Stupid Punts!

Stupid Punts!

Text

Examples of the "Nigerian scam" that flood my email box everyday.
Showing posts with label hacked. Show all posts
Showing posts with label hacked. Show all posts

Saturday, February 02, 2013

Twitter Hacked

As per Reuters, Twitter has been hacked and the passwords of up to 250,000 accounts have been compromised:
"Anonymous hackers attacked Twitter this week and may have gained access to passwords and other information for as many as 250,000 user accounts, the microblog revealed late on Friday.

Twitter said in a blog post that the passwords were encrypted and that it had already reset them as a "precautionary measure," and that it was in the process of notifying affected users.

The blog post noted recent revelations of large-scale cyber attacks against the New York Times and the Wall Street Journal, but unlike the two news organizations, Twitter did not provide any detail on the origin or methodology of the attacks.

"This attack was not the work of amateurs, and we do not believe it was an isolated incident," Twitter said. "The attackers were extremely sophisticated, and we believe other companies and organizations have also been recently similarly attacked."

Privately held Twitter, which has 200 million active monthly users, said it was working with government and federal law enforcement officials to track down the attackers.

The company did not specifically link the attacks to China in the blog post, in contrast to the New York Times and the Wall Street Journal, which both said the hackers originated in China.

Twitter, the social network known for its 140-character messages, could not speculate on the origin of the attacks as its investigation was ongoing, said spokesman Jim Prosser.

"There is no evidence right now that would indicate that passwords were compromised," said Prosser.
The attack is not the first time that hackers have breached Twitter's systems and gained access to Twitter user information. Twitter signed a consent decree with the Federal Trade Commission in 2010, subjecting the company to 10 years of independent privacy reviews, for failing to safeguard users' personal information."

Wednesday, August 03, 2011

Sun Hacked

The Guardian reports that News International on Monday emailed thousands of people to warn them that one or more hackers have copied personal details of thousands of people who entered competitions and polls on the Sun's website and are posting them publicly on the internet. The hack took place several weeks ago, on 19th July.

Chris Duncan, the director of customer data for News International, wrote in the email:

"..some customer information from competitions and polls was breached...

No financial or password information was compromised.
."

Given that names, addresses, dates of birth, emails and phone numbers were taken this exposes people to the risk of id theft and fraud (whatever Duncan may claim).

Tuesday, July 12, 2011

Military Email Addresses Hacked

The Telegraph reports that 90,000 email addresses have allegedly been stolen from Booze Allen Hamilton (which provides technological services including cyber-security consulting to the military and other US government agencies).

The "online collective" Anonymous claims that it has posted the details on the internet.

Seemingly 53,000 of the hacked emails carried the military “.mil” domains.

Tuesday, July 05, 2011

Google+ Hacked

Be warned, the Telegraph reports that Google+ (the new social network) has been hacked. The hackers are now sending out bogus invites to Google+, which instead directs users to a pharmaceutical website.

Friday, June 03, 2011

Sony Hacked Again

Much like the return of an unloved season, it appears that hacking Sony's systems is becoming a tedious regular event.

LulzSec, a hacker group, have attacked Sony Pictures (the entertainment distribution division) and stolen/published the private details (including names, birth dates, addresses, emails, phone numbers and passwords) of more than a million people.

The Telegraph reports that LulzSec claims that the hack was designed to prove how vulnerable Sony was to "simple attacks".

All very, maybe. However, why then publish people's private details and leave them open to abuse by criminals, stalkers, phishers, scammers and other dross?

Friday, May 06, 2011

Wednesday, May 04, 2011

Sony Shuts Stable Door

The Guardian reports that Sony has hired private investigators, including a former special agent with the US Naval Investigative Service, to track down the hackers who stole the personal details of more than 100 million online gamers.

The UK information commissioner's office is also making enquiries, as well as the FBI in the US.

Unconfirmed reports in the media indicate that some Sony customers have noted irregular activities in their bank accounts.

As to whether there is another hack, that has yet to be identified/admitted/occur remains to be seen.

Tuesday, May 03, 2011

Sony PlayStation Network Hacked II

Last week Sony admitted that up to 77 million users of its PlayStation Network may have had their security compromised by a hack.

Now it has revealed that a further 25 million users may face a security compromise.

It seems that on 18 April, the day before PlayStation Network was hacked, Sony Online Entertainment PC games network was hacked. However, Sony did not find out about the breach until early on Monday and shut down the service shortly afterwards.

Sony Online Entertainment network hosts games such as "EverQuest".

Sony stated that the names, addresses, emails, birthdates, phone numbers and other information from 24.6 million PC games accounts may have been stolen from its servers as well as an "outdated database" from 2007.

Wednesday, April 27, 2011

Sony PlayStation Network Hacked

Sony shut down its PlayStation Network last week because it has discovered a "non-gaming" intrusion into the system.

However, it had not realised until late yesterday (after forensic security testing) that the breach had led to the theft of the data of the 77 million users. This data theft could compromise the financial security of the 77 million users who have registered their details with Sony.

