![]() |
|
|
|
Registered
Join Date: Jan 2001
Location: So. Cal.
Posts: 9,104
|
Hacked
Hacked. Hey out there be careful. Looks like I got hacked a little after 9:00 this morning. I was on PPOT at the time & haven't been on any other websites this morning except for Amazon. I changed my security code for my Hotmail acct. & hope that fixed it, but who knows.
__________________
Marv Evans '69 911E |
||
![]() |
|
Back in the saddle again
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,932
|
good luck!
__________________
Steve '08 Boxster RS60 Spyder #0099/1960 - never named a car before, but this is Charlotte. '88 targa ![]() |
||
![]() |
|
Registered
Join Date: Jul 2004
Location: Maryland
Posts: 31,447
|
Sorry to hear that, Marv. I really wish there was a way for folks like me to get smarter in term a layman can understand.
I got bounced last week from a scanner. Navy Federal called and said are these your charges...nope. No more debit cards except for cash at specific locations.
__________________
1996 FJ80. |
||
![]() |
|
Registered
|
My brother and I both had fraud/hacking incidents recently which caused me to do a lot of thinking about cyber security:
1) I recently mailed a check to an attorney for $35k. Attorney said they never got the check so I looked at my account. The check had indeed been deposited, but the scan showed the check had been fraudulently deposited in the name of someone else. Somehow they intercepted my check and either washed it or duplicated it with their own name as the recipient. The only handwriting on the check appeared to be legit was “my” signature. Everything else was different. Crazy. Thank God I used carbon checks. I still had to file a police report, rewire all of my recurring direct deposits and debits…. Serious PITA. I did get my money back but it took 2 weeks and a wasted day of my time. And my checking account of 20 years had to be shut down. The local police department is investigating, but I’m not hopeful. Lessons learned: - Checks are pretty old school and completely lacking in security. It’s probably best to minimize their use. Same with debit cards… - Use credit cards wherever you can. If there’s check/debit fraud, YOU are out the money until your bank agrees it was fraudulent and gives your money back. If there’s CC fraud, your bank/retailer is out the money. Big difference. - If you do need to write checks, use carbon checks so you have a record of what you wrote (and to whom!). Or be sure to take pictures of the checks you write — especially the big ones. - If you are mailing a check, particularly a big one, put it in an envelope and then mail that envelope in a FedEx, UPS or other registered mail envelope. You want the security of a tracking number and fully opaque envelope. In my case, I’d wrapped the check in paper, put it in a security envelope, and then dropped in a blue mail box. Apparently that wasn’t enough. - You’re going to want to have 2 checking accounts: primary and backup. If your primary get’s breached and shut down, you may not be able to write checks untile you get a new account setup and checks received (which takes time). In my case, I was able resend a check to my attorney using my wife’s checking account. 2) As eye opening as my experience was, my brother got a bigger scare. He often works nights, and noticed he was getting some odd messages in his primary email account (provided by Comcast). He realized he’d been hacked and that someone was trying to access his financial accounts and was resetting passwords. Compounding the issue, and this is super scary, the scammers had also hacked (social engineered) his Verizon account and somehow managed to either forward all his calls/messages or otherwise clone his phone. So with his primary email and phone, the hacker was attempting to gain access to all his financial accounts. Long story short, he spent the next 4 days playing whack-a-mole with his hacker. It was a complete nightmare. He ended up nuking his old email address and all messages, closed his old account at Verizon, and had to buy a new phone and SIM card. He fortunately lost no money nor had any fraudulent charges (to his knowledge so far). Lessons learned: - Do NOT use and email address provided by your cable provider or phone provider for any sensitive communications (especially financial accounts). You’re better off with Yahoo or Gmail or another account with 2-factor security (like an Authenticator app) and that doesn’t have a help desk — “help” desks can be socially engineered. In my brother’s case, the bad guys called the help desk at Comcast with “problems” related to the cable service, leveraged that into some moron giving out his MAC address, then parlaying that info into divulging his email passwords. With his email details, the hacker silently went to work on the “help” desk at Verizon. - Make sure you have a secondary account password on your cell phone account (not just the PW you use to access your account online). This second password is needed to authenticate ALL telephonic or in-person activity. And make sure this password is unique — it’s actually really important as cell phones are the de facto 2-factor security solution for many accounts these days. - Enable “real” 2 factor authentication on all your important accounts (email, financial, etc.). There are several authenticators, and some companies like Yahoo or Google have their own. These authenticators are essentially an app with a unique rolling code on your phone. The only way someone can get access is if they physically have your phone with the synced authenticator. - Use different, complex passwords for all your material accounts: Email, phone, financial accounts, etc. It’s not new advice, but it’s a PITA to manage, so consider using a password manager. - Assuming you’re not regularly opening up credit accounts. Put a freeze on your credit with all the agencies. It’s also a pain, but far less work than undoing the damage of a hacker. Anyway, long post, but hope that helps someone. Hackers suck. Sent from my iPad using Tapatalk |
||
![]() |
|
canna change law physics
|
Marv, I received a hacked e-mail from you at 11AM this morning (CDT).
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
I see you
Join Date: Nov 2002
Location: NJ
Posts: 29,891
|
My former employer got hacked some years ago. Hackers got the personal info on tens of thousands of us. It took me years to clean that sheet up.
![]() My personal take...don't relax just yet. Check your stuff frequently. A little paranoia is OK right now.
__________________
Si non potes inimicum tuum vincere, habeas eum amicum and ride a big blue trike. "'Bipartisan' usually means that a larger-than-usual deception is being carried out." |
||
![]() |
|
canna change law physics
|
Here it is:
Quote:
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
Registered
Join Date: Apr 2001
Location: Linn County, Oregon
Posts: 48,518
|
Guess I lucked out...my 'puter security service says I am clean..
__________________
"Now, to put a water-cooled engine in the rear and to have a radiator in the front, that's not very intelligent." -Ferry Porsche (PANO, Oct. '73) (I, Paul D. have loved this quote since 1973. It will remain as long as I post here.) |
||
![]() |
|
Bland
|
Quote:
![]()
__________________
06 Cayenne Turbo S and 11 Cayenne S 77 911S Wide Body GT2 WCMA race car 86 930 Slantnose - featured in Mar-Apr 2016 Classic Porsche Sold: 76 930, 90 C4 Targa, 87 944, 06 Cayenne Turbo, 73 911 ChumpCar endurance racer - featured in May-June & July-Aug 2016 Classic Porsche |
||
![]() |
|
Platinum Member
Join Date: Jul 2001
Location: Leave the gun. Take the cannoli.
Posts: 20,956
|
__________________
The truth is that while those on the left - particularly the far left - claim to be tolerant and welcoming of diversity, in reality many are quite intolerant of anyone not embracing their radical views. - Charlie Kirk |
||
![]() |
|
Still here
|
Quote:
Were you using free Wifi ? Are you in a foreign country ? |
||
![]() |
|
Registered
Join Date: Jan 2001
Location: So. Cal.
Posts: 9,104
|
Hi everbody. I changed my email account security code as soon as I found out. I have an alternate email account & when I change the code, they send an email to that account for me to enter a new code. This exact same scam happened to a friend of mine a month & a half ago. I'm trying to answer all the emails I'm getting asking about it. The crappy thing is it wiped out all the emails in my "sent" folder and my arriving emails now are going into a different folder than my inbox, which is now operating like my inbox. They started around 9:00 this morning, and I wasn't on any websites except PPOT and Amazon. I trust links on PPOT, but I vaguely remember opening a link I didn't think went with the subject of the thread. Maybe or maybe not. I haven't opened links from questionable sites - that I know of. I have no idea how I got zapped.
James - I think the last time I emailed you was a few years ago. Shows how thorough it was I guess.
