Stop being the product.
Become the owner.
or
sign uplog in
(On this day
7 years ago)

I use FIREFOX browser and NORTON Anti-Virus (and a few free/subscription AVs just to periodically check on pc-health/vulnerability, etc,) -but recently was alerted (by a Firefox security monitoring extension) that one of my current eMail accounts has recently been shown on ' the dark web .'

Cited were some web-hosting sites that have shared/been hacked that I've used, years ago, and that thousands, even MILLIONS of user's eMail, passwords and 'other data' were stolen and being sold on said 'dark web.'

Needless to say, I scrambled to change and heavily obfuscate all my passwords on every current account. My passwords are typically very, very difficult anyway (I used to be an avid #LINUX user so character-heavy passwords were not unfamiliar to me.)

Well, within days of this Firefox extension 'warning' me of this breach, I began gettting dozens and dozens of spammy eMails on that particular eMail account. -Viagra, Cialis, Hot Brazilian Chics, Asian Babes, hot naughty chat, -- shit like that.

Well, I created a new personal eMail account to be rid of spammy eMails like this and for this past week, have been re-populating my Contacts, Subscriptions, etc. therein. All with the intent to CANCEL the 'compromised' account/s.

Tonight just for shits-n-giggles, I signed into an old 'semi-disposable' eMail account that I created back in 2015 during my web-page building/beta-testing period and have not used since circa late 2017, -among the maybe one-hundred plus 'spammy' commercial posts that have accumulated, was an actual THREAT from a hacker!

In the lengthy message, s/he showed an actual PASSWORD that I used to use from that dedicated-use account (a password that was changed by me almost two years ago, apparently AFTER the site I used it on was 'hacked'!) and his 'threat' further fell apart when his 'demand' for $800 in #BitCoin **** ( Depending on when in 2015 you made the purchase, $800 would have bought between 1.74 BTC and 5 BTC ) **** to be deposited into the provided BitCoin wallet provided with his claim to have 'recorded' me via my webcam in '...compromising sexual acts' and would post this (non-existent!) video on social media if I fail to pay-up! (My webcam is and always has been heavily taped-over, -no video is or ever was possible!) And really? I'd be about as scared if he claimed to have 'actual video' of me on a grassy knoll in Dallas in 1963... So, a great big fat FUCK YOU to that exaggerated threat!

I have staged for deletion my 'affected' eMails accounts (and created new, heavily secured 2-step authorization passcodes to further thwart future hack attempts) and with that, -a generic WARNING to you all:

-Treat your password/s like your toothbrush: don't let anyone else use yours and get a NEW one every 6 months... especially this, CREATE A NEW PASSWORD EVERY SIX MONTHS (or oftener if you can deal with it.)

This (hopefully!) has saved me from a very real hacking threat...

#hacker #scammer #phishing #phishingawareness
As of March 31st, Google is allowing users to change their primary Gmail address username. Although a nice feature for those who created unfortunate names originally, it may also undermine spam and phishing blocking.

The feature is intended to allow the user account to be changed while keeping the underlying account intact. The original name then becomes an alias, so the user will get their messages regardless of which address is used. Swell for some who want to change their account name but not lose their emails, calendar, and connections with others.

But there may be a sinister side to this. Gmail is a favorite for spammers, fraudsters, and phishing hackers. Although many providers use sophisticated filters that are based on reputation systems, behavioral signals, and infrastructure validation to block the bulk of malicious messages, some get through.

Recipients then have the ability to create a personal block as a final line of defense. Many people, including myself, will block addresses that flood my inbox with such inappropriate content, rendering future attempts by that account no longer a threat in my inbox. I have hundreds of email addresses blocked (to the dislike of spammers and social engineers).

The Attackers Advantage
If the attackers realize their list of targets is dwindling due to blocks, they can rename their accounts and be back in business to try again. This is convenient as fraudsters want to retain all the email engagements, customer lists, and information gathered as part of their campaign.

I believe most email providers use email addresses for the end-user blocks and don’t dive in any deeper. So, renaming the account is like starting fresh, and a malicious email that found its way through the bulk filters can then get into the inbox, until it is blocked again.

Right now, attackers are forced to create new email accounts, which is not that hard, but it can be time-consuming, and verification eventually becomes a problem. This option will reduce that friction and may increase the effective distribution of more spam and phishing.

Limits for Abuse
Google may have considered these potential downsides. They have instituted limits that will help the situation. A user can only rename their account once every 12 months and for a total of 3 times.

This may regulate some of the misuse by spammers and fraudsters, but I fear my list of blocked addresses, which are mostly Gmail accounts, will likely be undermined shortly, and my inbox once again flooded by unwanted and dangerous messages from adversaries who already possess my email address in their bulk distribution tools.

#cybersecurity #phishing
loved
1
Blur Network Hit by Second High-Profile Phishing Attack

Explore the turmoil as the Blur network encounters a second phishing attack, resulting in the loss of valued NFT assets.

Article: https://www.cryptonavigator.net/blur-network-hit-by-second-high-profile-phishing-attack/

#blur #NFT #network #phishing #hack