Here is a list of FAQ's from the Sony site re the security breach:

Update on PSN Service Outages

Q.1 When did you realise the system had been intruded?

We discovered between April 17 and April 19 there was an illegal and unauthorized intrusion into our network.

Q.2 How did you know that the system was intruded?

We watch for any issues that may be raised with respect to security and monitor for such issues both internally and externally.

Q.3 What is the main reason to this problem? Which parts of the system were vulnerable to the intrusion?

We are currently conducting a thorough investigation of the situation. Since this is an overall security related issue, we will not comment further on this case.

Q.4 What action did you take (are you taking)? Is there any possibility of further unauthorized access?

As soon as we learned of this issue, 1) we temporarily turned off PlayStation Network and Qriocity services in order to conduct a thorough investigation and to verify the smooth and secure operation of our network services, 2) we have also engaged an outside, recognized security firm to conduct a full and complete investigation into what happened, and 3) quickly taken steps to enhance security and strengthen our network infrastructure by re-building our system to provide you with greater protection of your personal information.

Q.5 How many were affected? How many per each region? What is the latest status of PlayStation Network registered account/ operating countries.

Our investigation indicates that all PlayStation Network/ Qriocity accounts may have been affected.

Q.6 Does that mean all users’ information was compromised? Tell us more in details of what personal information leaked.

In terms of possibility, yes. We believe that an unauthorized person has obtained the following information that you provided: name, address (city, state/province, zip or postal code), country, email address, birthdate, PlayStation Network/Qriocity password, login, password security answers, and handle/PSN online ID. It is also possible that your profile data may have been obtained, including purchase history and billing address (city, state/province, zip or postal code). If you have authorized a sub-account for your dependent, the same data with respect to your dependent may have been obtained. If you have provided your credit card data through PlayStation Network or Qriocity, it is possible that your credit card number (excluding security code) and expiration date may also have been obtained.

Q.7 Have you notified those users?

We are sending out e-mails directly to these users to their e-mail address registered on the PS Network accounts. Also, we have posted web notices, and additional necessary procedures have been followed by each region.

Q.8 Have you received reports or claims that their PSN ID information/ credit card had been used improperly?

Not at this point in time.

Q.9 I want to know if my account has been affected.

To protect against possible identity theft or other financial loss, we encourage you to remain vigilant to review your account statements and to monitor your credit reports. Additionally, if you use the same user name or password for your PlayStation Network or Qriocity service account for other unrelated services or accounts, we strongly recommend that you change them. When the PlayStation Network and Qriocity services are back on line, we also strongly recommend that you log on to change your password.

For your security, we encourage you to be especially aware of email, telephone, postal mail or other scams that ask for personal or sensitive information. Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking.

Q.10 What should I do to prevent any unauthorized use of my (credit card) personal information?

For your security, we encourage you to be especially aware of email, telephone, postal mail or other scams that ask for personal or sensitive information. Sony will not contact you in any way, including by email, asking for your credit card number, social security number or other personally identifiable information. If you are asked for this information, you can be confident Sony is not the entity asking. Additionally, if you use the same user name or password for your PlayStation Network or Qriocity service account for other unrelated services or accounts, we strongly recommend that you change them. When the PlayStation Network and Qriocity services are back on line, we also strongly recommend that you log on to change your password.

To protect against possible identity theft or other financial loss, we encourage you to remain vigilant to review your account statements and to monitor your credit reports.

Q.11 Since when have PSN/Qriocity become unavailable and in which region?

PSN/Qriocity services have not been available since April 20 (US time) in all regions.

Q.12 How come it is taking so much time to resume the service?

We are taking the investigation seriously. We decided to keep the service down to allow us to conduct a thorough investigation and verify smooth operation of our network services.

Q.13 How serious is this? Have the hackers broken the security on PSN/Qriocity? Are you taking necessary measures to prevent such outage happening in the future?

Since this is an overall security related issue, we will not comment further on this case but we are working to restore and maintain the services, including countermeasures against future intrusions.

Q.14 When will the service resume?

We are taking the investigation seriously. We will keep the service down to allow us to conduct a thorough investigation and verify smooth operation of our network services but are working hard to resume the services as soon as we can be reasonably assured security concerns are addressed.

Q.15 Seems like SOE service was also not available/ suffering outage. Is this true? Is this due to the same reason as the PSN/Qriocity outage?

SOE's service is available although a service interruption due to an external attack did occur. A thorough investigation is ongoing.

Q.16 I want my money back (subscription fee, content) since the PSN/Qriocity was not available.

When the full services are restored and the length of the outage is known, we will assess the correct course of action.

Q.17 There seems to be some games that cannot be played even offline?

Depending on the game titles, but mainly PSN games, some may require access to PSN for trophy sync, security check, etc.