__________________
Marv Evans '69 911E Last edited by Evans, Marv; 06-16-2021 at 08:34 PM.. |
||
![]() |
|
![]() |
Still here
|
Wow, how did it get your email credentials ? I wonder if your machine is still compromised. I would run a scan on it.
Best to use a clean machine for setting up the new email etc. Is your browser set to autorun downloaded files ? Last edited by pmax; 06-16-2021 at 09:27 PM.. |
||
![]() |
|
You do not have permissi
Join Date: Aug 2001
Location: midwest
Posts: 39,864
|
If you can, post more details than just "hacked"
(only because the term describes a wide range of nefarious activity)
__________________
Meanwhile other things are still happening. Last edited by john70t; 06-16-2021 at 09:15 PM.. |
||
![]() |
|
Registered
|
Sorry to hear you were hacked Marv. It happened to me a few months ago. I have run scans and everything is good. I called my credit card co. and got a new credit card. You might want to do the latter in case you used your credit card.
Cheers, Guy |
||
![]() |
|
Registered
Join Date: Sep 2009
Location: North of You
Posts: 9,160
|
There is a very interesting video by the 'Catch Me If You Can' guy on YouTube.
It is quite long and I thought I would watch a few minutes, then move on, instead I watched the entire hour. I found it fascinating. In the end he says 'Never EVER use a debit card'. The banks are responsible for credit card theft, but a compromised debit card is your problem. https://youtu.be/vsMydMDi3rI
__________________
"A machine you build yourself is a vote for a different way of life. There are things you have to earn with your hands." |
||
![]() |
|
Registered
Join Date: Jan 2001
Location: So. Cal.
Posts: 9,104
|
John. I'm not a tech guru, & described about as much as I noticed & can think of in my post above.
I never used a credit card for anything and only use a debit card a couple of times a year - mostly at the post office. I changed my email security code as soon as I found out, & I've checked my security for McAfee, Windows, updates, fire walls, etc. and everything is enabled & updated as it should be. Like I said, I'm pissed about the changes it left in my email, which I described above. Like I said, be careful out there. I'm not the most informed, but I try to be careful as I can and got zapped anyway.
__________________
Marv Evans '69 911E |
||
![]() |
|
Driver
|
Quote:
I'm surprised your local PD is investigating. LAPD didn't care. Told me to take it up with the post office. Post office didn't care and told me to file a complaint with the post master online. I did and even checked off the box that I wanted a reply, but never heard back from anyone. Fortunately my bank (B of A) stood behind me and replaced my money with just a simple, one-page form to fill out. I'm not against using checks, but I'm a lot more careful with where I mail them now. Always inside the post office.
__________________
1987 Venetian Blue (looks like grey) 930 Coupe 1990 Black 964 C2 Targa |
||
![]() |
|
The Unsettler
|
Quote:
Here is what's happening. They have set a rule in your online / web portal mail account, yes you have one, everyone does. The rule moves all incoming mail into either spam or some folder other than your inbox. They are monitoring that for emails from your contacts who are replying asking if what "you" just sent them is legit. They are replying yes to continue to spread their phising link. They also typically will move all other mail back to your inbox so you are not aware anything odd is going on. I've seen them run that on users for up to 2 weeks undetected. You can scan your local machines all you want, the compromise is not there, it's in your web portal.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|
The Unsettler
|
I strongly advise all of you to open a LastPass or Bitwarden account. If Bitwarden write your Master Pass somewhere as it's a zero knowledge service, meaning if you lose your pass there is no recovering it, ever.
Once set up go to all the sites you have accounts with and let LP or BW generate a unique password for that site. The logic there is obviously if one account does get compromised you don't have to run around like a chicken without a head trying to remember where you reused it and changing them all. Enable 2FA / MFA on every site that supports it especially any financial accounts. Getting "hacked" is a misnomer, no one gets hacked these days, we get compromised because we are creatures of habit, lazy, and value convenience over security.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|