Help some brothers out.. scammer content

What's Hot
1468910

Comments

  • SupportactSupportact Frets: 1084
    Sorry to hear about this, I can totally see how it happened as I also tend to trust profiles that have been here for a while. And thanks to the mods for everything they do to try to counter this type of thing. 
    0reaction image LOL 0reaction image Wow! 3reaction image Wisdom
  • Mike58Mike58 Frets: 162
    DefaultM said:
    I've apparently been part of a hack of Truefire that revealed pretty much every single personal detail about me.
     Full name, address, email, password, DoB, phone number. That’s not great is it!
    How did you find out all that info was taken from the Trufire breach please?
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • KittyfriskKittyfrisk Frets: 19337
    Mike58 said:
    DefaultM said:
    I've apparently been part of a hack of Truefire that revealed pretty much every single personal detail about me.
     Full name, address, email, password, DoB, phone number. That’s not great is it!
    How did you find out all that info was taken from the Trufire breach please?
    Usually it would be shown in the details from an email search of https://haveibeenpwned.com/  site as mentioned earlier.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • DefaultMDefaultM Frets: 7424
    Mike58 said:
    DefaultM said:
    I've apparently been part of a hack of Truefire that revealed pretty much every single personal detail about me.
     Full name, address, email, password, DoB, phone number. That’s not great is it!
    How did you find out all that info was taken from the Trufire breach please?

    Yeah it's just on the website mentioned above, then go in your Truefire profile and see if you actually added any of the info.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • Fifty9Fifty9 Frets: 492
    edited January 2
    DefaultM said:
    Mike58 said:
    DefaultM said:
    I've apparently been part of a hack of Truefire that revealed pretty much every single personal detail about me.
     Full name, address, email, password, DoB, phone number. That’s not great is it!
    How did you find out all that info was taken from the Trufire breach please?

    Yeah it's just on the website mentioned above, then go in your Truefire profile and see if you actually added any of the info.
    I take it truefire sorted all this out? Ie improved security etc after it happened?

    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • stickyfiddlestickyfiddle Frets: 27678
    Just to be clear to anyone who finds their email on haveibeenpwend.com - you need to change your password on every website where you've used that username & password combination (unless it's completely inconsequential, probably, but even then it's a good idea)

    So if you're using the email "myusername@gmail.com" and password "idiot" on Truefire then that combination is leaked everywhere it used, including your bank, your email, paypal, fretboard, deliveroo, uber, netflix, ebay, amazon, reddit, facebook, instagram, twitter, tiktok, patreon, youtube, etc etc!! 

    This is why it's so important to switch to a password manager and long, random passwords wherever possible, and use a different one for every site. I don't even know my own passwords for 99% of websites these days because Apple keychain (in my case) manages it all for me. 

    Note with most email services you can also use "+text" modifiers for logins, so username+eby@gmail.com and username+amzn@gmail.com will both send emails to username@gmail.com (similar to @digitalscream's suggestion) so if you get leaked there's much less chance of a hack elsewhere unless someone actively spots this and tries to get into your accounts by changing that modifier according to the site. 

    But in all cases, password managers and ridiculous passwords are the best bet these days. 
    The Assumptions - UAE party band for all your rock & soul desires
    0reaction image LOL 0reaction image Wow! 3reaction image Wisdom
  • Jimbro66Jimbro66 Frets: 2431
    Just out of interest, I went to the haveibeenpwned website and entered four of my email addresses. It came back with nothing on two of those addresses but said the third had been leaked in a ReverbNation hack many years ago and the fourth was leaked in a MySpace hack, also quite a few years ago. Now, those two email addresses were only created three years ago, a long time after those two sites were hacked, so how could they have been leaked then?
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • jasonbone75jasonbone75 Frets: 677
    edited January 2
    Jimbro66 said:
    Just out of interest, I went to the haveibeenpwned website and entered four of my email addresses. It came back with nothing on two of those addresses but said the third had been leaked in a ReverbNation hack many years ago and the fourth was leaked in a MySpace hack, also quite a few years ago. Now, those two email addresses were only created three years ago, a long time after those two sites were hacked, so how could they have been leaked then?
    Not sure what is going on there - if you have your own domain you can use the domain section of the site to get a link sent to your email to check all aliases in a domain. Perhaps that would provide a bit more information on what is leaked where - this assumes you use your own domain for these multiple addresses rather than just having multiple accounts at gmail et. al

