I'll start at the beginning, so it might make a little sense.
I had an account with Scan last year, with which I made at least one order. When I went to make an order this year, the account was gone. Not a trace of it on their system. According to their website they had upgraded recently and older logins may not have been transferred.. so I didn't really think anything of it.
Come mid this year, I fancied a few things on 'Today Only', so I went to make an order. Account was gone, as I just said, so I made a new one. Same account details as the old one, but a more secure password. They managed to screw that order up and take over a week to sort out a bag of accessories, they didn't even reply to the 'customer service' emails, I had to get someone through the Hexus.net forums! That was sorted out only a few weeks ago and I was able to complete my computer build.
Yesterday, we were discussing purchasing a new server for our email/internet duties at work. The IT Manager was on about buying a tiddly little P4 3Ghz box with no highlights, I spec'd him up something better from Scan and said I would build it. So, yesterday evening I made the order, on my account.
Login, add the Company credit card + address (under the MDs name), delivery address changed itself. This was as expected, though it did ask for mothers maiden name (presumed to be for the credit card, it was on the same page) and email address (didn't think much of it at the time), I used the IT Managers details for both.
I attempted to login today, 'account not found'. I tried with a few passwords, and strangely my old password worked (I was confused, considering my old account wasn't there a few months ago). It had the details of my order from last year, but not the recent orders. I gave Scan a ring, it seems I now have an account under my MDs name, company address, IT Managers maiden name and email, and my password! It had also changed my entire order history to my MDs name and company address!
The 'customer service' lady on the phone had the cheek to say it was entirely my fault, their system was perfectly fine and there were no errors/bugs to be found. She also assured me that previous invoices could not have their details changed, and it was impossible for this to happen.. (she also rambled on for quite a long time and ignored me trying to interrupt). I tripped her over however when I said 'I have paper invoices at home, with these invoice numbers, but they have MY name and address on them, would you like to explain that?'.. she rambled about contacting the IT department, and that was pretty much the end.
However, one other thing she did do.. was ask for my account password (surely no real company should ever do this), I obviously refused. She then told me what my password was over the phone! Have these people never heard of encryption?!
So, from this experience, Scan have a completely open computer system, with your name, address, email, password plain to see to any employee, and easily changable (not sure if they store cc information). They also know my forum login, due to it being associated with the Scan account for free delivery (password is the same.. it's actually encrypted on the forum and more secure!). There is also the issue that anyone can seemingly change their entire order history and account information.
If anyone steals a Scan computer, which just so happens to have the store login details cached (or they know them already), they can easily make the purchase seemingly theirs by changing the persons account history and login details!
What can I say except, Scan are a complete joke of a company.
Since writing this, my account details have been changed again. I was promised they would be fixed and reverted to my previous details.. they have not been. I now have no idea what my account login details are. I have an order in progress which is urgently required (and was also promised would arrive tomorrow on the phone), and I cannot check the progress of it.. bravo!