Home U.S. Coin Forum
Options

After Heritage hack, my log in credentials were compromised...

AbueloAbuelo Posts: 1,761 ✭✭✭✭✭

This could be a coincidence, but just received an email from a credit alert system (not spam) to notify me that the email I use to log in HA.com has been detected yesterday on the dark web... there you have it. I put this in the thread of the official Heritage hack but several of you asked me to start a new thread with this information. So change your passwords, monitor accounts, etc.

Comments

  • Options
    CoinstartledCoinstartled Posts: 10,135 ✭✭✭✭✭

    My father never owned a computer and seemed to enjoy life just the same.

    The off the grid guy on the PM forum might have the right idea.

  • Options
    topstuftopstuf Posts: 14,803 ✭✭✭✭✭

    @Coinstartled said:
    My father never owned a computer and seemed to enjoy life just the same.

    The off the grid guy on the PM forum might have the right idea.

    He got silver coins in change. :p

  • Options
    skier07skier07 Posts: 3,699 ✭✭✭✭✭

    Thanks. I still can’t log into my account but I will change my password once I’m able to access my account.

  • Options
    PhilLynottPhilLynott Posts: 881 ✭✭✭✭✭

    I got an email this morning from groupon that "suspicious account activity was detected". I haven't used groupon in probably a decade.

    Also could be completely unrelated but I'm definitely going to go start changing passwords everywhere I can think of as a precaution.

  • Options
    ms70ms70 Posts: 13,946 ✭✭✭✭✭

    I'm hoping there's not a dark-web list of customer home addreses that coins were shipped to.

    Great transactions with oih82w8, JasonGaming, Moose1913.

  • Options
    CoinstartledCoinstartled Posts: 10,135 ✭✭✭✭✭

    @Tomthecoinguy said:

    @Coinstartled said:
    My father never owned a computer and seemed to enjoy life just the same.

    The off the grid guy on the PM forum might have the right idea.

    OK, I will bite, how can someone be off the grid and also on the PM forum? :/

    He let the forum know of his intentions.

    https://forums.collectors.com/discussion/1026331/thanks-to-all-i-am-taking-my-gold-and-silver-i-am-out-of-here#latest

  • Options
    TurboSnailTurboSnail Posts: 1,668 ✭✭✭✭✭

    @ms70 said:
    I'm hoping there's not a dark-web list of customer home addreses that coins were shipped to.

    Possible. I was one of the victims from yahoo incident many years back. My email account and pw was posted on a Russian site and ended up with half of my other accounts on major sites stolen due to same pw etc.

  • Options
    BAJJERFANBAJJERFAN Posts: 30,994 ✭✭✭✭✭

    @TurboSnail said:

    @ms70 said:
    I'm hoping there's not a dark-web list of customer home addreses that coins were shipped to.

    Possible. I was one of the victims from yahoo incident many years back. My email account and pw was posted on a Russian site and ended up with half of my other accounts on major sites stolen due to same pw etc.

    Be prepared for an influx of blackmail emails asking for $$$ or they will post videos to your address book showing you doing something to yourself. Course they never show YOU the video to validate the threat.

  • Options
    amwldcoinamwldcoin Posts: 11,269 ✭✭✭✭✭

    LOL! They tried that on me. Funny thing was I have my computer camera covered. I guess they had x-ray vision!

    @BAJJERFAN said:

    @TurboSnail said:

    @ms70 said:
    I'm hoping there's not a dark-web list of customer home addreses that coins were shipped to.

    Possible. I was one of the victims from yahoo incident many years back. My email account and pw was posted on a Russian site and ended up with half of my other accounts on major sites stolen due to same pw etc.

    Be prepared for an influx of blackmail emails asking for $$$ or they will post videos to your address book showing you doing something to yourself. Course they never show YOU the video to validate the threat.

  • Options
    TurboSnailTurboSnail Posts: 1,668 ✭✭✭✭✭

    @BAJJERFAN said:
    Be prepared for an influx of blackmail emails asking for $$$ or they will post videos to your address book showing you doing something to yourself. Course they never show YOU the video to validate the threat.

    Google "vavilon.cc › attachments" and see what come after email. I assume some members here are using the same pw for major accounts and emails.

  • Options
    PhilLynottPhilLynott Posts: 881 ✭✭✭✭✭

    Should we just worry about changing passwords that were the same as Heritage or change all passwords for some reason?