    EDIT - I have had my own domain for about 25 years and have found aliases in leaks that I have never used or put into a site. I think this is due to spammer lists being distributed with stuffed credentials so it is possible a bot created those original addresses/profiles you are seeing.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • jasonbone75jasonbone75 Frets: 677
    Just to illustrate this in detail (my main email is very much in the public domain so no concerns about privacy here):

    Only four of these addresses have ever been used by me and yet here they all are in breaches over the years. The other 12 are completely fabricated by someone or some system:

    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • glitterjetglitterjet Frets: 69
    Sorry to hear about this, I can totally see how it happened as I also tend to trust profiles that have been here for a while. And thanks to the mods for everything they do to try to counter this type of thing. 
    Thanks for the comment and contribution to @mankytom Crowdfunding, this post seems to have gone in a different direction but thanks to all who have contributed.........I salute you!!    Good that the mods have got to the bottom of it too.  
    Be careful out there.....
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • mankytommankytom Frets: 286
    No bother man… would be good to get a few more donations in.. we’re at 315 quid last time I looked. Which is great, but hopefully we can get closer to the 1450 you are out of pocket 
    0reaction image LOL 1reaction image Wow! 0reaction image Wisdom
  • carloscarlos Frets: 3526
    Just as an update...I'm currently processing the entirety of the breach file in question, with the aim of comparing it to our members table.

    All matching accounts will get a PM notification. If I'm able to use the leaked credentials to log that user in, I'll change the user's password and notify them with instructions on how to recover their account.

    It's gonna take a while, though - there are 230 million email addresses. Just importing them is gonna be a multiple-day exercise.
    That's incredible work. Thank you!
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • KittyfriskKittyfrisk Frets: 19337
    mankytom said:
    Happy new year all..

    https://www.justgiving.com/crowdfunding/tom-regan

    this is the link for the fundraiser.. up to 275 now, which is brilliant! 

    This discussion has now had 5.1k views.. if every view gave 25p we would have enough to reimburse the loss. Anything people feel able to manage would be greatly appreciated. Lots of small amounts from so many of us who are interested, and could have fallen foul of this, could make a real difference.

    <geldof mode disengaged> 
    Agree with your viewpoint Sir Bob  ;)
    Small point, I must admit to not having being impressed at having to give an additional minimum 10% to Justgiving as a “voluntary contribution”.
    I wanted to give to help your effort, not to subsidise the company without the option to opt out. Paid it anyway, but it did seem to be very similar to the 'tipping' thread. Hope more people here can help out :+1: 
    <rant mode off>
    1reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • mankytommankytom Frets: 286
    I think there is a way of not tipping them. I’ve fallen foul of it before but I think you can do it! 

    I think you have to write the amount in the box again.. 

    It’s a shame that they make it difficult 
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • NiteflyNitefly Frets: 4952
    mankytom said:
    I think there is a way of not tipping them. I’ve fallen foul of it before but I think you can do it! 

    I think you have to write the amount in the box again.. 

    It’s a shame that they make it difficult 
    It let me enter "Custom Amount" for the tip, which I set to zero.

    Good work @mankytom and @digitalscream ; :)

    0reaction image LOL 0reaction image Wow! 3reaction image Wisdom
  • mankytommankytom Frets: 286
    Thanks man! That’s what I was trying to say :)
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • mankytommankytom Frets: 286
    @Fifty9 did you get sorted by PayPal? 

    If so I will update the target.

    lots more contributions yesterday which is great! Every penny counts.. if everyone who read this thread had given 50p we would have smashed it several times over!

    https://www.justgiving.com/crowdfunding/tom-regan
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • Mike58Mike58 Frets: 162
    Worth chipping in folk,  price of a beer or two won’t affect you but will cumulatively make a difference.
    believe you me.. being scammed affects you. Big time.
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • mankytommankytom Frets: 286
    £332… it’s amazing what a group of people who mostly chat about guitars over the internet can do..

    can anyone else help?

    https://www.justgiving.com/crowdfunding/tom-regan
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
  • Fifty9Fifty9 Frets: 492
    mankytom said:
    @Fifty9 did you get sorted by PayPal? 

    If so I will update the target.

    lots more contributions yesterday which is great! Every penny counts.. if everyone who read this thread had given 50p we would have smashed it several times over!

    https://www.justgiving.com/crowdfunding/tom-regan

    Have to wait to Jan 9 but so far it looks good
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom
Sign In or Register to comment.