We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Pixmania email security breach?

Dear MSE'rs

I have just received some spam to my pixmania account email address (I know this because it was addressed to a dedicated email address I used for, i.e. pixmania@....).

Has anyone else seen spam via pixmania recently? I am concerned about the fact that they might have had their security breached a la Sony.

The sender of the email was "petryrojxbana@hotmail.com" and looking at the source of the email it is peddling:

Customer Service Assistant vacancy at ASTRO Consulting

I have had similar issues with Play.com and my Playstation account too - this is getting very concerning now as they are no longer rare isolated incidences for me.
«1

Comments

  • 8u87fhsd
    8u87fhsd Posts: 28 Forumite
    & I also use pixmania@
  • asbokid
    asbokid Posts: 2,008 Forumite
    balfralf wrote: »
    Dear MSE'rs

    I have just received some spam to my pixmania account email address (I know this because it was addressed to a dedicated email address I used for, i.e. pixmania@....).

    Has anyone else seen spam via pixmania recently? I am concerned about the fact that they might have had their security breached a la Sony.

    The sender of the email was "petryrojxbana@hotmail.com" and looking at the source of the email it is peddling:

    Customer Service Assistant vacancy at ASTRO Consulting

    I have had similar issues with Play.com and my Playstation account too - this is getting very concerning now as they are no longer rare isolated incidences for me.

    Your suspicions of an email compromise are probably well founded.. Although the compromise might not have been through pixmania and its email or e-commerce servers.

    How is your email provided? Can you be sure that the mail servers you are using have always been free from compromise? Or indeed is the security of your own connectivity provided through your ISP beyond doubt?
  • System
    System Posts: 178,376 Community Admin
    10,000 Posts Photogenic Name Dropper
    asbokid wrote: »
    Your suspicions of an email compromise are probably well founded.. Although the compromise might not have been through pixmania and its email or e-commerce servers.

    How is your email provided? Can you be sure that the mail servers you are using have always been free from compromise? Or indeed is the security of your own connectivity provided through your ISP beyond doubt?

    I Agree ASBOKID, I thought a concensus of opinion on MSE might help indicate that Pixmania was the culprit rather than my ISP or perhaps even the delivery firm they've used for my deliveries.
    This is a system account and does not represent a real person. To contact the Forum Team email forumteam@moneysavingexpert.com
  • debitcardmayhem
    debitcardmayhem Posts: 13,161 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    asbokid wrote: »
    Your suspicions of an email compromise are probably well founded.. Although the compromise might not have been through pixmania and its email or e-commerce servers.

    I don't use pixmaniacs at all , but I get spam at my FT com throwaway address plus also for some throwaways for the OH (trust is a wonderful thing :D) and a couple of others I use
    How is your email provided? Can you be sure that the mail servers you are using have always been free from compromise? Or indeed is the security of your own connectivity provided through your ISP beyond doubt?
    My throwaways are via several mail providers , and if it is the ISP that is compromised then how did they specifically choose to use B7370616d6674 @ myaddresstoday.com which identifies ft(and the year I registered) and others eg A7370616d6d7365 being from mse , oh and also I also use a non-throwaway when I first register so that I can track the spam if I get two identical mails. I haven't yet found one that doesn't allow you change your email after registration
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • asbokid
    asbokid Posts: 2,008 Forumite

    I don't use sexmaniacs at all, but I get spam at my FT com throwaway address plus also for some throwaways for the OH (trust is a wonderful thing) and a couple of others I use

    My throwaways are via several mail providers , and if it is the ISP that is compromised then how did they specifically choose to use B7370616d6674 @ myaddresstoday.com which identifies ft (and the year I registered) and others eg A7370616d6d7365 being from mse , oh and also I also use a non-throwaway when I first register so that I can track the spam if I get two identical mails. I haven't yet found one that doesn't allow you change your email after registration

    That's interesting although I don't fully understand what you are doing.

    You have used unique and unguessable email addresses to subscribe to each online service?

    And yet 'they' still send spam to those unique email mailboxes?

    But who is 'they', and how are they linked to the subscribed service?

    The spammers might just have compromised a router, or a web server that provides hosting to the company, among many others.

    I just did a traceroute to www.ft.com and it was more than 20 hops. Any one of those routers could be compromised, allowing traffic to be sniffed for harvesting email addresses.
  • balfralf wrote: »
    Dear MSE'rs

    I have just received some spam to my pixmania account email address (I know this because it was addressed to a dedicated email address I used for, i.e. pixmania@....).

    Has anyone else seen spam via pixmania recently? I am concerned about the fact that they might have had their security breached a la Sony.

    The sender of the email was "petryrojxbana@hotmail.com" and looking at the source of the email it is peddling:

    Customer Service Assistant vacancy at ASTRO Consulting

    I have had similar issues with Play.com and my Playstation account too - this is getting very concerning now as they are no longer rare isolated incidences for me.

    Same here - dedicated Pixmania email COMPROMISED! Same with TheBookDepository and a couple of others. Oh dear!:eek:
  • asbokid
    asbokid Posts: 2,008 Forumite
    Same here - dedicated Pixmania email COMPROMISED! Same with TheBookDepository and a couple of others. Oh dear!

    Again, what does this prove? Most important question is who provides the mailboxes?

    If all your 'dedicated' mailboxes are provided by gmail.com, then Google would be the prime suspect, not pixmania nor thebooksuppository..
  • debitcardmayhem
    debitcardmayhem Posts: 13,161 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    edited 7 June 2011 at 9:14PM
    asbokid wrote: »
    And yet 'they' still send spam to those unique email mailboxes?

    But who is 'they', and how are they linked to the subscribed service?
    I will save some and if you like I will send you the UPS / DHL and others, trojan dropper zip/pdf(really a zip) files
    The spammers might just have compromised a router, or a web server that provides hosting to the company, among many others.
    Mmmm but registering is ssl'd so they must have trawled through the outgoing emails in that case.

    Edited: Sorry I can't send you the Viagra I have a use for it :beer:
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • debitcardmayhem
    debitcardmayhem Posts: 13,161 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    @asbokid That's interesting although I don't fully understand what you are doing.

    take away first letter (A=10,B=11,9=9,etc ...ok it only keeps me going til 2015) then eg
    use your linux box and do enter "echo spamft | od -xc" then you get 7073 6d61 7466 000a ie 7370616d6674 @ a throwaway com. So I register as that and also for "debitcardmayhem @ mse..... " . I opt for no contact on the "real debit address" and lo I get the same spam to each ergo it must be from spamft , not explaining too well but hey it has been free beer day .
    4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy
  • asbokid
    asbokid Posts: 2,008 Forumite
    edited 7 June 2011 at 9:59PM
    take away first letter (A=10,B=11,9=9,etc ...ok it only keeps me going til 2015) then eg
    use your linux box and do enter "echo spamft | od -xc" then you get 7073 6d61 7466 000a ie 7370616d6674 @ a throwaway com. So I register as that and also for "debitcardmayhem @ mse..... " . I opt for no contact on the "real debit address" and lo I get the same spam to each ergo it must be from spamft , not explaining too well but hey it has been free beer day .

    blimey! i wish i had never asked!

    anewman has posted elsewhere, and he too reports getting spam to the mailbox he only uses for pixmania..

    did you read this?

    http://www.boards.ie/vbulletin/showthread.php?p=70778012

    read lower down and someone adds the caveat that just because some scrote says he has hacked a server, doesn't necessarily mean that he has..
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.