Most of the Web sites found out about the problem when their customers called them, suspicious because their credit card information had been compromised. The lesson from this failure is that companies that operate electronic commerce Web sites must know the source of the software used in creating and maintaining their sites and must monitor news about the security of that software.