Contact Details

Country Customer Support
Africa sonycustomercare.mea@ap.sony.com
Australia 1-300 365-911
Austria 0820 44 45 40
Belgium 011 516 406
Bulgaria support@sbhbg.com
Croatia playstation.hr@arsvenatus.hr
Cyprus 22352282
Czech Republic 222 864 199
Denmark 90137013
Estonia 6543484
Finland 600411911
France 0820 31 32 33
Germany 01805 766 977
Greece 801 11 92000
Hungary 1 814 4800
Iceland 591- 5100
India 1800-103-7799
Ireland 0818 365065
Israel 09-9711700
Italy 199 116 266
Latvia 67046049
Lithuania 37338655
Luxembourg 0820 31 32 33
Malta 234 360 00
Middle East - All sonycustomercare.mea@ap.sony.com
Netherlands 0495 574 817
New Zealand 09 415 2447
Norway 82068322
Poland 0 801 230 000
Portugal 707 23 23 10
Romania support@sbhbg.com
Russia 8-800-200-76-67
Slovakia 232 112 209
Slovenia 1 510 31 30
South Africa 0861 773783
Spain 902 102 102
Sweden 09002033075
Switzerland 0848 84 00 85
Turkey bilgi@eu.sony.com

Ukraine 0 800 307 669
UK 0844 736 0595

Wednesday, April 06, 2011

Marks and Spencer Spam Warning

Following on from my earlier article about the largest data theft in history, it seems that Marks and Spencer have been caught up in that theft as well.

M&S have warned their customers to expect an increase in spam e-mail after hackers stole their details from the marketing firm Epsilon.

Wednesday, February 25, 2009

Straw Scammed

It seems that even intelligent people can be scammed by the scammers, according to this article from The Times.

The phones began to ring in Jack Straw's constituency office late last week, and the questions that the callers asked were always the same: was the Justice Secretary really stranded in Africa with no wallet? And did he really need $3,000 to get home?

No, and no, replied baffled officials. It was some time before they realised the truth - that Mr Straw, who as Home Secretary once launched a National Hi-Tech Crime Unit to crack down on computer hackers, had himself become the victim of Nigerian internet fraudsters.

The culprits had gained access to a Hotmail account that Mr Straw used to reply to questions from voters in his Blackburn constituency, by the simple expedient of sending a phishing email claiming that the email account would be suspended unless a reply was sent.

Perhaps unwisely, somebody in Mr Straw's office fell for it and sent a reply last Thursday. This gave the fraudsters enough information to hack into the account and glean the names of hundreds of Mr Straw's contacts in his online address book, ranging from Labour party members to council bosses.

Related Links
Twitter accounts of Obama, Britney hacked
Straw may curb freedom of information
Thousands hit by tax return ‘phishing’ scam
Soon afterwards, bogus emails with the official heading The Right Hon Jack Straw MP began pouring into e-mail inboxes around Blackburn.

Startled voters found themselves reading a personal plea from the Justice Secretary for help after finding himself stranded while visiting Lagos, the Nigerian capital, for a project called Empowering Youth To Fight Racism.

“I misplaced my wallet on my way to the hotel where my money and other valuable things were kept," the fake Mr Straw wrote.

“I would like you to assist me with a soft loan urgently to settle my hotel bills and get myself back home.”

This week Mr Straw confirmed the incident, in an interview with his local newspaper, the Lancashire Telegraph, but attempted to make light of it.

“I started getting phone calls from various constituents asking if I was really in Nigeria needing $3,000.

“It was an issue for constituents, not the Government. We are checking all that and I am assured there’s no evidence that confidentiality of constituents was affected.”

He added that there were no security issues relating to his Cabinet post as the attempted fraud related to addresses stored in his Blackburn email account rather than a ministerial one.

“A lot of work goes on by the serious organised crime organisation in this country," philosophised Mr Straw.

“The internet is wonderful in many ways, but these gangs put a lot of effort in because they make money from it.

“In a lot of cases they do get people to cough up. But I think it was so obviously ridiculous that I could go off trekking in Africa and I would lose my wallet.”

One constituent is believed to have replied to the email, but - in what may be a blow to Mr Straw's self esteem - nobody offered any money.

The account was later suspended by Microsoft officials.

Thursday, February 23, 2006

PHISH WARNING

The following phish, claiming to be from Visa, is doing the rounds at the moment.

Do not, if you receive one, click on the link and enter your details. This is a scam, designed to trick you into reveling your passcodes and id details.

Good afternoon, unfortunately some processings have been cracked by hackers, so a new secure code to protect your data has been introduced by Visa. You should check your card balance and in case of suspicious transactions immediately contact your card issuing bank. If you don't see any suspicious transactions, it doesn't mean that the card is not lost and cannot be used. Probably, your card issuers have not updated information yet. That is why we strongly recommend you to visit our website and update your profile, otherwise we cannot guarantee stolen money repayment. Thank you for your attention. Click here and update your profile.

Tuesday, May 04, 2004

Warning, the Nigerian scammers are becoming more imaginative.

Account holders of international banks such as Barclays are receiving internet messages asking them to "reactivate" their accounts. The message requests the recipient to enter their account number.

This of course gives the scammers instant access to the account holders funds.

The Nigerian scam now also includes the hacking into of authentic websites of banks.

Do not respond to these messages, they are scams.

It's a nasty old world out there!