📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Clearscore - email re. passwords found on dark web

Hi !
Today, I received an email from Clearscore saying that my passwords have been found on dark web.
After the initial panic, I realised I've never shared my passwords with Clearscore.
I'm beginning to believe it may be a marketing ploy to get me to buy into the monthly fee protection scheme the company offers ?
Has anyone had any similar experiences with the company ?
Thanks

Comments

  • funkycredit
    funkycredit Posts: 536 Forumite
    500 Posts First Anniversary Name Dropper
    I read it as they trawl the dark web and find matches based on your email address. As in on mine it has a couple linked to the same email address used to login to clear score. 

    Example, my main Hotmail email - the password hint they showed was my password so I changed it.
  • Interesting, I see ...
    Thanks funkycredit
  • MattMattMattUK
    MattMattMattUK Posts: 10,966 Forumite
    10,000 Posts Fourth Anniversary Name Dropper
    Put your emails in here, it will allow you to see if your details have been exposed from various leaks and hacks etc. the chances are one will contain a password hack and you can tell from when it occurred whether your current passwords are vulnerable or not. 

    https://haveibeenpwned.com/

  • PRAISETHESUN
    PRAISETHESUN Posts: 4,778 Forumite
    Sixth Anniversary 1,000 Posts Photogenic Name Dropper
    Clearscore won't know your passwords, but as above will check your email against known data breaches. It is a marketing gimmick designed to make you scared and panic buy something you probably don't need, but you don't need to buy their services to protect yourself online - you can do most of it yourself.

    Having been involved in a breach, I'd be looking to change your passwords, particularly if you reused the same one(s) for multiple services. In an ideal world you'd use a unique password + two factor authentication (2FA) for every online service where possible. Checking all your emails against haveibeenpwned as @MattMattMattUK on a semi-regular basis is also a good idea - schedule an "online health check up" in your calendar every 6 months or so.
  • There were quite a few old sites like Zynga (does a lot of facebook games) where accounts were accessed. Safest bet is to check the pwned site and ensure any sites affected you change your password and if you use the same password/email on other sites, change them too.

    Browsers like chrome will offer random passwords for password creation, difficult to guess 15+ character ones, so long as you have them saved securely e.g. behind a finger print reader or similar, then that is better than just your dog's name with 123 on the end.
  • Ohfeelya
    Ohfeelya Posts: 70 Forumite
    Sixth Anniversary 10 Posts Name Dropper
    I haven't gotten that message from ClearScore but I saw they were selling their monthly scheme. funkycredit's explanation makes sense.

    I would recommend using a password manager. I use BitWarden but there are several good ones.

    1. Can use unique, strong passwords for each app/website.
    2. Multiplatform support - works on my Linux laptop, windows PC, Android Phone + Tablet, firefox and chrome
    3. BitWarden is open source and has been tested by a third party
    4. It's free
    5. You can check if your password has been exposed in the BitWarden app.


Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.4K Banking & Borrowing
  • 252.9K Reduce Debt & Boost Income
  • 453.3K Spending & Discounts
  • 243.4K Work, Benefits & Business
  • 597.9K Mortgages, Homes & Bills
  • 176.6K Life & Family
  • 256.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.