    The former is only one other place I can think of the latter would take all day lol

  • Options
    BBNBBN Posts: 3,761 ✭✭✭
    edited October 21, 2019 10:56AM

    @Coinstartled said:

    The off the grid guy on the PM forum might have the right idea.

    The irony here is someone on a web forum being off the grid. :D

    edit
    OK, just saw. My question is how long will he last and how far will he make it. Like homesteading or just living off of his investments. I hope he makes it but not sure how long someone can just go off the grid after years of living on it.


    Positive BST Transactions (buyers and sellers): wondercoin, blu62vette, BAJJERFAN, privatecoin, blu62vette, AlanLastufka, privatecoin

    #1 1951 Bowman Los Angeles Rams Team Set
    #2 1980 Topps Los Angeles Rams Team Set
    #8 (and climbing) 1972 Topps Los Angeles Rams Team Set
  • Options
    TurboSnailTurboSnail Posts: 1,668 ✭✭✭✭✭

    @PhilLynott said:
    Should we just worry about changing passwords that were the same as Heritage or change all passwords for some reason?

    The former is only one other place I can think of the latter would take all day lol

    The same pw that can be link from HA to your email and then to other accounts with same user name, ip address etc. Unfortunately HA is one of the few sites that we use true identity and link to our major accounts with similar pw.

  • Options
    TradesWithChopsTradesWithChops Posts: 640 ✭✭✭✭

    @PhilLynott said:
    Should we just worry about changing passwords that were the same as Heritage or change all passwords for some reason?

    The former is only one other place I can think of the latter would take all day lol

    General computer security guidelines dictate that no password should be shared among any login - and they should be changed every 6 months (bonus to you if you change them more frequently).

    Minor Variety Trade dollar's with chop marks set:
    More Than It's Chopped Up To Be

  • Options
    PhilLynottPhilLynott Posts: 881 ✭✭✭✭✭

    @TradesWithChops said:

    @PhilLynott said:
    Should we just worry about changing passwords that were the same as Heritage or change all passwords for some reason?

    The former is only one other place I can think of the latter would take all day lol

    General computer security guidelines dictate that no password should be shared among any login - and they should be changed every 6 months (bonus to you if you change them more frequently).

    Yeah probably a good idea to get in that habit. It's a hassle but not as big of a hassle as dealing with fraud. I try to mix up passwords across sites but definitely never change them over time.

  • Options
    zas107zas107 Posts: 825 ✭✭✭

    The lists on the dark web are not updated terribly often, this was unlikely due to heritage. Go to www.haveibeenpwned.com and you can actually determine the source of the leak.

  • Options
    TradesWithChopsTradesWithChops Posts: 640 ✭✭✭✭
    edited October 21, 2019 1:09PM

    @PhilLynott said:

    @TradesWithChops said:

    @PhilLynott said:
    Should we just worry about changing passwords that were the same as Heritage or change all passwords for some reason?

    The former is only one other place I can think of the latter would take all day lol

    General computer security guidelines dictate that no password should be shared among any login - and they should be changed every 6 months (bonus to you if you change them more frequently).

    Yeah probably a good idea to get in that habit. It's a hassle but not as big of a hassle as dealing with fraud. I try to mix up passwords across sites but definitely never change them over time.

    I'd suggest you look into True Key (or other likewise programs).

    You can manage your logins there, and change them routinely. They make it easy to create pseudo-randomly generated passwords.

    Just make sure to use two-factor or even three-factor authentication to access True Key, since it acts as the keys to your kingdom.

    That is, I'd recommend two+ factor on all accounts that allow it, too.... but surprisingly not many do yet

    Minor Variety Trade dollar's with chop marks set:
    More Than It's Chopped Up To Be

  • Options
    AbueloAbuelo Posts: 1,761 ✭✭✭✭✭

    @zas107 said:
    The lists on the dark web are not updated terribly often, this was unlikely due to heritage. Go to www.haveibeenpwned.com and you can actually determine the source of the leak.

    Already did this morning. Sadly, there were no details that could be found about this specific. As I said maybe was coincidental, but one never knows...

  • Options
    BAJJERFANBAJJERFAN Posts: 30,994 ✭✭✭✭✭

    @TurboSnail said:

    @BAJJERFAN said:
    Be prepared for an influx of blackmail emails asking for $$$ or they will post videos to your address book showing you doing something to yourself. Course they never show YOU the video to validate the threat.

    Google "vavilon.cc › attachments" and see what come after email. I assume some members here are using the same pw for major accounts and emails.

    More than 10 years ago someone somehow got my email pswd. I was tipped off when I started getting strange emails that looked like they came from me so I immediately changed that pswd. Someone must have recently bought it off of the dark web I expect.

  • Options
    BStrauss3BStrauss3 Posts: 3,170 ✭✭✭✭✭

    @amwldcoin said:
    LOL! They tried that on me. Funny thing was I have my computer camera covered. I guess they had x-ray vision!

    My desktop doesn't even HAVE a camera

    -----Burton
    ANA 50 year/Life Member (now "Emeritus")
  • Options
    ffcoinsffcoins Posts: 517 ✭✭✭
    edited October 23, 2019 5:50AM

    The iphone also has an effective password manager that can generate “strong” passwords for you.

    @TradesWithChops said:

    @PhilLynott said:

    @TradesWithChops said:

    @PhilLynott said:
    Should we just worry about changing passwords that were the same as Heritage or change all passwords for some reason?

    The former is only one other place I can think of the latter would take all day lol

    General computer security guidelines dictate that no password should be shared among any login - and they should be changed every 6 months (bonus to you if you change them more frequently).

    Yeah probably a good idea to get in that habit. It's a hassle but not as big of a hassle as dealing with fraud. I try to mix up passwords across sites but definitely never change them over time.

    I'd suggest you look into True Key (or other likewise programs).

    You can manage your logins there, and change them routinely. They make it easy to create pseudo-randomly generated passwords.

    Just make sure to use two-factor or even three-factor authentication to access True Key, since it acts as the keys to your kingdom.

    That is, I'd recommend two+ factor on all accounts that allow it, too.... but surprisingly not many do yet

  • Options
    messydeskmessydesk Posts: 19,705 ✭✭✭✭✭

    @BAJJERFAN said:

    @TurboSnail said:

    @BAJJERFAN said:
    Be prepared for an influx of blackmail emails asking for $$$ or they will post videos to your address book showing you doing something to yourself. Course they never show YOU the video to validate the threat.

    Google "vavilon.cc › attachments" and see what come after email. I assume some members here are using the same pw for major accounts and emails.

    More than 10 years ago someone somehow got my email pswd. I was tipped off when I started getting strange emails that looked like they came from me so I immediately changed that pswd. Someone must have recently bought it off of the dark web I expect.

    The problem wasn't your password, but rather your e-mail address was harvested from somewhere, probably someone else's e-mail, and then spoofed in outgoing mail, which is easy to do.

  • Options
    BAJJERFANBAJJERFAN Posts: 30,994 ✭✭✭✭✭

    @BStrauss3 said:

    @amwldcoin said:
    LOL! They tried that on me. Funny thing was I have my computer camera covered. I guess they had x-ray vision!

    My desktop doesn't even HAVE a camera

    It might be in the monitor.

  • Options
    BAJJERFANBAJJERFAN Posts: 30,994 ✭✭✭✭✭

    @messydesk said:

    @BAJJERFAN said:

    @TurboSnail said:

    @BAJJERFAN said:
    Be prepared for an influx of blackmail emails asking for $$$ or they will post videos to your address book showing you doing something to yourself. Course they never show YOU the video to validate the threat.

    Google "vavilon.cc › attachments" and see what come after email. I assume some members here are using the same pw for major accounts and emails.

    More than 10 years ago someone somehow got my email pswd. I was tipped off when I started getting strange emails that looked like they came from me so I immediately changed that pswd. Someone must have recently bought it off of the dark web I expect.

    The problem wasn't your password, but rather your e-mail address was harvested from somewhere, probably someone else's e-mail, and then spoofed in outgoing mail, which is easy to do.

    Possibly but someone got it somehow. The "blackmail" email I got some months ago had the correct password [even tho it wasn't valid now].

  • Options
    WHPRATTWHPRATT Posts: 114 ✭✭✭

    Same here. My credit monitoring stated my email address was added to the dark web, too.

Leave a Comment

BoldItalicStrikethroughOrdered listUnordered list
Emoji
Image
Align leftAlign centerAlign rightToggle HTML viewToggle full pageToggle lights
Drop image/file