TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“Change your password qwerty immediately. You have been hacked.”

43 pointsby tbodtover 6 years ago

15 comments

nwellnhofover 6 years ago
I've been getting these emails for a while now. If you realize that it's just a scam, they're providing a service similar to Have I Been Pwned, delivered directly to your inbox!
jermaustin1over 6 years ago
They&#x27;ve earned nearly 3BTC off of this scam if BitRef is accurate: <a href="https:&#x2F;&#x2F;bitref.com&#x2F;15ZHnf1MPn6ybb8yUeAoCQ1AJtiKhg3NrP" rel="nofollow">https:&#x2F;&#x2F;bitref.com&#x2F;15ZHnf1MPn6ybb8yUeAoCQ1AJtiKhg3NrP</a>
评论 #18409813 未加载
评论 #18408727 未加载
asveikauover 6 years ago
I have been getting a variation of this email for months sent to mailer-daemon@ on a mail server on a VM that hosts absolutely no personal information or credential about anyone.<p>If you Google some phrases from it it seems like it&#x27;s been going around nearly verbatim for years.<p>I think they are probing for mail servers which don&#x27;t try to force any kind of authentication on From: headers. So mailing lists would probably be a fit for them. They have no idea who their targets are. They are just looking for gullible people to scam.
评论 #18408568 未加载
jandreseover 6 years ago
I&#x27;m surprised it doesn&#x27;t include a link to a &quot;security site&quot; with a domain like &quot;passwordcheck.ru&quot; to verify that the new password is secure.<p>The thing that confuses me about this is that it includes the password. Certainly most people would go &quot;that&#x27;s not my password&quot; and ignore it. Are they trying to filter out the results to only people with atrocious passwords?
评论 #18408563 未加载
评论 #18408481 未加载
评论 #18408999 未加载
评论 #18408650 未加载
1001101over 6 years ago
Ouch [1]<p>I like the cut of whoever sent 0.00000666 BTC&#x27;s jib.<p>[1] <a href="https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;15ZHnf1MPn6ybb8yUeAoCQ1AJtiKhg3NrP" rel="nofollow">https:&#x2F;&#x2F;www.blockchain.com&#x2F;btc&#x2F;address&#x2F;15ZHnf1MPn6ybb8yUeAoC...</a>
raintreesover 6 years ago
&gt; This is a hacker code of honor.<p>Had me right there. The entertainment value alone would be worth it, if I did not also have to calm down those (few) of my clients who are a little more, shall we say, persuadable?<p>Then out comes the &quot;good security practices&quot; text, along with credit card monitoring recommendations text, etc.<p>&quot;I know it&#x27;s true, &#x27;cause I saw it on tv.&quot; - John Fogerty
评论 #18408606 未加载
monksyover 6 years ago
What happens if you keep sending them more &quot;incriminating information&#x2F;pics&quot;?
DyslexicAtheistover 6 years ago
a lot of people get this spam. I received as similar one. it&#x27;s spam filter configuration of lkml and I doubt that it is an actual targeted attack.<p><i>&gt; After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).</i><p><i>&gt; I made a screenshot of the intimate website where you have fun (you know what it is about, right?). After that, I took off your joys (using the camera of your device). It turned out beautifully, do not hesitate. </i><p>+1 for social engineering.<p>and very similar to the thousands of other such mails sent out every day by scammers.
评论 #18408732 未加载
PascLeRascover 6 years ago
&gt; Do not worry, the timer will start at the moment when you open this letter. Yes, yes .. it has already started!<p>The most impressive part of this hack is that he got read receipts for emails!
评论 #18410740 未加载
schaeferover 6 years ago
The mysterious individual extorting me assures me that paying their ransom via bitcoin is even easier than a credit card transaction.<p>How informative and thoughtful of them.
nullvariableover 6 years ago
according to blockchain dot com,<p>Total Received 2.98619488 BTC (apx $19k USD)<p>So not an unsuccessful campaign I guess
评论 #18408792 未加载
评论 #18408725 未加载
jamiewebover 6 years ago
I&#x27;ve seen similar emails in my DMARC rejected email reports.<p>The unique thing about these ones is that they send it from your own address. I.e. they spoof your address so that it looks like your account really has been compromised.<p>Like this:<p>From: me@example.com<p>To: me@example.com
X6S1x6Okd1stover 6 years ago
That btc address started receiving txs last month and has almost 3 BTC in it. At time of writing that is worth ~20k USD
raverbashingover 6 years ago
So I guess the question is: was the password for that email ever qwerty or how did it end up there?
antocvover 6 years ago
This is spam people, how easily fooled are you!?