Jump to content

Conspiracy Theory: Password hacking and attempted logins.

SeanTwig

I say this is a conspiracy theory because in this time of forced advertising I can't be sure of anything anymore.

 

Backstory:

I have had the same variation of a password since I was 13 (I am now 26). Bear in mind that this password is not a general word. It is a name of a very obscure creature from a very unknown book series I read as a kid. I change this around for the different sites, adding caps and numbers where needed.

 

Recently, I am getting notifications from places like Google, Ubisoft, Blizzard, etc that my account has been either hacked or there was an unsuccessful login attempt. Normally its from some random country in either Asia or one of the Eastern block countries.

 

What I want to know is if there are any of you lovely people who are getting these notifications lately. Obviously whenever there is an attempted login, I change my password completely but lately I am getting these "attempts" maybe 2 or 3 times a month.

 

My theory is that they are giving me these false attempts in an attempt to get me to sign up to their authenticators etc.

 

Let me know what your experiences are.

Link to comment
Share on other sites

Link to post
Share on other sites

i mean... i keep getting pasword reset request from roblox (lol) but nothing else.... go to haveibeenpwned and check if your emails/passwords have been leaked. That is VERY strage behavior for it to be coming from many different places. 

Link to comment
Share on other sites

Link to post
Share on other sites

I've never had an unauthorised login attempt email/notification before for anything. I have 2FA wherever available, passwords which literally only I would know, and I reserve my own sensitive data if I have the option to. I'm not popular nor on-the-radar enough to have people try breach my accounts.

 

Yes, I take my online security far too seriously, but I digress.

mechanical keyboard switches aficionado & hi-fi audio enthusiast

switch reviews  how i lube mx-style keyboard switches

Link to comment
Share on other sites

Link to post
Share on other sites

I think you're a fool that doesn't realize your email definitely and probably password has been leaked through a database breach. I'm not trying to be ass about it, it's just that this is like the most naive thing I've read in the past week.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

they might have cracked through a server with your data in it instead.

 

Nothing beats having scammers use your own email address for phishing scams though, and that's what happened to me. I literally got a scam email from my own account....

CPU: i7-2600K 4751MHz 1.44V (software) --> 1.47V at the back of the socket Motherboard: Asrock Z77 Extreme4 (BCLK: 103.3MHz) CPU Cooler: Noctua NH-D15 RAM: Adata XPG 2x8GB DDR3 (XMP: 2133MHz 10-11-11-30 CR2, custom: 2203MHz 10-11-10-26 CR1 tRFC:230 tREFI:14000) GPU: Asus GTX 1070 Dual (Super Jetstream vbios, +70(2025-2088MHz)/+400(8.8Gbps)) SSD: Samsung 840 Pro 256GB (main boot drive), Transcend SSD370 128GB PSU: Seasonic X-660 80+ Gold Case: Antec P110 Silent, 5 intakes 1 exhaust Monitor: AOC G2460PF 1080p 144Hz (150Hz max w/ DP, 121Hz max w/ HDMI) TN panel Keyboard: Logitech G610 Orion (Cherry MX Blue) with SteelSeries Apex M260 keycaps Mouse: BenQ Zowie FK1

 

Model: HP Omen 17 17-an110ca CPU: i7-8750H (0.125V core & cache, 50mV SA undervolt) GPU: GTX 1060 6GB Mobile (+80/+450, 1650MHz~1750MHz 0.78V~0.85V) RAM: 8+8GB DDR4-2400 18-17-17-39 2T Storage: HP EX920 1TB PCIe x4 M.2 SSD + Crucial MX500 1TB 2.5" SATA SSD, 128GB Toshiba PCIe x2 M.2 SSD (KBG30ZMV128G) gone cooking externally, 1TB Seagate 7200RPM 2.5" HDD (ST1000LM049-2GH172) left outside Monitor: 1080p 126Hz IPS G-sync

 

Desktop benching:

Cinebench R15 Single thread:168 Multi-thread: 833 

SuperPi (v1.5 from Techpowerup, PI value output) 16K: 0.100s 1M: 8.255s 32M: 7m 45.93s

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Jurrunio said:

they might have cracked through a server with your data in it instead.

 

Nothing beats having scammers use your own email address for phishing scams though, and that's what happened to me. I literally got a scam email from my own account....

Some scams intentionally spoof the email address with your own.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, 2FA said:

I think you're a fool that doesn't realize your email definitely and probably password has been leaked through a database breach. I'm not trying to be ass about it, it's just that this is like the most naive thing I've read in the past week.

I mean, that is why I am asking for some insight lol ?

 

My doubts come from the fact that I have never had anything come of it. They're just attempts and nothing happens. No money from my account. No password changes other than the ones I made. Nothing. Just an attempted login and that's it.

 

Very strange

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, saksham said:

i mean... i keep getting pasword reset request from roblox (lol) but nothing else.... go to haveibeenpwned and check if your emails/passwords have been leaked. That is VERY strage behavior for it to be coming from many different places. 

Thanks for the suggestion. I will check!

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, SeanTwig said:

I mean, that is why I am asking for some insight lol ?

 

My doubts come from the fact that I have never had anything come of it. They're just attempts and nothing happens. No money from my account. No password changes other than the ones I made. Nothing. Just an attempted login and that's it.

 

Very strange

If your email address is just as old and isn't super important, I would suggest moving to a new email address. It helps with the automated login attempts by bots.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, 2FA said:

If your email address is just as old and isn't super important, I would suggest moving to a new email address. It helps with the automated login attempts by bots.

I have one "throw away" address, but my main one (the one that has been targeted) is quite important as I have a business that links sort of to it. Although that business has its own email, many of my customers have my personal address.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, SeanTwig said:

I have one "throw away" address, but my main one (the one that has been targeted) is quite important as I have a business that links sort of to it. Although that business has its own email, many of my customers have my personal address.

I didn't say stop using it for actual email purposes, just stop using it with services.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, SeanTwig said:

I just checked haveibeenpwned and it turns out there was a leak from Nexus Mods that might have leaked my email. Fuckin Skyrim mods! 

Also, does anyone know why I have supposedly been leaked from sites I have never heard of before? Like Disqus and Pemiblanc. Apparently my email passwords and usernames were leaked there too but I have never visited those sites?

 

Maybe its time I embraced the VPN meme LUL

Link to comment
Share on other sites

Link to post
Share on other sites

38 minutes ago, 2FA said:

it's just that this is like the most naive thing I've read in the past week.

well, obviously you have not seen what i post on discord ?

✧・゚: *✧・゚:*  Quote for a reply  *:・゚✧*:・゚✧

 

✧・゚: *✧・゚:*   Ask for discord   *:・゚✧*:・゚✧

Link to comment
Share on other sites

Link to post
Share on other sites

The only emails of the sort I get, is from "Epic Games" where my account supposedly had a bunch of failed login attempt, so I should change the password by clicking their link... But that make no sense, because if they fucked up their log in attempt, it means my password worked at keeping them out in the first place, hence having no need to change it.
So I'm guessing it's just idiots trying to fish for Fortnite accounts using leaked emails+password they find online from other services that were previously hacked.

 

I use a password manager (keepass) and don't reuse a single password, all of them are between 16 and 32 characters long. (because some services still have a character limit of 16... ridiculous)

As for my email, I have 4 addresses that I use(but really only use 3 of them and just keep the last one as a "backup" of sort for recovery purposes... Professional email, personal email and throw away email), and all of them have two factor auth enabled and a unique password, not worried on that side of things either.

CPU: AMD Ryzen 3700x / GPU: Asus Radeon RX 6750XT OC 12GB / RAM: Corsair Vengeance LPX 2x8GB DDR4-3200
MOBO: MSI B450m Gaming Plus / NVME: Corsair MP510 240GB / Case: TT Core v21 / PSU: Seasonic 750W / OS: Win 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

57 minutes ago, TetraSky said:

I use a password manager (keepass) and don't reuse a single password, all of them are between 16 and 32 characters long. (because some services still have a character limit of 16... ridiculous)

Is there a subscription for that service? I just bought a car so I am fairly tight on expendable cash atm.

Link to comment
Share on other sites

Link to post
Share on other sites

Jabberwocky? Bandersnatch? 

 

If its important and youre not using 2FA then thats terrible and youre asking to get hacked.

 

Also, your computer is likely full of malware, probs a RAT or rootkit. 

 

Run malwarebytes with rootkit detection enabled.

 

Password managers are also targets for hackers. Better off using an easy password with 2FA, writing down or printing backup codes and putting them in a fireproof safe.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, VegetableStu said:

if there's an attempted brute-force attack or a database leak, I'd change emails / login names as well I think ._.

Unless the provider is hacked(yahoo style) theres no need to switch emails. If he has access to the email and can purge everyone else from accessing it, it can be secured.

 

Once he has 2FA set up with backup codes and deletes any other "trusted devices" he should be secure.

 

I should note that all of this is a moot point if the device he logs in from is pwned with malware.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Amazonsucks said:

If its important and youre not using 2FA then thats terrible and youre asking to get hacked.

What 2FA should I be using then? I have seen some saying Google Authenticator and I use this for Uplay now. However, I don't quite get how it all works. Do I have to do things like unlog from my Facebook app on my phone and then manually sign in with 2FA every time?

 

I have also run malware checks on my system and I have no 3rd party apps installed on my phone bar things like Google Calendar and Inbox etc.

Link to comment
Share on other sites

Link to post
Share on other sites

I use different passwords for everything, three parts to them. What? You think I'm gonna tell you? 

 

I'd recommend changing your passwords sometime... Or at least start using different ones

Corsair 4000D RGB

Asus B550 Tuf Gaming II

Asus 7700XT Tuf Gaming

AMD 5600x3d

32gb 3200mhz gskil 

 

Link to comment
Share on other sites

Link to post
Share on other sites

No password is safe forever unfortunately, and once one person finds it it will end up on a wordlist/dictionary for brute force attacks.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

In the past week alone I've gotten emails from Blizzard, Epic Games, Facebook, Google, PayPal, Bank of America, Linkedin, and about a half dozen other places that there are claiming invalid login attempts or that I have funds waiting for me, messages, etc.. There is just ONE problem. I either do not have an account at these places or that email address is NOT linked to those accounts and digging a little bit shows the emails coming from other sources.

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

>https://haveibeenpwned.com/

 

My email was leaked in 2016 thanks to Epic Games and their Unreal Engine forum. Thus, I got email from Google about someone trying to login into my rather precious Google account with the right password. If someone attempted to login with the right password it means that it was bruteforced, someone guessed it or it was leaked. Otherwise it's someone just guessing the passwords or something and you should activate 2 factor authentication and not worry.

12 hours ago, 2FA said:

Some scams intentionally spoof the email address with your own.

Ahaha, I got a message to my email from a gmail address that had my name on it about bitcoin investing. I don't even use my name on gmail addresses. ?

My stuff:

Spoiler

CPU :  Intel i5 8400 | GPU : MSI GTX 970 Gaming 4GB

 

RAM : 32GB Corsair Vengeance DDR4 @ 3600MHz

 

Mouse : Logitech G502 HERO SE | Keyboard : Mountain Everest Max w/ Cherry MX Brown

 

Headset : Beyerdynamics DT990 Pro 250Ω w/ AT2020USB+

 

Monitor : Acer XF240H @  144Hz

 

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, SeanTwig said:

What 2FA should I be using then? I have seen some saying Google Authenticator and I use this for Uplay now. However, I don't quite get how it all works. Do I have to do things like unlog from my Facebook app on my phone and then manually sign in with 2FA every time?

 

I have also run malware checks on my system and I have no 3rd party apps installed on my phone bar things like Google Calendar and Inbox etc.

Google authenticator is good. 

 

https://en.m.wikipedia.org/wiki/Google_Authenticator

 

The TLDR is that the app on your phone continuously generates codes that are valid for a short time, and when you try to log into the account, it asks you for the code. Without the correct code, you cant get into the account even if you have the password.

 

Thats why you need a backup fixed code in case your phone breaks, preferably stored in a fireproof safe. Without a second factor, you cant get into the account.

 

You can tell the account(facebook, google whatever) to remember the device and not ask for 2FA codes if its your phone, or your PC that no adversary is going to have physical access to. You wouldnt want to do it, for example, on a public computer that someone could get into your account and steal the backup codes from.

 

I have 2FA on for everything that supports it. Its good opsec to use it. Text message based 2FA is going out of favor because the texts can actually be intercepted and the person being hacked wont even know they got hacked because the text doesnt appear on their phone, or can even be remotely deleted.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, Lurick said:

In the past week alone I've gotten emails from Blizzard, Epic Games, Facebook, Google, PayPal, Bank of America, Linkedin, and about a half dozen other places that there are claiming invalid login attempts or that I have funds waiting for me, messages, etc.. There is just ONE problem. I either do not have an account at these places or that email address is NOT linked to those accounts and digging a little bit shows the emails coming from other sources.

Your email likely got pwned. Do you have 2FA on? Have you removed access from all trusted devices? Someone else could be currently using your email account if you dont have 2FA on, and if they have set up a back way into your email or you have a RAT or rootkit on your computer, changing your password does NOTHING to stop them.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×