
Exp
Well that`s our 14th year & still loving it.
The clubs facebook page is has lots of comments re the situation, though typical of a controlling club most have been taken down, a lot of unhappy members out there that can't make use of the clubs facilities either booking a pitch or cancelling one.
All in in all an abysmal performance by the clubs management team who have made no updates apart from the "Unfortunately we are experiencing technical issues"
 
Aug 31, 2020
105
238
Funster No
75,266
MH
Hymer A Class
Exp
2019
We rang them on Monday to book a ferry , they told us all systems down hope to be back at the end of the week .

Subscribers  do not see these advertisements

 

Join us or log in to post a reply.

To join in you must be a member of MotorhomeFun

Join MotorhomeFun

Join us, it quick and easy!

Log in

Already a member? Log in here.

Latest journal entries

Funsters who are viewing this thread

Back
Top