📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

IMPORTANT! Have you received an email to your forum username?

1404143454695

Comments

  • emmell
    emmell Posts: 1,228 Forumite
    I have had notification of an email and I'm a user from Feb 2009, if this helps you out at all.
    ML.
    He who has four and spends five, needs neither purse nor pocket
  • 23n1th
    23n1th Posts: 1,523 Forumite
    Just voted on the poll as having joined this year and for some reason the vote went to "joined before 2010" sort it out.
  • mp3duck
    mp3duck Posts: 1,305 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    I am sure this may have been said by others, but I too got the email.
    However, it was addressed to my username that I changed a long time back. I think it was around 8 months back..

    I know for sure that our details were not sold.. Like Martin said, that is something they would never do.
    No website if 100% secure. Hackers will always find a new way to gain access to our details.
  • dmbw
    dmbw Posts: 378 Forumite
    yupp i got one in my junk box, opened it aswell but didn't click anything as thought it was dodgy looking purporting to be business ME
  • MSE_Martin
    MSE_Martin Posts: 8,272 Money Saving Expert
    Part of the Furniture 1,000 Posts Combo Breaker
    I've just spoken to my team about this.

    There are two people who have joined since 2010 who say they've got an email which is of course worrying, though we've yet to verify it and want to check those emails before drawing any conclusions. I have now started the poll to see when the people who got the email joined.

    Originally I was going to ask whether people got it or not - but then realised it would be massively skewed because people who got the email would be the ones who clicked the "have you got an email to your forum address" link.

    We are going to further look at this in the morning. Both my team and our server company's security team have been logging at this and the access logs and no indication of a recent breach has been found yet (as far as Im aware it is 10.30pm and I can't get hold of them all)
    Martin Lewis, Money Saving Expert.
    Please note, answers don't constitute financial advice, it is based on generalised journalistic research. Always ensure any decision is made with regards to your own individual circumstance.
    Don't miss out on urgent MoneySaving, get my weekly e-mail at www.moneysavingexpert.com/tips.
    Debt-Free Wannabee Official Nerd Club: (Honorary) Members number 000
  • same as some other posters, I got it today but it was showing my old username that was changed a while back
  • fletty
    fletty Posts: 731 Forumite
    I didn't have the email earlier on today but have just recieved it now so it's still on going.....
    :beer:
  • Olipro
    Olipro Posts: 717 Forumite
    Fair enough, but even so as I'm sure you'll know, if you've got a dump of a database with 'double hashed' passwords, it doesn't take too long to apply the same hashing to a file of dictionary words. Then go through your stolen database, and see which hashes match. Boom, now you have the passwords of the 90% of users who had passwords straight out of the dictionary (or perhaps those on the super-common list, e.g. 'fred', 'god', 'password1', 'letmein', etc).

    No, it'd take ages with a database the size of MSEs, not to mention that having a forum account password isn't terribly useful unless you happen to know who that person is.

    However, further compounding the problem for any would-be password cracker is the fact that VBulletin uses a salt, so the only way you'd even be able to either crack the password OR find a hash collision is to have gotten not only the SQL DB dump but also the complete forum script files... not impossible of course if the leak was a result of an insider of course.

    in any case, if you receive one of these scam e-mail, I suggest you dump the full headers, do a WHOIS on the IP of the server responsible for sending it and then hopefully, if it's an actual webhost and not a zombie machine, let the host know about it so they can take the account down.
  • Does anybody know, when the Usernames & Email addresses were "harvested" last year (I take it they mean stolen), were Passwords stolen too?

    I can't be the only (stupid) person who uses similar passwords on MSE and on other websites.

    I've changed a few of them already in the light of this breach :o

    Don't worry - you're not the only one ;). I do (did!) the same so it's been an arduous afternoon changing them all :eek:
  • cagsd
    cagsd Posts: 7,662 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    I have received this email this afternoon :-/
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.3K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.4K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.