EMAIL FROM HACKER - ADVICE NEEDED

The #1 community for Gun Owners in Indiana

Member Benefits:

  • Fewer Ads!
  • Discuss all aspects of firearm ownership
  • Discuss anti-gun legislation
  • Buy, sell, and trade in the classified section
  • Chat with Local gun shops, ranges, trainers & other businesses
  • Discover free outdoor shooting areas
  • View up to date on firearm-related events
  • Share photos & video with other members
  • ...and so much more!
  • rhino

    Grandmaster
    Rating - 100%
    24   0   0
    Mar 18, 2008
    30,906
    113
    Indiana
    Your information could be posted online, and they could just be contacting you to try to get some money. My info was leaked with an old (3+ year old) password. I don't like the wallet idea, so I have a bunch of encrypted passwords that I typically change 3-4x per year.

    So long as they didn't actually gain access and try to CHANGE your 2 step authentication you're fine. My guess is that your email/password combo was listed on some nefarious sites. I think I have 5 old passwords listed when I used search. Oh well. None are current.

    I think someone is searching for different combinations of my first and last name and then trying what the find with that old password. The gmail account had my name, but it also had some other characters and obviously the domain was different than the email address that was stolen with the password from the uspsa web site a couple of years ago.
     

    Phase2

    Grandmaster
    Rating - 100%
    6   0   0
    Dec 9, 2011
    7,014
    27
    Since it is impossible to keep up with all of the sites that have had their databases breached, this site is a very good resource to check if your e-mail has been linked to any compromised accounts.

    https://haveibeenpwned.com

    It is a very well-known and widely-used security tool. They get copies of accounts that have been compromised and sold/published and keep them in one place for you to check. It is a handy way to look for places where your credentials may have been compromised that you aren't even aware of.
     

    CHCRandy

    Master
    Rating - 100%
    5   0   0
    Feb 16, 2013
    3,723
    113
    Hendricks County
    I just got one of these the other day. They had the right password, but that is not a surprise because I use it frequently on many different sites. The bad part is I have no idea what site they got it from. They wanted $7000 from me....I just deleted email and have been trying to change it at the places I could remember.
     

    rhino

    Grandmaster
    Rating - 100%
    24   0   0
    Mar 18, 2008
    30,906
    113
    Indiana
    I just got one of these the other day. They had the right password, but that is not a surprise because I use it frequently on many different sites. The bad part is I have no idea what site they got it from. They wanted $7000 from me....I just deleted email and have been trying to change it at the places I could remember.


    Yep, it's a good reminder!
     

    rhino

    Grandmaster
    Rating - 100%
    24   0   0
    Mar 18, 2008
    30,906
    113
    Indiana
    Got mine to the USPSA address last week. Happily, I remembered seeing this thread, so no concern.


    I think about 20,000 other people are getting the same thing from the exact same source. I am reminded of how irritated I was by an organization that had essentially zero security measures in place at the time, and worse yet, an unencrypted text file just sitting there with all of the passwords and email addresses. UGH.
     

    SmileDocHill

    Grandmaster
    Rating - 100%
    61   0   0
    Mar 26, 2009
    6,174
    113
    Westfield
    I just got almost the exact same email. Part of the password they supposedly hacked had "uspsa" in it. I honestly can't remember if the full password is actually one I have or used to have but it looks similar to something I would come up with. So at some point they hacked someone that likely had a password of mine. Makes you wonder if they got any others in the mix. time to change the 1.3 million passowords I have to various sites.
     

    SmileDocHill

    Grandmaster
    Rating - 100%
    61   0   0
    Mar 26, 2009
    6,174
    113
    Westfield
    Since it is impossible to keep up with all of the sites that have had their databases breached, this site is a very good resource to check if your e-mail has been linked to any compromised accounts.

    https://haveibeenpwned.com

    It is a very well-known and widely-used security tool. They get copies of accounts that have been compromised and sold/published and keep them in one place for you to check. It is a handy way to look for places where your credentials may have been compromised that you aren't even aware of.

    That is exactly what a hacker would say to get you to click on a link. I'm not falling for that!



    I know its an old post but I can't resist. (-:
     

    GLOCKMAN23C

    Resident Dumbass II
    Site Supporter
    Rating - 100%
    22   0   0
    Feb 8, 2009
    38,127
    83
    S.E. Indy
    I just got almost the exact same email. Part of the password they supposedly hacked had "uspsa" in it. I honestly can't remember if the full password is actually one I have or used to have but it looks similar to something I would come up with. So at some point they hacked someone that likely had a password of mine. Makes you wonder if they got any others in the mix. time to change the 1.3 million passowords I have to various sites.

    I received 2 emails in the last week. Virtually identical, from different addresses. It is a pw that I haven't used for a long time.
     

    fullmetaljesus

    Probably smoking a cigar.
    Rating - 100%
    6   0   0
    Jan 12, 2012
    5,884
    149
    Indy
    There have been lots of sensitive info has been leaked. Lots of hacks have happened so it should come to no surprise that somebody your passwords and email addresses have been shared freely online.

    You can check via
    Haveibeenpwned.com


    It would be wise if y'all would change your passwords regularly. And never use the same one for more than one thing. I use LastPass personally. It generates and saves your passwords for you.
     

    Thor

    Grandmaster
    Site Supporter
    Rating - 100%
    2   0   0
    Jan 18, 2014
    10,713
    113
    Could be anywhere
    I got the same sort of thing this morning...of course he said he had FacePlant account information and computer cam videos which made me LOL as I have neither. Screw you hacker scum!
     

    churchmouse

    I still care....Really
    Emeritus
    Rating - 100%
    187   0   0
    Dec 7, 2011
    191,809
    152
    Speedway area
    I received 2 emails in the last week. Virtually identical, from different addresses. It is a pw that I haven't used for a long time.

    I used PayPal (Not my account) to get some stuff for my computer. The next day my card number showed up in my history feed out in the open.

    Trust me the :poop: hit the fan.

    Is everything a scam.
     

    WebSnyper

    Time to make the chimichangas
    Rating - 100%
    59   0   0
    Jul 3, 2010
    15,651
    113
    127.0.0.1
    It would be wise if y'all would change your passwords regularly. And never use the same one for more than one thing. I use LastPass personally. It generates and saves your passwords for you.

    Agreed, I use LastPass as well, and yes, unique passwords, and where you can set it up (email address, bank, etc) use Multi Factor Authentication, and preferably not just SMS/Text MFA, unless that is all they offer. Unfortunately most banks seem to only want to use text or email MFA. Much better if you can use an actual MFA provider application.

    If you use same passwords across accounts and no MFA, you are only as good as the weakest possible website that you use it on.

    Can't wait until the world is passwordless. There are some passwordless authentication methods out there in use now. Work pretty well, as long as you have your phone/token, etc available.
     
    Last edited:
    Top Bottom