We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
IMPORTANT! Have you received an email to your forum username?
Comments
-
Mine arrived in my spam box.
I am wondering why everyone is worried about them getting our email adds?0 -
Can't remember when I signed up, but it will appear when I post this!
I also use the "mse@mydomain.com" trick to track the origin of spam and over the years it's surprising how many organisations have lost or sold my details!
The fact that the email also quotes my user name for this forum means that the MSE forum database has been hacked or sold by an insider. Either way I'm afraid that it really makes me question the professionalism of the setup at MSE, which is a real, real shame. As an IT professional of decades' standing I tried to apply for a job that you advertised a year or so ago, but despite repeated attempts I never got an acknowledgement or a response to my application.
I seem to remember getting some spam to my "mse@...." email address last year, which I assume is when the original data breach occured, but I'm pretty sure it was generic spam and didn't include my forum user name, so this new outbreak is a bit worrying.
All I need to do is change my subscription email address to something like "mse2@...." and set my mail server to bounce any emails to the old address, a trifle inconvenient but not the end of the world. If you've only got one email address and used it to sign up to MSE then sorry but prepare to be spammed!
Webmaster - you've already referred to the original data breach, but I think we need "full disclosure" to reassure your many subscribers. You can see how many accusations of a sell-out are already circulating. I'm personally sure that it's "!!!!-up not conspiracy" but even so this is a major secuity breach at your end. For example, can we now assume that it is the forum database that was compromised rather than your full mailing list?
PS Last logged on to this forum in February.0 -
Yes i had recieved one too,thought it looked a wee bit suss so just deleted it.0
-
The_Gerbil wrote: »Could this be a clue? Somebody else said they had a friend who hadn't visited the site for ages and also hadn't received the suspect email.
Are you saying that you didn't get the email until after you visited the site.
If the database had been simply hacked and all the usernames and emails stolen you wouldn't see situations like this. They would just send the emails out to everyone in the database.
This looks more like the site has been hacked and there is malicious code on it (XSS). So you need to visit the site or some specific page or post to then trigger the evil email?
Just a theory.
Yes i did not get the email from them untill after i logged on to mse and have not been on for at least six months, logged on and early afternoon on mse and then got the suspect email at about sixDarling son born 10/12/09 hopefully the 1st of many :j0 -
I am concerned as the email I received connects my mse username with an email address that I have never used in connection with the user name in any other context but here. The breach has to have come from this site, as otherwise it would have gone to one of my other email addresses.All shall be well, and all shall be well, and all manner of things shall be well.
Pedant alert - it's could have, not could of.0 -
Hmmm ... somebody mentioned a few posts ago that they received the fake message to an email address they use for the weekly newsletter, and not the one that is registered for the forum - I wonder if there is anything in this?
Bang went that theory - ButterBean has received one, and he's not signed up for the email.
ETA. Just seen somebody else's theory that the emails may not be triggered until you log in - I shall log in as Frank and then wait to see!:heartpuls Mrs Marleyboy :heartpuls
MSE: many of the benefits of a helpful family, without disadvantages like having to compete for the tv remoteProud Parents to an Aut-some son
0 -
It's also remarkable (well, to me at any rate) the sheer number of posters who want justice NOW! as well as explanation NOW!
And possibly, Martin Lewis's head on a plate.
Incidents like these always bring out the Drama Queens. It's the LAW!
I haven't received an email yet - my username obviously begins with Z, so an automated dump may not have got up to me.
Any other "old-timers" who *haven't* received an email?
In future though, I would suggest that someone in MSE picks an email address with a unique token in it - (something more complicated than A1B2C3D5) and subscribes with A1B2C3D5A1B2C3D5@emailprovider.com (twice so going across packet boundaries doesn't matter). Then they can use snort to look for that token and at least have it kick-off during the copy, rather than weeping and wailing after.
It's not hard, and it's not expensive.Good job the overwhelming majority on here have the wits, and the patience, to allow MSE's Webbys to investigate -- though shame on all those vindictive posters with their various conspiracy theories who seem to have conveniently forgotten that this entire bloody thread wouldn't be here in the first place if MSE itself hadn't started it. . .
No, no. There needs to be constant communication, when there's nothing to say. After all, it's not like people who work at MSE have something better to do than constantly post. There's nothing else going on, like a security breach or anything..."Follow the money!" - Deepthroat (AKA William Mark Felt Sr - Associate Director of the FBI)
"We were born and raised in a summer haze." Adele 'Someone like you.'
"Blowing your mind, 'cause you know what you'll find, when you're looking for things in the sky." OMD 'Julia's Song'0 -
Can't remember when I signed up, but it will appear when I post this!
I also use the "mse@mydomain.com" trick to track the origin of spam and over the years it's surprising how many organisations have lost or sold my details!
The fact that the email also quotes my user name for this forum means that the MSE forum database has been hacked or sold by an insider. Either way I'm afraid that it really makes me question the professionalism of the setup at MSE, which is a real, real shame. As an IT professional of decades' standing I tried to apply for a job that you advertised a year or so ago, but despite repeated attempts I never got an acknowledgement or a response to my application.
I seem to remember getting some spam to my "mse@...." email address last year, which I assume is when the original data breach occured, but I'm pretty sure it was generic spam and didn't include my forum user name, so this new outbreak is a bit worrying.
All I need to do is change my subscription email address to something like "mse2@...." and set my mail server to bounce any emails to the old address, a trifle inconvenient but not the end of the world. If you've only got one email address and used it to sign up to MSE then sorry but prepare to be spammed!
Webmaster - you've already referred to the original data breach, but I think we need "full disclosure" to reassure your many subscribers. You can see how many accusations of a sell-out are already circulating. I'm personally sure that it's "!!!!-up not conspiracy" but even so this is a major secuity breach at your end. For example, can we now assume that it is the forum database that was compromised rather than your full mailing list?
PS Last logged on to this forum in February.
Have a word please.
You didn't get the job.. woopy doo. Your post sounds pretty much in anger.
Secondly i highly doubt MSE would sell details. I mean get real. This website has helped thousands if not millions obtain information to correct their life styles etc. Do you really think a highly acclaimed person like Martin would allow this?
Nasa gets hacked. Is that an inside job too?
Companies and servers get hacked all the time. It doesn't mean its an inside job.
Lastly this is an email address only people. How many people use Yahoo and have spam recieved every day? It's hacked nothing more. Email addresses are free so change it. No point grumbling about it
Most of you are going on like you are about to corrupted by fraud over a blinking Email.If Adam and Eve were created first
.Does that mean we are all inbred0 -
I would have thought it would have been sense to put this on the home page rather than just at the top of the forums.0
-
For those with Google Mail (GMail) accounts you may be interested in a little known feature.
You can use instead of signing up to stuff with [EMAIL="yourname@gmail.com"]yourname@gmail.com[/EMAIL] you can use yourname+something[EMAIL="unique@gmail.com"]unique@gmail.com[/EMAIL]. Any email sent to that address will go to your normal gmail account but then you can instantly see if your email address has been stolen/sold. You can also use this technique to set up filters0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.3K Banking & Borrowing
- 253.2K Reduce Debt & Boost Income
- 453.7K Spending & Discounts
- 244.2K Work, Benefits & Business
- 599.4K Mortgages, Homes & Bills
- 177.1K Life & Family
- 257.7K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards